When your biggest security risk has never signed a contract | Computer Weekly
Summary
The article argues that agentic AI and nonhuman identities (NHIs) are reshaping the identity perimeter and exposing fundamental gaps in traditional IAM, which was built for human lifecycles. It explains the 'semantic pivot' risk where authorised agents use valid permissions to perform unintended actions and shows why existing logs and permission models cannot prevent this. The author calls for intent-bound authorisation, continuous behavioral monitoring, fine-grained dynamic guardrails, and cryptographically signed intent manifests to contain autonomous agents. The piece also stresses assigning and training a human sponsor for legal and operational accountability under regimes like the UK SMCR, EU AI Act and DORA to ensure oversight before agents enter production.