Search engine for discovering works of Art, research articles, and books related to Art and Culture
ShareThis
Javascript must be enabled to continue!

Non-Human Identity and Access Management for Agentic AI

View through CrossRef
<p>Background. Identity and access management was designed for human users, and a modest population of long-lived service accounts, yet agentic artificial intelligence has inverted the population it must govern. Non-human identities, comprising service accounts, OAuth tokens, API keys, certificates, and now autonomous AI agents, already outnumber human identities in the enterprise by a factor commonly estimated at twenty-five to fifty, and the ratio is accelerating as agentic deployment scales through 2026. Contemporary breach data confirms the consequence: most security incidents now involve machine identities; the 2026 Verizon Data Breach Investigations Report singles out service and machine accounts as the likely locus of compromise in an agentic future; and high-profile token-based intrusions have propagated across hundreds of downstream environments via compromised non-human credentials.</p> <p><span>Purpose. </span><span>This paper argues that the central security problem of agentic AI identity is an attribution gap: existing identity infrastructure cannot reliably establish which identity, at which layer of the agentic stack, authorised a given action, because agents create ephemeral, delegated, machine-speed identities whose chains of authority traditional IAM was never built to represent. It develops the claim that resolving this attribution gap is the necessary precondition for any framework that would allocate responsibility across the layered agentic stack, and it positions the gap as the identity-layer foundation of the orchestration liability framework that is the subject of the author's doctoral work.</span></p> <p><span>Approach. </span><span>The paper adopts a conceptual and standards-review methodology, synthesising the contemporary 2025 to 2026 practitioner and standards literature, including emerging workload-identity primitives (SPIFFE/SPIRE), delegation-preserving authorisation patterns (OAuth 2.0 Token Exchange and the act claim), the OWASP Top 10 for Agentic Applications 2026, the NIST AI Agent Standards Initiative, and zero-trust guidance for non-person entities. It maps the attribution gap onto the three-layer agentic stack used elsewhere in this series and analyses how identity-based access control, least privilege, and the emerging principle of least agency bear on each layer.</span></p> <p>Findings. Three findings emerge. First, the attribution gap is structural rather than incidental: the dominant failure mode, shared credentials across multiple agents, collapses attribution by design, and even well-architected deployments struggle to preserve a verifiable chain of authority across dynamic multi-agent invocation. Second, the technical primitives needed to close the gap, cryptographic workload identity, short-lived and identity-bound credentials, and delegation-preserving tokens, now exist and are converging, but their adoption lags the pace of agentic deployment, producing a widening governance deficit. Third, identity is emerging across the standards landscape as the control plane for agentic security, with OWASP, NIST, and zero-trust guidance converging on identity-centric, least-agency controls, making the identity layer the natural anchor for accountability.</p>
Elsevier BV
Title: Non-Human Identity and Access Management for Agentic AI
Description:
<p>Background.
Identity and access management was designed for human users, and a modest population of long-lived service accounts, yet agentic artificial intelligence has inverted the population it must govern.
Non-human identities, comprising service accounts, OAuth tokens, API keys, certificates, and now autonomous AI agents, already outnumber human identities in the enterprise by a factor commonly estimated at twenty-five to fifty, and the ratio is accelerating as agentic deployment scales through 2026.
Contemporary breach data confirms the consequence: most security incidents now involve machine identities; the 2026 Verizon Data Breach Investigations Report singles out service and machine accounts as the likely locus of compromise in an agentic future; and high-profile token-based intrusions have propagated across hundreds of downstream environments via compromised non-human credentials.
</p> <p><span>Purpose.
</span><span>This paper argues that the central security problem of agentic AI identity is an attribution gap: existing identity infrastructure cannot reliably establish which identity, at which layer of the agentic stack, authorised a given action, because agents create ephemeral, delegated, machine-speed identities whose chains of authority traditional IAM was never built to represent.
It develops the claim that resolving this attribution gap is the necessary precondition for any framework that would allocate responsibility across the layered agentic stack, and it positions the gap as the identity-layer foundation of the orchestration liability framework that is the subject of the author's doctoral work.
</span></p> <p><span>Approach.
</span><span>The paper adopts a conceptual and standards-review methodology, synthesising the contemporary 2025 to 2026 practitioner and standards literature, including emerging workload-identity primitives (SPIFFE/SPIRE), delegation-preserving authorisation patterns (OAuth 2.
0 Token Exchange and the act claim), the OWASP Top 10 for Agentic Applications 2026, the NIST AI Agent Standards Initiative, and zero-trust guidance for non-person entities.
It maps the attribution gap onto the three-layer agentic stack used elsewhere in this series and analyses how identity-based access control, least privilege, and the emerging principle of least agency bear on each layer.
</span></p> <p>Findings.
Three findings emerge.
First, the attribution gap is structural rather than incidental: the dominant failure mode, shared credentials across multiple agents, collapses attribution by design, and even well-architected deployments struggle to preserve a verifiable chain of authority across dynamic multi-agent invocation.
Second, the technical primitives needed to close the gap, cryptographic workload identity, short-lived and identity-bound credentials, and delegation-preserving tokens, now exist and are converging, but their adoption lags the pace of agentic deployment, producing a widening governance deficit.
Third, identity is emerging across the standards landscape as the control plane for agentic security, with OWASP, NIST, and zero-trust guidance converging on identity-centric, least-agency controls, making the identity layer the natural anchor for accountability.
</p>.

Related Results

A Survey on Agentic AI Frameworks for Network Security
A Survey on Agentic AI Frameworks for Network Security
The development of the new category of the AI-driven systems called the Agentic AI that represents a paradigm shift in the architectural design of autonomous networked and security...
Exploring Agentic AI in Healthcare: A Study on Its Working Mechanism
Exploring Agentic AI in Healthcare: A Study on Its Working Mechanism
Introduction Rapid advancements in artificial intelligence (AI) have ushered in an era of hyperautomation and intelligent orchestration across multiple engineer...
Agentic AI Systems: Architectures, Autonomy, and Emergent Behaviours
Agentic AI Systems: Architectures, Autonomy, and Emergent Behaviours
<p><b><i><span>Background.</span></i></b><span> Agentic artificial intelligence systems, defined by their capacity to reason, plan, ...
SOCIOCULTURAL IDENTITY POSTMODERN: PROBLEM OF SOCIAL CONSTRUCTION
SOCIOCULTURAL IDENTITY POSTMODERN: PROBLEM OF SOCIAL CONSTRUCTION
Problem setting. The relevance of our study is due to the excessive popularity of the concept of «socio-cultural identity» as a scientific term and tool for studying the postmodern...
Agentic Engagement Siswa: Tinjauan Literatur Sistematik
Agentic Engagement Siswa: Tinjauan Literatur Sistematik
Engagement is the effort that students make by directly contributing to achieving the goal of learning success. Student engagement is considered a predictor of improved learning pe...
A Framework for Building Robust AI Agents
A Framework for Building Robust AI Agents
Agentic AI has evolved from experimental prototypes to a central paradigm for building intelligent systems. While early demonstrations showcase impressive autonomy through tool use...
A Comprehensive Study of Agentic AI Systems
A Comprehensive Study of Agentic AI Systems
Agentic AI is a revolutionary development in artificial intelligence, as it can mimic human behavior, thanks to enabling technology that allows it to act with a level of independen...

Back to Top