As organisations are increasingly using, or at least experimenting with, AI agents including autonomous workflows, an important identity security question seems to be surfacing.
Can we govern AI agents using the same identity and access governance (IGA) approaches we’ve used for the last 20 years?
(And yes, whilst I'd claim no part in setting that approach, I've certainly been in and around it for all those years!)
I've observed that many vendor narratives implicitly suggest a straightforward answer - AI agents are just another form of non-human identity.

Author:
Paul Dawson
Chief Services Officer at CyberIAM
This means bringing them into existing IGA platforms, applying lifecycle management, enforcing least privilege, running access certifications, etc., which would seem to make sense, and is rather convenient.
There’s logic to treating AI agents as just another identity type - very early on in our 20-year journey we included NHIs (initially service accounts) in the mix, so adding AI agents doesn’t feel like a leap.
Implicitly, the message is:
This is the same problem, just at greater scale and pace of change.
Of course, many of the core principles still hold - least privilege, accountability, visibility - but increasingly my feeling is that this view glosses over two important shifts happening at the same time; two shifts that may necessitate a change in the model.
1) AI agents don’t behave like traditional identities.
They:
- Can act autonomously
- Make decisions
- Operate continuously
- Evolve over time
Humans can behave like this, but there are surely real differences, and this alone starts to stretch traditional IGA.
2) Control is moving to runtime
Increasingly, organisations are moving towards, or would like to move towards:
- Policy enforcement at runtime
- Continuous authorisation
- Just-in-time (JIT) access
- Zero standing privilege (ZSP)
In this model, access is not granted once and reviewed later. Instead, it is evaluated continuously based on context, behaviour, and risk.
Again, this trend isn't necessarily specific to non-humans or agents, but it feels like it might be the only way to deal with the pace and scale of agents.
It does however raise a more fundamental question:
If access is decided at the point of use, what role does traditional IGA play?
This is because AI agents:
- Act in real time
- Take decisions dynamically
And runtime policy:
- Evaluates access in real time
- Enforces controls dynamically
One can argue that traditional constructs like static roles, periodic access reviews, and pre-defined entitlements start to feel… less relevant as primary controls.
Consider one or more AI agents in a traditional organisation that can create suppliers, approve invoices and trigger payments. Our current version of identity governance can ensure ownership, accountability and policy are defined, but the actual access decision may need to be evaluated every time the agent acts. At that point, governance and runtime enforcement become distinct but complementary controls.
Had we really nailed IGA?
There’s also something else worth acknowledging.
Traditional IGA never fully solved the problem at scale anyway. To be clear, this wasn't a technology problem, but few can deny that in many, many organisations:
- Access models became overly complex
- Role-based approaches struggled to keep up
- Certifications often became tick-box exercises
- Onboarding applications took years
So, as we look at AI agents and think “can our existing model cope?” it’s worth asking:
Did it really cope or fully address our control needs in the first place?
Here's my take (for now!)
I don’t think this is as simple as “AI agents are just identities” or “IGA is obsolete.”
My view is that the arrival of AI agents, and the need to move towards runtime authorisation are together shifting identity governance away from static control and towards real-time decisioning.
"Traditional" IGA absolutely still matters, because it allows for...
- Defining ownership
- Establishing accountability
- Setting policy intent
But it is no longer where control primarily happens (or needs to happen). That control increasingly must be:
- Policy-driven
- Enforced at runtime
- Granted just-in-time
- and removed just as quickly
If we can get there, that approach can actually reduce the governance overhead that has historically made IGA so difficult to operate at scale.
In conclusion...
Can we govern AI agents with traditional identity governance?
Apologies for a bit of fence perching but for me the answer is partially. But not in isolation.
The three realities we face are:
1) AI agents increase complexity
2) Continuous authorisation changes the control model
3) Traditional IGA, as we’ve known it, was already under strain
We shouldn’t be discarding traditional identity governance but perhaps rethink its role to be more about owning the control and defining intent and accountability, while the real-time controls become the enforcement mechanisms…because we never really got to the enforcement bit anyway.
The rise of AI agents coincides with a broader shift in how we wish to control access - dynamic identities, ephemeral access and pace of change means that identity governance doesn’t go away, but it does need to evolve from periodic oversight to part of a real-time control model.
I think we were all coming to the realisation that that change was needed anyway.
You can contact CyberIAM to discuss how your organisation can build identity-first controls into its AI strategy from day one. Simply fill in this very quick form!
Get in touch
If you would like more information about CyberIAM’s Services offering,
contact us here and a member of our specialised team will be in touch as soon as possible
Current State Assessment guide
Access our comprehensive current state assessment guide to discover how we
initiate our end-to-end analysis, setting the foundation for providing you with the best possible advice.

