ai-compliancetrade-pressNewsThe Broadside3 min read

NIST flags credential-sharing, HITL gaps in agentic AI push

Early agentic AI deployments are repeating the security-by-omission pattern of early cloud adoption, and NIST's NCCoE is surfacing the identity-and-authorization blind spots before the market locks in.


TL;DR

NIST's NCCoE is launching a project on identity and authorization controls for agentic AI, drawing on public comments and stakeholder engagement that surfaced three recurring problems: users sharing personal and enterprise credentials with AI agents, agents running under local user accounts with broadly scoped access, and reliance on human-in-the-loop controls that current deployments can saturate. The project aims to produce reference designs and an online resource hub showing how existing identity standards and best practices can reduce risk. No timeline or specific control recommendations have been released, and it's unclear whether eventual guidance will be advisory or mandatory for federal contractors and critical infrastructure operators.

NIST's Bill Fisher and Ryan Galluzzo published a blog post on August 27 that lays out the identity and authorization problems the National Cybersecurity Center of Excellence is hearing about as it shapes an upcoming agentic AI project. The post draws on public comments to the NCCoE's February 2026 concept paper and on "extensive engagement with stakeholders in the agentic AI ecosystem." The diagnosis is blunt: "early agentic deployments are repeating a familiar pattern: prioritizing feature development and immediate value over security."

The post walks through three failure patterns that are already showing up in production.

Credential sharing is the default, not the exception

"Individuals giving their personal and enterprise credentials to agents has quickly become a common pattern," Fisher and Galluzzo write. The problem isn't merely sloppy hygiene, it creates accountability gaps that matter in regulated sectors. "This is particularly true for sectors that require non-repudiation as a core security feature, such as in financial transactions or the sharing of health information." Consumer-facing scenarios compound the difficulty: enterprises have "little to no control over the agentic identity and may struggle to distinguish an agent from a human, especially if user credentials are shared with the agent, allowing for user impersonation."

The authors note that the FIDO Alliance is exploring agent authenticators bound to user identities, but "this work is still in early phases." And they acknowledge the incentive problem plainly: "for consumer scenarios, the 'secure path' will also need to be the 'easy path' or credential sharing and impersonation will continue to proliferate."

Local accounts give agents too much runway

The second pattern: deploying agents with local user accounts. "While this deployment model is convenient, and many developers prefer to work locally, giving agents local account access allows the agent to both impersonate the user and act with broadly scoped access." The downstream consequences include undermined non-repudiation when agents act without the user's full understanding or consent, and a structural barrier to centralized identity management, local deployments "encourage other challenging IAM practices such as static credentials that are stored in local files."

Human-in-the-loop is a checkbox, not a control

The third pattern is the one the post treats most delicately. "Many still see Human-in-the-Loop (HITL) as a fundamental element of agentic control," Fisher and Galluzzo write, but they frame it as a design problem that echoes earlier IAM history: "durable agentic identity and authorization design requires enterprises to consider both the usability and security considerations for HITL." The post doesn't call HITL useless, but it positions it as insufficient by itself, a pattern that the NCCoE project will need to address through reference designs rather than assumptions.

The NCCoE plans a series of follow-up blog posts, with the next installment promising to "highlight some of the identity and authorization principles necessary for durable agentic design." An online resource hub and NIST publications are also in the pipeline, all aimed at demonstrating how existing identity standards and best practices can be applied to agentic architectures. The concept paper that launched this work closed its public comment period on April 2, 2026, and the project is part of the broader AI Agent Standards Initiative NIST announced in mid-February 2026.


Published ·Deep Fathom