Join our Newsletter — 33% off our NHI Course

AI infrastructure governance at API Summit, Sept 30: are controls ready?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: AI infrastructure is becoming more complex as engineers, architects, and leaders gather around production AI systems at Kong's AI + API Summit on Sept 30 to Oct 1, 2026, with sessions, workshops, and certification training focused on how these systems actually run. The governance problem is no longer tooling hype, it is whether IAM, NHI, and access controls can keep pace with AI-driven runtime behaviour.

Editorial analysis by NHI Mgmt Group, based on content published by Kong: “# AI + API Summit”.

Key questions

Q: How should security teams govern AI pilot identities before production?

A: Security teams should treat AI pilot identities as production candidates from the start.

Q: Why do static access reviews fall short for AI infrastructure?

A: Because AI infrastructure changes faster than periodic recertification can reflect.

Practitioner guidance

  • Inventory AI infrastructure identities Identify every service account, token, certificate, and API credential used across model hosting, orchestration, retrieval, logging, and deployment paths.
  • Tie ownership to each runtime credential Assign a business and technical owner to every machine identity used by the AI platform, including temporary identities created by pipelines and runtime automation.
  • Shorten the review gap Replace slow periodic reviews with controls that continuously observe issuance, use, and revocation so identities do not outlive their intended task.

Bottom line: AI infrastructure governance now depends on how well organisations control the machine identities that make production AI systems run.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 9 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21514
 

AI infrastructure governance is becoming an identity problem before it is an architecture problem. The event language is about sessions, workshops, and production systems, but the real issue is who or what is allowed to act inside those systems. When AI infrastructure touches secrets, APIs, and runtime automation, IAM and NHI controls become the limiting factor, not the compute layer. Practitioners should treat AI infrastructure as an identity governance surface, not just a platform stack.

A few things that frame the scale:

  • Only 13% of organisations feel extremely prepared for the reality of agentic AI despite the majority racing toward autonomous adoption, according to The 2026 Infrastructure Identity Survey.
  • 69% of security leaders agree identity management must fundamentally shift to address agentic AI systems, according to the same survey.

A question worth separating out:

Q: What should identity teams ask before approving AI platform expansion?

A: Identity teams should ask which actions are truly necessary, which ones require human approval, and which ones should be limited to workload identity with explicit context. If the answer is vague, the platform is likely accumulating hidden privilege. The right question is not whether AI can do more, but whether the governance model can still explain who is acting.

👉 Read our full editorial: AI infrastructure governance at API Summit: what practitioners need



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21514
 

AI infrastructure governance is becoming an identity problem before it is an architecture problem. The event language is about sessions, workshops, and production systems, but the real issue is who or what is allowed to act inside those systems. When AI infrastructure touches secrets, APIs, and runtime automation, IAM and NHI controls become the limiting factor, not the compute layer. Practitioners should treat AI infrastructure as an identity governance surface, not just a platform stack.

A few things that frame the scale:

  • Only 13% of organisations feel extremely prepared for the reality of agentic AI despite the majority racing toward autonomous adoption, according to The 2026 Infrastructure Identity Survey.
  • 69% of security leaders agree identity management must fundamentally shift to address agentic AI systems, according to the same survey.

A question worth separating out:

Q: What should identity teams ask before approving AI platform expansion?

A: Identity teams should ask which actions are truly necessary, which ones require human approval, and which ones should be limited to workload identity with explicit context. If the answer is vague, the platform is likely accumulating hidden privilege. The right question is not whether AI can do more, but whether the governance model can still explain who is acting.

👉 Read our full editorial: AI infrastructure governance at API Summit: what practitioners need



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21514
 

AI infrastructure governance is becoming an identity problem, not just an architecture problem. Once AI production stacks depend on many service accounts, API credentials, and orchestration paths, the security question shifts from where the model runs to who or what is authorised to move through the stack. That makes lifecycle and privilege scope the controlling variables for the whole environment. Practitioners should treat AI infrastructure as governed identity infrastructure first.

A few things that frame the scale:

  • AI-related credential leaks surged 81.5% year-over-year in 2025, with the surrounding AI infrastructure leaking 5x faster than core LLM providers, according to the State of Secrets Sprawl 2026.

A question worth separating out:

Q: How do IAM and PAM boundaries change in AI infrastructure environments?

A: They need to separate who can operate the platform from who can change it. If deployment privileges and runtime access are blurred, administrators can end up with broad control over both the infrastructure and the AI service itself, increasing blast radius.

👉 Read our full editorial: AI infrastructure governance at API Summit: what practitioners need


This post was modified 9 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.