Join our Newsletter — 33% off our NHI Course

The NHI & Agentic AI Summit – The Next 24 Months – IDV 2026

Session 7: The Next 24 Months — Predictions on Where NHI & Agentic AI Security Goes Next | Non-Human & Agentic AI Identity Summit @ Identiverse 2026

Speakers: Lalit Choda, CEO & Founder, NHI Management Group | Amir Ofek, Co-Founder & CEO, Aizome | Eve Maler, Founder, Venn Factory | John Yeoh, Chief Scientific Officer, CSA

In the closing session of the Non-Human & Agentic AI Identity Summit at Identiverse 2026, some of the most experienced voices in identity security — including one of the co-creators of SAML — make their predictions for where NHI and agentic AI security is heading over the next 24 months, and which of the controls the industry currently relies on are most likely to fail first.

Eve Maler opens with a prediction that shifts the frame of the entire conversation. The industry has been focused almost entirely on protection — credentials to manage, access to control — but within 24 months the conversation will broaden to treat AI agents as entities with something closer to human-like qualities in commercial contexts. That shift, she argues, will be accelerated by regulation that begins to apportion liability around agent actions in a clearer way, similar to how consumer credit card liability is capped in the US. Once liability clarifies, risk models become simpler and the governance picture consolidates.

Amir Ofek’s prediction follows directly: the agent-builder is no longer the developer. Within the next 24 months, every employee in an organisation will be capable of building and deploying AI agents through enterprise tools like Microsoft 365 and similar platforms. The BYOD parallel is apt — organisations will need to develop a bring-your-own-agent framework, because the alternative is attempting to govern an explosion of agent creation that has already outpaced centralised control.

John Yeoh raises the prediction that carries the most immediate operational weight. The threat isn’t just rogue agents or compromised credentials — it’s well-governed agents, with valid controls and validated credentials, doing things nobody expected. Next-generation AI models are already capable of chaining low-level CVEs together to produce high-impact exploits. The same capability applied in production, by agents that organisations believe are properly controlled, will produce a wave of unintended data exposures and IP leakage. The governance practices that exist today are not built for what these systems can do.

On the emerging attack surface, Amir Ofek identifies intent drift as the core vulnerability. Agents are not deterministic — they are designed to change their behaviour in response to context, and a threat actor who understands that can manipulate an agent’s intent over time in ways that are far harder to detect than a straightforward credential compromise. John Yeoh adds the over-privileging problem: when humans build agents, they tend to assign them the same credentials they themselves hold. A human with excessive privileges doesn’t necessarily use them all. An agent will use every key it’s given, everywhere it can, all the time.

Eve Maler sharpens the intent discussion with a harder-edged warning. The industry is at risk of treating intent as an authorization problem — and it isn’t. Intent corruption through prompting is already demonstrable with current models, and it is impervious to finer-grained authorization controls or closer approaches to zero standing privilege. Those things are worth doing, but they don’t address the intent problem. She names this directly: the tendency to look for solutions where the light is rather than where the problem actually sits.

On controls, the panel’s assessment of what breaks first is blunt. John Yeoh identifies lifecycle management — already weak for traditional NHIs, as the CircleCI and Microsoft Midnight Blizzard incidents illustrated — as the first domino to fall in an agentic environment where agents are spun up and down at machine speed, often by other agents. Amir Ofek adds that the leaver scenario is particularly dangerous: when an agent’s owner leaves the organisation, the agent doesn’t leave with them. A poorly governed agent with no active owner becomes a loose cannon with whatever access it was originally granted. Eve Maler points to delegation chains running north-south — deep, branching, multi-hop — as the area where existing controls are least prepared. Token exchange works reasonably well east-west across microservices. It does not have the same maturity when applied to the depth and volume of agent-to-agent delegation that agentic architectures produce.

When asked for the single most important control to focus on, the answers are revealing. Amir Ofek says intent. John Yeoh says asset management — understanding what is in your agentic harness matters as much as understanding what the agent is doing. Eve Maler reframes the question: this is as much an appsec problem as it is an IAM problem, and the supply chain controls that come from that world are directly relevant.

The session closes with each panellist naming the one thing organisations will most regret not starting immediately. Eve Maler: define your metrics now, specifically mean time to contain on agent actions, so that you have a clear operational measure of whether your controls are working before a breach forces the conversation. Amir Ofek: get visibility into every AI agent already running in your organisation — they are there whether you know about them or not, and you cannot govern what you cannot see. John Yeoh: understand your agent and kernel systems from an asset management perspective before vendor lock-in makes that impossible — the ecosystem consolidation happening around AI development tools is moving faster than it did in cloud, and the window to establish portability and visibility is closing.