Why AI Agents Break Traditional Identity Governance (And What To Do About It)
AI agents don't fit the old identity governance model. They're not users, they're workloads — and they need their own lifecycle. Here's what changes when agents enter the picture, and how to stay ahead.
Why AI Agents Break Traditional Identity Governance (And What To Do About It)
Published: 2026-06-24 | Category: Cybersecurity & AI | Reading time: ~7 min | Sources cited below
If you read the first piece in this series 📖, you now know that non-human identities outnumber humans 100 to 1 in cloud-native organisations. 📊 And you've probably accepted that service accounts, API keys, and OAuth apps need governance. ✅
Good. 👍 Now let me tell you why the AI agent layer is making all of that obsolete. 💥
At the AI Agent Security Summit earlier this year 🏔️, Zenity published a finding that every security leader should sit with: agentic workflows now span browsers, open-source tools, identities, and knowledge sources, with persistent permissions that change at runtime. 🌐🔄
Read that sentence twice. 📖📖 Because "change at runtime" is the part your IAM team hasn't figured out how to handle yet. 🧩
The old model was built for static things 🗿
Traditional identity and access management was designed in an era when identities did predictable things. 🧍♂️
- A human logs in 🌅, does some work 💼, logs out 🌇.
- A service account runs a cron job ⏰ at 2am 🕐, accesses the same three tables every time 📊.
- An API key calls the same endpoint with the same payload 🔁, day after day.
Static roles. 👔 Long-lived credentials. 🔑 Session-based trust. 🤝 The entire architecture of enterprise IAM assumes this kind of determinism. 🏛️
Now meet your AI agent. 🤖
Agents don't fit the model 🚫
At NHIcon 2026, David Goldschlag — CEO and co-founder of Aembit — put it bluntly in his keynote 🎤: "Agents are not people, yet they must access the same sensitive systems that humans do." 🧍♂️🤖🔐
That's the paradox. 🎯 An AI agent isn't a human, but it needs to read your CRM 📊, query your data warehouse 🗄️, send emails on your behalf 📧, update your calendar 📅, file tickets in your helpdesk 🎫, and call external APIs 🌍.
And it does all of this with credentials that look exactly like the static service account credentials we've been issuing for 20 years. 🎭
Except the agent doesn't behave like a service account. 🎲 It behaves like a slightly unpredictable intern who reads the entire wiki before answering one question. 📚🤯
What actually breaks at runtime ⚙️
Here's where it gets interesting. 🔍 And a bit terrifying. 😱
Zenity's analysis of the AI Agent Security Summit surfaced several runtime behaviours that traditional IAM simply cannot govern. ❌
1. Permission inheritance through MCP 🧬 When an agent connects to a Model Context Protocol server 🔌, an open-source tool 🛠️, or an identity provider 🪪, it inherits the permissions of every system it touches. 📚 This isn't additive — it's multiplicative. ✖️ An agent with read access to five systems now effectively has cross-system read access that no single IAM policy ever approved. 🎭
2. Natural-language goal changes 🗣️ A human user with a sales role keeps that role until HR changes it. 🧑💼 An AI agent can be told "now act as a finance analyst" 💬 — and within seconds, the goal it was pursuing has completely shifted. 🔄 Your static permission model has no idea this happened. 😶
3. Persistent permissions across sessions 🔁 Agents don't log out. 🌙 They keep their credentials warm. ☕ They maintain access across multiple systems, multiple sessions, multiple days. 📅 The traditional concept of a session boundary — log in, do work, log out — barely applies. 🫥
4. Behaviour that adapts to prompts 🎭 The same agent, with the same credentials, given two different prompts, will take two different actions. 🎯🎯 Your IAM policy says "read access to customer table." 📋 But after a prompt, the agent decides to write. ✍️ Who approved that? 🤷
The lifecycle problem 📉
Here's the question that breaks most NHI programmes today. 💔
Who owns the agent's lifecycle? 👤
Not "who deployed it" — that's the easy part. 🛠️ I mean: when the agent's task is done ✅, when the model is updated 🔄, when the underlying API changes ⚙️, when the business process it serves is retired 📦 — who is responsible for revoking its access? 🛑
For a service account, the answer is usually "the team that owns the application." 👥 For an AI agent, the answer is often... nobody. 🫥
The data team built the prompt. 🎨 The platform team provided the credentials. 🪪 The security team approved the use case. ✅ The business unit wanted the outcome. 🎯
Four teams. 4️⃣ Zero owners. 0️⃣
This is the lifecycle gap. 🕳️ And it's where most NHI breaches will originate in the next 24 months. 📅
What good governance looks like (intermediate level) 🏗️
You're past inventory now. 📋 You know what NHIs exist. 👀 Here's the next layer. 🧅
1. Lifecycle ownership as a first-class concept 👤 Every agent needs a named human owner — not a team, not a Slack channel, a person. 🧑 The person who gets paged at 3am if the agent misbehaves. 📟 Make this a deployment gate. 🚧 No owner, no deploy. ❌
2. Scoped permissions that match intent, not just identity 🎯 Move from "this service account can read X" to "this agent can perform action Y on resource Z for purpose W." 🔍 Intent-based authorisation is harder to build 🛠️ but much harder to abuse. 🛡️ It also makes the audit story clearer when something goes wrong. 📋
3. Revocation paths that actually work 🛑 When an agent is decommissioned, its credentials should die in minutes ⏱️, not months. 📅 Rotation should be automatic 🤖, not "when someone remembers." 🧠 Test your revocation paths quarterly. 🔁 If you haven't tested it, you don't have it. ❌
4. Runtime monitoring, not just provisioning time checks 👁️ You can't govern what changes at runtime with a policy that was set at provisioning. ❌ You need behavioural monitoring 🧠, intent logging 📝, and the ability to kill an agent mid-action. ☠️ This is where the runtime layer matters most. 🎯
5. Short-lived credentials by default ⏳ Stop issuing API keys with no expiry. 🚫 Every credential should have a maximum lifetime. ⏰ Workload identity federation (AWS IAM Roles Anywhere 🔐, Azure Managed Identity 🪪, GCP Workload Identity Federation 🌐) makes this achievable today. ✅ No more 10-year service account passwords. 🚫
6. Continuous exposure detection 📡 Static secrets in code repositories. 💻 Secrets in CI logs. 📜 Secrets in Slack messages. 💬 The exposure surface for NHIs is everywhere. 🌍 Tools that continuously scan for leaked credentials — across code, configs, chat, and cloud — close the gap between creation and detection. 🔍
7. Enforceable revocation mechanisms ☠️ A revocation policy that requires three teams to coordinate is not a revocation policy. ❌ It's a hope. 🌈 Build it so one person can kill an agent's access in under five minutes. ⏱️ Then test that they actually can. 🧪
The uncomfortable truth 😬
Most organisations are not ready for this. ❌
Deloitte's 2025 Global AI Survey found 82% of organisations that deployed AI agents without process intelligence overlay failed to achieve ROI targets. 📉 The same pattern is now emerging for security: organisations deploying agents without governance overlay are creating breach pathways faster than they can document them. 📝
The good news? 🟢 The patterns above are well understood. 📚 The platforms exist. 🏗️ And you don't have to boil the ocean. 🌊 You have to start. 🚀
The capability gap is widening 📐
Here's what keeps CISOs up at night. 🌙
The pace of agent deployment is accelerating. 🚀 Every week, another team spins up another agent — a customer support bot 🤖, a sales assistant 📈, a research agent 🔍, a code reviewer 💻 — each one with its own credentials, its own permissions, and its own blast radius if compromised. 💥
Meanwhile, the governance layer is moving at the speed of committee. 🐢 Quarterly reviews. 📅 Annual audits. 📋 Six-month platform rollouts. 🏗️
The ratio of agents deployed 📈 to agents governed 🛡️ is going the wrong way. 📉 By a lot. 📉
You can't close that gap by adding headcount alone. 👥 You need tooling 🛠️, automation 🤖, and — most importantly — a decision to treat agent governance as a first-class engineering discipline. 🏛️ Not a side project. 🧩
The organisations that figure this out in 2026 will have a compounding advantage. 📈 The ones that don't will be writing breach reports in 2027. 📝
What's coming in the third piece 🔮
The advanced piece goes deep on the platform landscape 🏢 — the ten-plus dedicated NHI platforms that didn't exist as a category 24 months ago 🚀, what they actually do 🛠️, how to evaluate them 🧐, and where the gaps still are. 🕳️
If you're a CISO, an MSP, or a security architect 🛡️, that's where the buying decisions live. 💰
Sources: Zenity — Automation, Intent, and Ownership: AI Agent Security Summit 2026; Zenity — Identity Isn't Enough: AI Agent Security Requires Runtime Context; GitGuardian NHIcon 2026 recap; Aembit NHIcon 2026 keynote (David Goldschlag); Microsoft Secure Access Report 2026; Deloitte Global AI Survey 2025; Cremit RSAC 2026 NHI Field Report
Which part of the agent lifecycle are you most uncertain about — ownership, scoping, or revocation? 🤔 That uncertainty is exactly where the next breach will come from. ⚠️