Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AI agents and IGA: what identity teams need to govern now


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15374
Topic starter  

TL;DR: AI agents expose the limits of governance models built only for human joiner-mover-leaver patterns, because they can inherit permissions, use tools, and act without waiting for quarterly review cycles, according to Fischer Identity. The governance gap is not IGA itself but whether ownership, lifecycle, certification, and auditability can extend to every non-human identity.

NHIMG editorial — based on content published by Fischer Identity: AI Agents Do Not Make IGA Obsolete. They Make Modern Identity Governance More Important

Questions worth separating out

Q: How should security teams manage permissions for AI agents?

A: Security teams should regularly assess and update the permissions granted to AI agents to ensure they align with their intended scope.

Q: Why do AI agents complicate traditional access reviews?

A: AI agents complicate access reviews because they can accumulate permissions across tools and environments faster than manual certification cycles can observe.

Q: What breaks when organisations audit AI agents like service accounts?

A: Audit trails break when teams record only the API call and ignore the prompts, tools, and model outputs that caused it.

Practitioner guidance

  • Model AI agents as governed identities Assign each agent an owner, sponsor, business purpose, and lifecycle state before it is allowed into production workflows.
  • Tie certification to runtime telemetry Use SIEM, PAM, cloud logs, and application instrumentation to validate whether the access reviewed in IGA matches what the agent actually used.
  • Separate ownership from execution Require an accountable human or business function for every agent, even when the agent performs actions autonomously inside applications.

What's in the full article

Fischer Identity's full blog post covers the operational detail this post intentionally leaves for the source:

  • The article expands the governance model for AI agents, including ownership, sponsorship, and lifecycle state assignment.
  • It outlines how certification, provisioning, and deprovisioning should work when the identity is software-created.
  • It describes how Fischer Identity positions IGA alongside runtime tooling such as SIEM and PAM for auditability.
  • It includes the broader business case for treating non-human identities as governed identities in enterprise programmes.

👉 Read Fischer Identity's analysis of why AI agents strengthen modern IGA →

AI agents and IGA: what identity teams need to govern now?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14958
 

AI agents do not obsolete IGA, they expose where IGA was never extended far enough. The article is right to frame agents as part of the broader non-human identity problem, not a separate category that replaces governance. Service accounts, scripts, bots, and API credentials already proved that identity is a governance discipline, not a human-only process. The practitioner conclusion is simple: if the programme cannot govern software identities, it is not ready for agentic workloads.

A few things that frame the scale:

  • 98% of companies plan to deploy even more AI agents within the next 12 months, despite documented rogue behaviour in 80% of current deployments, according to AI Agents: The New Attack Surface.
  • Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation, according to the same report.

A question worth separating out:

Q: Who is accountable when an AI agent makes an unauthorised change?

A: Accountability should be assigned to the governance model that authorised the delegation, the owner of the workflow, and the team that set the policy boundary. In practice, organisations need clear responsibility for agent configuration, monitoring, and incident response because the machine’s speed does not remove human accountability for the delegated identity.

👉 Read our full editorial: AI agents strengthen the case for modern identity governance



   
ReplyQuote
Share: