What's Happening?
Akto has released a Non-Human Identity (NHI) Security Guide for AI Agents, addressing the unique security challenges posed by AI agents compared to traditional service accounts. NHI refers to digitized identities for machines, such as service accounts,
API keys, and OAuth tokens. While traditional NHI governance assumes predictable actions, AI agents operate with dynamic reasoning, making their actions difficult to predict and govern with conventional tools. This guide highlights that AI agents can make decisions on the fly, choose tools, and generate new behaviors, breaking the assumption of fixed functions. The core problem areas identified are ungoverned and persistent access, overly permissive default access, and a lack of clear ownership or audit trails for AI agents. Akto proposes a 'blended identity' model that continuously validates both the agent's identity and its delegated authority at the time of action.
Why It's Important?
The proliferation of AI agents in business and government systems introduces significant security vulnerabilities if not properly managed. Traditional security models are ill-equipped to handle the dynamic and unpredictable nature of AI agent behavior, leading to potential over-privileging and an expanded 'blast radius' if compromised. A single compromised AI agent could combine the capabilities of multiple tools, potentially escalating privileges or creating new, unauthorized behaviors. This guide is crucial for organizations adopting AI, as it provides actionable insights to build effective NHI security programs. Without robust security frameworks, the benefits of AI integration could be overshadowed by severe data breaches, operational disruptions, and compliance failures, impacting sensitive data and critical infrastructure. The shift from fixed-function governance to dynamic, context-aware authorization is essential for secure AI deployment.
What's Next?
Organizations will need to implement a four-step process for building NHI security in agentic systems: discovery, policy, evaluation, and violation triage. Discovery involves inventorying all AI agents, their models, deployments, and associated credentials, including those created by other agents. Policy development will focus on defining least-privilege authorizations and time-bound delegations with clear expiration and renewal policies. Runtime evaluation will be critical to continuously check an agent's authorization for every action, detecting and capturing the decision-making context of anomalous behaviors. Finally, violation triage will establish severity levels and response procedures for unauthorized actions, ensuring accountability. The industry will likely see increased development of tools and frameworks, like Akto's 'Identity for AI agents' product, designed to discover, govern, and secure this new category of non-human identities, emphasizing token segregation, expiration tracking, and rotation enforcement.
Beyond the Headlines
The emergence of NHI security for AI agents signifies a fundamental shift in cybersecurity paradigms. It moves beyond securing human users and predictable machine processes to managing autonomous entities with evolving behaviors. This raises profound questions about the nature of digital identity and trust in automated systems. The concept of 'blended identity'—validating both the agent and its delegated authority—underscores the need for granular, context-dependent access controls. This evolution will necessitate new regulatory frameworks and industry standards to ensure responsible AI deployment. Furthermore, the challenge of distinguishing legitimate anomalous activity from malicious behavior in AI agents will push the boundaries of anomaly detection and threat intelligence, requiring more sophisticated AI-driven security solutions to monitor and protect AI systems themselves.










