Join our Newsletter — 33% off our NHI Course

Agentic AI security at RSA 2026: what practitioners should watch

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Enterprise Management Associates' 2026 Vendor Vision report highlights ten vendors for RSAC 2026, with particular emphasis on solutions securing agentic AI and the autonomous enterprise against machine-speed threats, according to Acalvio. That shift shows identity teams are moving from point-tool evaluation to governance decisions about non-human and autonomous actors.

Editorial analysis by NHI Mgmt Group, based on content published by Acalvio: “EMA Unveils Top Security Innovators in Annual Vendor Vision Report Ahead of RSAC 2026”.

By the numbers:

  • The report identifies ten security companies driving innovation at the 2026 RSA Conference.
  • The 2026 RSA Conference is taking place March 23-26 at San Francisco's Moscone Center.
  • EMA says over 600 vendors and tens of thousands of cybersecurity professionals are expected to attend.

Key questions

Q: What breaks when teams treat autonomous agents like service accounts?

A: Teams lose visibility into dynamic decision-making, tool choice, and action timing.

Q: Why do autonomous systems change the way identity risk should be measured?

A: Because the main risk is no longer only credential exposure or standing privilege.

Q: What are the signs that agentic AI controls are too weak?

A: The warning signs are capability exposure and late-stage detection.

Practitioner guidance

  • Define agent identity boundaries Document which autonomous systems are allowed to initiate actions, which tools they may call, and which datasets or services are out of scope.
  • Separate human and machine approval paths Review where human review is still being used as the primary guardrail for runtime decisions and replace that assumption with policy enforcement that can block or constrain machine action before execution.
  • Map delegated tool use to privilege scope Inventory the tools, APIs, and service credentials an agent can reach during a task, then compare that runtime scope with the access granted at provisioning so hidden expansion is visible.

Bottom line: Agentic AI security is emerging as a distinct category because autonomous behaviour changes how identity, privilege, and delegation must be governed.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 1 day ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Agentic AI security is becoming an identity governance problem, not just a detection problem. EMA’s framing shows the market is moving from narrow tool security toward the harder question of who or what is permitted to act. That shift matters because the control surface now includes runtime decisions, delegated actions, and machine-speed execution paths. For identity teams, the field is converging on governance of behaviour, not just credentials.

A few things that frame the scale:

  • 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, according to the Ultimate Guide to NHIs.
  • 71% of NHIs are not rotated within recommended time frames, which leaves long-lived machine access exposed to persistence risk.

A question worth separating out:

Q: How can organisations tell whether their NHI programme is ready for agentic AI?

A: An NHI programme is ready only if it can answer who may initiate actions, what tools they may use, and when those permissions end. If those questions are still handled through static entitlement review alone, the programme is not ready for agentic behaviour. Readiness shows up in runtime policy, delegated scope, and fast containment.

👉 Read our full editorial: RSA 2026 vendor vision shows agentic AI security is now a category



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Agentic AI security is becoming a distinct governance category, not a feature add-on. When vendor attention clusters around autonomous systems and machine-speed threats, the market is signalling that existing NHI and IAM programmes will not be enough on their own. The important shift is that practitioners now have to govern runtime decision-making as an identity problem, not just model safety or application control. The implication is that agentic AI needs its own policy language, ownership model, and review criteria.

A question worth separating out:

Q: What should security teams do when autonomous systems need access to multiple tools?

A: They should define the actor's authority first, then map each tool and credential to that authority instead of granting broad workflow access and hoping the system stays inside it. The practical test is whether a task can be completed without giving the system reusable scope that outlives the session or the intended objective.

👉 Read our full editorial: RSA 2026 vendor vision shows agentic AI security is now a category


This post was modified 1 day ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.