Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

API security and agentic AI: what IAM teams need to know


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: 96% of attack attempts originate from authenticated entities, 80% of organisations still lack continuous API monitoring, and 50% have slowed or halted releases because of API risk, according to Salt’s H2 2025 State of API Security report. The message for security teams is clear: agentic AI increases API dependency faster than governance, so authorization, inventory accuracy, and runtime visibility now matter more than perimeter assumptions.

NHIMG editorial — based on content published by Salt: H2 2025 State of API Security

By the numbers:

Questions worth separating out

Q: What breaks when API security is treated as a perimeter problem instead of an identity problem?

A: Controls miss the real attack path, which now often begins with valid credentials and moves through excessive authorization.

Q: Why do AI agents create a governance problem for IAM teams?

A: AI agents create a governance problem because they authenticate and act as autonomous software entities with tool access.

Q: How can security teams tell whether API risk controls are actually working?

A: Look for reduced abuse volume, fewer successful automated attacks, and clearer visibility into which non-human clients are making requests and why.

Practitioner guidance

  • Build a real-time API inventory tied to identity ownership Map every API to a business owner, calling identity, and data sensitivity level.
  • Shift controls to post-authentication authorization checks Prioritise object-level and action-level authorization because most abuse is coming from authenticated entities.
  • Instrument runtime detection for abnormal API behaviour Watch for unusual call frequency, sequence drift, bulk reads, and access to objects outside the normal pattern.

What's in the full report

Salt's full report covers the operational detail this post intentionally leaves for the source:

  • Per-domain breakdowns of API risk patterns across AI development and production environments
  • Specific monitoring and governance benchmarks that help teams compare current inventory and response maturity
  • Practical guidance on securing authenticated API traffic, including runtime detection and authorisation controls
  • The report's readiness checklist for discovery, governance, and threat protection across agentic systems

👉 Read Salt’s H2 2025 State of API Security report on agentic AI and API risk →

API security and agentic AI: what IAM teams need to know?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

API security has become an identity governance problem, not just an application security problem. The article shows that authenticated entities now drive most abuse, which means the decisive control is no longer perimeter blocking but authorization quality. For IAM and PAM teams, that creates a direct bridge to service accounts, machine identities, and agent permissions. The practitioner conclusion is that API governance now sits inside the identity programme.

A question worth separating out:

Q: Which frameworks help teams govern AI systems that use internal tools?

A: NIST AI Risk Management Framework, OWASP Agentic AI Top 10, and MITRE ATLAS are the most relevant starting points when AI systems can reason, call tools, and touch data. Identity teams should pair them with NHI governance so credentials, permissions, and runtime reach are reviewed together instead of in separate silos.

👉 Read our full editorial: API security is now the control plane for agentic AI



   
ReplyQuote
Share: