Join our Newsletter — 33% off our NHI Course

IAM maturity models and AI agents: where current controls break

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: IAM maturity models still assume identities are comparatively stable, reviewable, and lifecycle-managed, but AI agents and other non-human identities expose gaps in provisioning, access review, and governance that human-centric programmes often leave uneven, according to Zluri research. Maturity now depends on governing identities that act at runtime, not just ones that can be reviewed later.

Editorial analysis by NHI Mgmt Group, based on content published by Zluri: “Identity & Access Management Maturity Model - A Guide For 2026”.

Key questions

Q: What breaks when identity maturity models exclude NHIs and AI agents?

A: They misstate the real control boundary.

Q: Why do AI agents change existing IAM assumptions?

A: AI agents change IAM assumptions because access is no longer a stable state that can be granted, reviewed, and trusted over a session.

Q: How can security teams tell whether IAM maturity is real for machine identities?

A: Look for evidence that the programme can trace ownership, purpose, scope, and retirement for every non-human identity.

Practitioner guidance

  • Rework maturity scoring for non-human access Assess whether your IAM maturity model measures runtime control, entitlement scope, and revocation speed for NHIs and AI agents, not just policy presence and review completion.
  • Inventory machine identities as governed assets Create an ownership, purpose, and retirement record for each service account, API key, token, certificate, or AI agent identity so lifecycle decisions are explicit.
  • Separate human review cadence from machine control Do not rely on periodic access certification to govern identities that can act and disappear inside one workflow.

Bottom line: The article shows that IAM maturity models can overstate control strength when they are built around human review cycles rather than machine-paced identity behaviour.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

Maturity models built for human access cannot measure machine-paced identity behaviour: The article shows that IAM maturity still tends to reward policy completeness, review cadence, and process consistency. Those are useful indicators for human users, but they understate the control gap when AI agents and NHIs can operate across systems faster than review cycles can react. The implication is that maturity has to include runtime governance, not just lifecycle formality.

A few things that frame the scale:

A question worth separating out:

Q: Should organisations use the same access model for humans and AI agents?

A: No. Human access models are built around stable roles and review cycles, while AI agents often need contextual, task-specific permissions that change quickly. Treating them the same usually leads to over-permissioning or constant exceptions. Organisations should separate identity proof from authorization design and apply resource-level controls for agents.

👉 Read our full editorial: IAM maturity models miss the identity shift AI agents create


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.