TL;DR: Agentic AI is forcing identity security, governance, and compliance teams to rethink control models as machine and human access patterns converge, according to Pathlock. The underlying issue is that IAM programmes built for static entitlements and review cycles do not fit runtime decision-making by autonomous systems.
Editorial analysis by NHI Mgmt Group, based on content published by Pathlock: “Pathlock CEO Talks Identity in the AI Era”.
Key questions
Q: What breaks when access review models are applied to agentic AI?
A: Access review models break when the actor can obtain, use, and release privileges before the review cycle sees a stable state.
Q: Why do AI-driven attacks change identity governance requirements?
A: Because they compress attacker decision cycles and increase the volume of abuse that identity controls must evaluate.
Q: How should organisations govern agentic AI when it makes judgment calls, not just automated actions?
A: Organisations should govern the decisions agentic AI is permitted to make, not only the data it can access.
Practitioner guidance
- Map runtime decision points Identify where an AI system can choose tools, data sources or actions after authentication, and separate those points from ordinary access approval flows.
- Define execution boundaries Document which actions remain human-approved, which can be delegated, and which require a policy gate before an agent can proceed.
- Instrument action-level logging Capture the action taken, the policy context and the data touched so audits can reconstruct what the system actually did, not just what it was allowed to do.
Bottom line: Agentic AI exposes a mismatch between static entitlement models and software that can make decisions during execution.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Agentic AI creates an identity governance assumption collapse, not just a new access risk. Static entitlement models were designed for actors whose intent, scope and timing are stable enough to be certified later. That assumption fails when the actor can decide and execute inside the session. The implication is that access governance must stop assuming a durable reviewable state and start treating runtime behaviour as the control boundary.
A few things that frame the scale:
- 88% of organisations have embedded AI agents in their workflows, according to KPMG's 2026 report.
A question worth separating out:
Q: What is the difference between AI automation and agentic AI from an identity perspective?
A: AI automation performs predefined tasks within narrow boundaries, while agentic AI can choose actions, call tools, and persist across sessions. From an identity perspective, agentic systems need stronger authentication, authorization, review, and offboarding because they behave more like active identities than fixed scripts.
👉 Read our full editorial: Pathlock CEO on identity security in the AI era