Join our Newsletter — 33% off our NHI Course

EchoLeak and AI agent runtime trust: are IAM controls enough?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: EchoLeak showed that Microsoft 365 Copilot could exfiltrate API keys and internal data through hidden email instructions, even after authentication and authorization succeeded, according to 1Password. The real issue is the access trust gap: identity confirms who the agent is, but not whether a runtime action still makes sense.

Editorial analysis by NHI Mgmt Group, based on content published by 1Password: “The next layer of AI security”.

By the numbers:

  • Microsoft patched EchoLeak in June 2025.

Key questions

Q: What breaks when an AI agent can turn untrusted content into privileged actions?

A: The trust boundary breaks because the agent no longer just reads external text.

Q: Why do valid authentication and authorization still fail to prevent prompt-injection abuse?

A: Because those controls answer who the actor is and what it may access, not whether the action still makes sense after the agent’s context changes.

Q: How can organisations tell whether AI agent governance is actually working?

A: Look for evidence that agent access is ephemeral, traceable, and constrained at the action level.

Practitioner guidance

  • Map runtime trust boundaries Identify every place where an AI agent can consume untrusted content and then act with inherited permissions.
  • Reduce standing permission Replace durable access with short-lived credentials, token exchange, and task-scoped authority wherever an agent can touch sensitive systems or data.
  • Enforce deterministic action checks Place controls at the moment of tool use or data retrieval so that the action is evaluated against current context, not just initial authentication.

Bottom line: EchoLeak demonstrates that an AI agent can pass authentication and authorization checks while still being manipulated into unsafe runtime behaviour.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 1 day ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Access trust is now a runtime problem, not an identity problem: EchoLeak shows that authenticating the actor and authorizing the scope are no longer enough to guarantee safe behaviour. The failure occurs after both controls succeed, when untrusted content reshapes what the agent decides to do. The implication is that identity programmes must govern execution context as well as access grants.

A few things that frame the scale:

  • DeepSeek alone generated 113,000 new exposed API keys in 2025, illustrating how new AI providers create credential exposure before security guardrails catch up, according to the State of Secrets Sprawl 2026.
  • Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: What is the difference between identity verification and runtime authority for AI agents?

A: Identity verification establishes that the agent is legitimate and has an approved caller. Runtime authority determines whether a specific action should happen now, given the current task, content, and destination. For AI agents, the second question is often more important because intent can drift after authentication.

👉 Read our full editorial: AI agent identity needs runtime governance after EchoLeak


This post was modified 1 day ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.