Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

AI agents and machine identities: what IAM teams need to watch


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18936
Topic starter  

TL;DR: AI will expand attack surfaces faster than defenders can rework controls, especially around machine identity, API keys, and agentic tooling, while attackers keep exploiting weak identity verification and access management, according to Expel's 2026 predictions. The governing problem is not AI itself, but the persistence of long-lived credentials and the visibility gap they create.

NHIMG editorial — based on content published by Expel: 2026 cybersecurity predictions on AI, identity, and attacker behaviour

Questions worth separating out

Q: How should security teams govern AI agents that can access enterprise systems?

A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring.

Q: Why do machine identities create more risk than human identities in some environments?

A: Machine identities are often numerous, long-lived, and embedded in code or infrastructure.

Q: How should security teams handle exposed API keys and service credentials?

A: Treat exposed credentials as active identities, not as misplaced text.

Practitioner guidance

  • Map all machine identities to owners and expiry rules Create an inventory of service accounts, API keys, tokens, and certificates used by AI tooling, then assign a business owner, technical owner, and expiration policy to each one.
  • Restrict agent permissions to task-scoped operations Require agents to use narrowly scoped credentials tied to a specific workflow, with separate approvals for data access, tool execution, and production changes.
  • Automate revocation for exposed or abandoned secrets Treat leaked keys, unused tokens, and orphaned certificates as immediate containment items, with automated rotation and revocation triggered by exposure signals.

What's in the full article

Expel's full forecast covers the operational detail this post intentionally leaves for the source:

  • Direct quotes from executives and field leaders on AI, geopolitics, and regulation
  • The broader 2026 prediction set across federal policy, attacker behaviour, and developer targeting
  • Practitioner context on how Expel's team is weighting identity, patching, and AI security in its outlook
  • The source article's full discussion of where AI changes the security workload versus where it does not

👉 Read Expel's 2026 cybersecurity predictions on AI, identity, and attacker behaviour →

AI agents and machine identities: what IAM teams need to watch?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 18527
 

Machine identity governance will become a board-level control issue, not a niche IAM concern. Expel's forecast is consistent with what we see across NHI programmes: the number of non-human credentials grows whenever interoperability and automation are rewarded faster than governance is redesigned. The new concept here is identity delegation drift: permissions granted for one workflow gradually become standing access across multiple workflows. That drift is what turns AI adoption into an access problem, and practitioners need lifecycle controls that match the pace of deployment.

A question worth separating out:

Q: How do IAM and PAM teams apply governance to agentic AI testing platforms?

A: Treat the agent as a delegated actor with bounded authority. That means scope limits, revocation conditions, approval gates, and traceability should be designed like privileged access controls, not left as product settings. If an agent can act on behalf of the organisation, the governance model should resemble controlled delegated access.

👉 Read our full editorial: AI agents and machine identities will widen 2026 attack surfaces



   
ReplyQuote
Share: