The real operational hazard is not the novelty of autonomous software, but the accumulation of non-human identities that already hold the authority those systems need. Service accounts, API keys, and tokens have long been treated as plumbing, so governance has lagged behind their actual privilege. That mismatch matters because agentic systems inherit whatever access is already available. If identity controls were built for people and only loosely adapted for automation, the result is broad authority with weak accountability, exactly where attackers look first.
The mechanism is straightforward: these agents act inside granted permissions, so any excess privilege or stale credential becomes a force multiplier. When workflows span applications and data sets, minor configuration flaws do not stay minor; they propagate at machine speed and can expose data or extend processes beyond their intended scope. The practical takeaway is not to invent new security theory, but to apply disciplined identity management: unique identifiers, tightly scoped permissions, clear ownership, frequent review, persistent policy controls, monitoring, and automated suspension when risk rises.
The limits are just as important. The source does not claim that every automated workload is dangerous, only that unmanaged identity sprawl turns useful automation into an expanding control problem. Real risk comes from orphaned identities, long-lived credentials, and governance added after authority has already been granted. Practitioners should read the message as a warning against treating access as a one-time provisioning task. If control does not evolve with deployment, scale itself becomes the vulnerability, and containment gets harder over time.
The quiet rise of non-human authority
Traditional identity programs were built around people. They incorporate structured onboarding, defined roles, periodic reviews and clear accountability to manage human users through the cycle of their access and responsibilities within the enterprise. But non-human identities (NHIs) are often overlooked by these governance processes. They persist quietly in the background, often are provisioned as part of administrative activities to keep systems running, and are often granted long-term credentials with elevated permissions — providing rich targets for attackers. As with human identities, there are best practices, such as least-privilege permission assignments and frequent credential rotation, that can help better secure the use of these NHIs. Applying appropriate governance processes to the creation, daily use and ongoing maintenance of NHIs can help ensure secure automation and more effective control. When automation within enterprises was limited and tightly scoped, this gap may have carried less consequence. Today, it holds far more weight as AI agents are instantiated, execute processes and interact across systems, coordinating workflows and advancing tasks without an integral human role.When NHIs act, weak controls scale fast
Agentic systems are designed to take action, retrieve data, interact with internal systems and move workstreams forward within the permissions they are granted. A recent report from Deloitte found that nearly three-quarters of 3,325 leaders surveyed plan to deploy agentic AI within two years. As those systems interact across applications and data sets, the scope of their authority matters even more. When permissions are overly broad or poorly governed, AI agents amplify those weaknesses at machine speed. Sensitive data may have greater exposure than intended, workflows may extend beyond their original design assumptions, and minor configuration gaps can cascade into larger operational risk. The issue is not simply the risk of breach; it’s the scale at which unintended outcomes may occur. The measures needed to secure AI agents are not conceptually new. Many of the principles applied to human users — least privilege, defined ownership, periodic review — remain directly applicable to NHIs. What changes is the consistency and coordination required when those principles are extended to non-human actors operating continuously and at scale. In practice, that includes:-
Define: Assigning each agent a unique identifier and establishing tightly scoped, purpose-driven permissions for both human and non-human actors supporting agent workflows.
-
Assess: Assigning clear ownership and ongoing review processes for NHIs to prevent orphaned identities, stale credentials and permission sprawl.
-
Enforce: Protecting sensitive data through encryption and persistent policy controls that remain enforced, regardless of how or where the data is accessed.
-
Detect: Monitoring access patterns and behavioral access changes to surface unusual activity or drift from expected norms.
-
Automate: Enabling automated response capabilities that can restrict access or suspend credentials when risk thresholds are met, without disrupting essential operations.
Security that doesn’t tax velocity
Enterprises are investing in agentic systems to streamline operations, reduce manual effort and accelerate decision-making. The objective of identity and access management strategies for agents is not to slow that momentum, but to ensure that expansion happens in a controlled and sustainable way to not scale risk. When agents are securely developed, provisioned with clearly bounded authority and monitored alongside the data they access, organizations gain confidence to expand deployment and scale automation innovation with their business. Risk doesn’t disappear, but it becomes more visible and governable, rather than compounding quietly over time until it becomes too significant to easily contain. NIST’s request for input reflects an industry still formalizing standards around agentic systems, but organizations can’t afford to wait for finalized frameworks before acting. Agentic AI is already advancing into core business processes. How successfully it scales will depend on whether governance evolves in parallel — ensuring agents operate within defined identity boundaries, with data protection intentionally integrated at every stage.Enjoyed this article? Sign up for our newsletter to receive regular insights and stay connected.

