AI lowers the cost of creating believable pretexts, fake personas, and polished communications, which lets attackers reach trust decisions more often. Once an organisation depends on informal approval, email confidence, or static onboarding checks, those controls become easier to manipulate. The risk is not new logic, but a much higher volume of convincing deception.
Why This Matters for Security Teams
AI changes the economics of social engineering and identity abuse. It can produce convincing emails, chat messages, voice scripts, and support conversations at scale, so attackers no longer need to rely on obvious spelling mistakes or poor impersonation. That matters because many identity and access decisions still depend on human judgement, loosely defined approval chains, or trust signals that are easy to simulate. Security teams often assume the weak point is the technology stack, when the real weakness is the decision path around it.
For this reason, controls need to focus on the trust boundary, not just the channel. Stronger identity proofing, phishing-resistant authentication, step-up verification for sensitive actions, and tighter approval workflows all become more important when deception can be automated. Guidance in NIST SP 800-53 Rev 5 Security and Privacy Controls remains useful because it anchors access control, authentication, and auditability in specific control outcomes rather than informal process expectations. In practice, many security teams encounter bypasses only after a believable pretext has already converted a human approver into an access grant.
How It Works in Practice
AI makes bypass easier by compressing the attacker effort needed to reach a trusted decision. A threat actor can quickly tailor messages to a role, reuse public context from social media or company sites, and create a polished narrative that appears consistent across email, chat, and voice. That can defeat weak verification methods such as knowledge-based checks, informal manager approvals, or manual help desk resets that rely on confidence rather than evidence.
The practical defence is to reduce the number of places where a person can be tricked into becoming the control. That means pairing identity verification with technical enforcement and making privileged or sensitive actions require stronger signals than a single conversation or one-time approval. Controls often include:
- Phishing-resistant MFA for users who can approve access or reset credentials.
- Step-up verification for password resets, payment changes, token issuance, and role escalation.
- Bounded approval workflows with logged evidence, not free-text sign-off in email or chat.
- Short-lived, least-privilege access for administrators and service identities.
- Monitoring for unusual request patterns, rapid privilege changes, and new device or location use.
For identity-heavy environments, this also intersects with non-human identity governance. If AI systems, automation, or agentic workflows can request access, then organisations need to control the secrets and tokens that let those systems act. The OWASP Non-Human Identity Top 10 is useful because it highlights how unmanaged credentials, long-lived secrets, and weak lifecycle controls create bypass paths that are just as dangerous as human deception. These controls tend to break down when access decisions are split across many tools with inconsistent logging, because attackers only need one weak approval path to succeed.
Common Variations and Edge Cases
Tighter identity controls often increase friction for legitimate users, requiring organisations to balance stronger assurance against support overhead and user experience. That tradeoff becomes more noticeable in customer-facing environments, high-volume service desks, and merger or contractor onboarding flows where speed has real business value.
There is also no universal standard for how much AI-specific verification should be added on top of existing identity governance. Current guidance suggests focusing first on the actions that create the highest blast radius, such as privileged access, financial changes, and secrets issuance. In those cases, a simple confirmation step is not enough if the underlying channel can be imitated by AI-generated text or voice. The better design is to make the approving party verify through a separate, harder-to-spoof control path.
Operationally, this means some environments will need stronger controls than others. A cloud platform team administering tokens and automation should treat access changes differently from a low-risk internal directory update. The same is true for regulated payment environments, where PCI DSS v4.0 and CIS Controls v8 both reinforce authentication discipline, logging, and least privilege. Where governance is mature, organisations can align these practices with ISO/IEC 27001:2022 Information Security Management to keep identity controls tied to risk, not convenience.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack surface, NIST CSF 2.0 set the technical controls, and PCI DSS v4.0 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-1 | AI-driven deception targets trust decisions and access granting. |
| OWASP Agentic AI Top 10 | Agentic workflows can amplify social engineering and approval abuse. | |
| OWASP Non-Human Identity Top 10 | AI systems often rely on secrets that attackers can exploit after deception. | |
| PCI DSS v4.0 | 8.4 | Payment environments need stronger authentication against impersonation. |
Restrict access requests to verified identities and separate approval from informal communication channels.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 18, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org