TL;DR: Gartner’s January 2026 analysis says enterprises are moving from experimental generative AI to autonomous agents, and predicts 50% of all service requests will be initiated by non-human identity customers powered by agentic AI by 2030, according to Oasis Security’s summary of the report. Traditional IAM, PAM, and IGA controls do not handle non-deterministic agent behaviour.
Editorial analysis by NHI Mgmt Group, based on content published by Oasis Security: “Oasis named in Industry Analyst Report Highlighting Emerging Tech in AI TRISM and Agentic AI”.
Key questions
Q: How should security teams govern data access for agentic AI workflows?
A: Security teams should treat data access as part of the agent’s decision boundary, not as a separate storage problem.
Q: Why do traditional IAM and PAM controls struggle with autonomous AI agents?
A: Traditional IAM and PAM controls assume access can be granted, reviewed, and removed around a stable identity.
Q: What are the signs that agentic AI is operating outside its intended security boundaries?
A: Common warning signs include agents accessing systems they were not meant to use, acting on data beyond their assigned scope, or producing chained errors that spread across workflows.
Practitioner guidance
- Define a distinct agentic identity class Document agentic AI as a separate governed actor type with its own issuance, authority, and revocation rules rather than folding it into human or service-account policy.
- Inventory shadow AI across endpoints and cloud Extend discovery to locally installed agents and unmanaged AI tools so access decisions are based on an authoritative inventory, not assumptions about approved platforms.
- Bind access to task-scoped sessions Issue access only for the exact session needed by the agent, and remove the identity immediately after the task completes to avoid standing privilege.
Bottom line: Agentic AI exposes a governance gap because autonomous systems do not fit the identity assumptions built into legacy IAM, PAM, and IGA.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Agentic identity is not a new wrapper around NHI, it is a governance discontinuity. The article shows why autonomous agents cannot be managed as if they were service accounts with better prompts. Decision timing, tool choice, and session length are all runtime variables, so identity governance has to move from static assignment to dynamic authority boundaries. Practitioner conclusion: agentic AI requires its own identity model, not a renamed NHI playbook.
A few things that frame the scale:
- 69% of security leaders agree identity management must fundamentally shift to address agentic AI systems, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: How should teams implement AI access controls in a governance programme?
A: Start by inventorying every AI identity, including users, service accounts, API keys, model endpoints, and vendor connections. Then apply role-based access as the baseline and use context-aware policies for sensitivity, time, and purpose. The goal is to prevent broad standing access while keeping approvals auditable and aligned to business use cases.
👉 Read our full editorial: Agentic AI identity governance exposes the new identity gap