The PAM blind spot: Where your AI agents are getting breached

Non-human identities (NHIs) are not new. We have run service accounts, scripts and machine credentials for years. What changed is the population. Every automation project and every AI investment adds more of them, and they now sit in the foreground of the security conversation, versus the background.

You have probably seen the ratios in every deck on the topic. One hundred NHIs per human. Two hundred to one. Pick a number. The point in this session was that the exact ratio does not matter much anymore. The scale is a given. What’s key is that the number is never still. NHIs are created and destroyed constantly, and they change far faster than your human headcount ever will.

AI agents raise the stakes again. An agent does not pass a single file or run a single task. It plans, acts, reads the result and moves on, over and over at machine speed, to reach a business outcome. That autonomy is exactly why we are investing in them, but it is also why old controls do not hold.

The assumption that broke

Legacy privileged access management (PAM) was built on one quiet assumption: There is a person behind every action. Identity governance made the same bet, and for a long time that was fine.

It is not fine anymore. When the actor is an AI agent, the intent of the control still applies, but the way you enforce it has to change. Its autonomy, reach and frequency of decisions have outpaced the controls most organizations have in place. That is the gap. And it is safe to assume your investment in agents and NHIs has already moved faster than your security program.

Think about the agentic loop. There is an input, a prompt, some training data, a planning step, an action and a reading of the result. Every one of those stages is an exposure. The model, the data, the action, the prompt.

One example discussed was when an airline ran an AI agent to handle customer conversations. A customer argued they qualified for free tickets under a promotion, and the agent agreed and issued them. When the airline tried to walk it back, the customer's answer was simple: Not my problem.

So, whose problem is it? (The airline's) And who is accountable? (No one takes an AI to court.) Those are the questions agentic access forces into the open.

Three ways to start closing the gap

  1. Govern every agent identity. Discovery matters, but do not start by hunting down every NHI you already have. Start by finding where they come from. Alan used a plumbing analogy: If water is spilling across your house, you plug the leak first, then clean up. Chasing the water while the leak runs is a losing game. In the human world, you point to HR as the source of truth. In the non-human world, there are many sources: line-of-business apps, your DevOps toolchain and the cloud platforms you run on. Map those first. Then bind every agent to a human sponsor. An identity with a non-human owner has no chain of accountability, and sooner or later an auditor will ask who authorized what and why.

  2. Enforce least privilege at machine scale. You will not drive risk to zero, and zero risk is not a real target. What you can do is make manipulation meaningless. A human might check out a credential for an hour, finish the task in five minutes then leave the access sitting there. An agent finishes in seconds. The window to act needs to match that, and not just time-bound privilege, but the whole chain scoped tightly to a single task and revoked the moment it is done. This is where legacy PAM runs out of room.

  3. Record and audit with a circuit breaker. Run the checks before, during and after every task, at speed. You define the purpose, owner and expected outcome so you know what normal looks like. Any deviation triggers a pause and a human review. When risk changes, the circuit breaker cuts the agent off, because one noncompliant action at machine speed will not stay a single action for long. And every step stays recorded and replayable, so you have a real chain of evidence.

It is a fabric, not a single tool

The recurring theme: PAM is foundational, but it is not the whole answer. To get your arms around agentic access, you need PAM, identity governance and administration (IGA) and DevOps working as one fabric. PAM gives you the inventory and operational controls. IGA gives you the business context, ownership and governance model that wraps around it. Tuned for humans, those systems miss agents. Tuned together for agents, they hold.

This is where Safeguard by One Identity fits. It delivers the just-in-time and scoped access the frameworks above call for, with a full API and MCP support built for scale. It manages agentic access, and it also lets AI use it, which closes the old chicken-or-the-egg problem of who governs the privileged tool itself. You can run it as an appliance, as SaaS, on-prem, hybrid, or in the cloud.

What to do Monday morning

An attendee asked the honest question: Agents are already running across my environment with no controls, so where do I start?

First, find out whether you have an identity program or a Center of Excellence, a group that already owns these decisions. If you do, bring them the question. If you do not, take it to your security team. Second, find out where the agents are coming from. That single answer tells you more than any inventory scan.

Alan also offered a diagnostic worth trying. Ask HR how many employees have a start date less than a year old paired with a very recent date of birth. If real human records are being created to stand in for machine access, that query tends to surface it. It happens more than you would think.

Watch the full session

The recording runs about 30 minutes and covers each of these points in more depth, along with a full Q&A.

[Watch on demand]

For the research behind the frameworks in this session, see Gartner's work on machine identity and AI agent taxonomy.

[Link to the Gartner reprint]

Anonymous
Related Content