Securing agentic AI identities in Indian BFSI: why autonomy doesn’t transfer accountability
By Unique Performance Techsoft | Identity Security Insights
Somewhere in your organization right now, an AI agent may be reviewing a credit application, triaging a fraud alert, or provisioning a cloud resource. It authenticates to your systems, holds credentials, calls APIs, and takes actions — just like an employee with privileged access.
Except no one interviewed it. No manager reviews its access quarterly. And when it’s decommissioned, there may be no offboarding process to revoke what it could touch.
This is the defining identity security question of 2026: where are your AI agents, what can they access, and what can they do?
AI agents are a new class of privileged identity
For years, identity security has dealt with two populations: humans (employees, contractors, administrators) and machines (service accounts, API keys, certificates, workloads). AI agents are something new — they combine the reasoning and autonomy of a human user with the scale and velocity of a machine identity. That means they inherit the risks of both:
- Human-identity risks: excessive privileges, credential compromise, session hijacking, social engineering (in the form of prompt injection)
- Machine-identity risks: hardcoded secrets, stolen API keys, unmanaged lifecycle, no clear owner
The scale problem is already here. CyberArk’s 2025 Identity Security Landscape found that machine identities outnumber human identities by more than 80 to 1 — and that while 42% of machine identities hold privileged or sensitive access, 88% of organizations still define “privileged user” as human-only. AI agents will accelerate this gap dramatically.
The adoption curve in financial services is steep. CyberArk’s research on securing agentic AI found that nearly 40% of financial institutions already have agentic AI in production, yet fewer than 10% of organizations have adequate security controls for it. In India specifically, a 2025 Nasscom report noted that over 64% of BFSI leaders have already piloted agentic AI for underwriting, fraud detection, and customer service.
Gartner has put a number on where this leads: it predicts that by 2028, 25% of enterprise breaches will be traced back to AI agent abuse.
Where the risk actually lives
The threats to agentic AI systems are not hypothetical. They map to well-understood identity attack patterns — amplified by autonomy:
1. Over-privileged agents. Teams under delivery pressure grant agents broad, standing access “to make it work.” An agent that can read a loan book, write to a CRM, and send emails is a lateral-movement engine if compromised.
2. Secrets sprawl. Agents authenticate to tools and data using API keys, tokens, and certificates. These often end up hardcoded in agent configurations, prompt files, or CI/CD pipelines. GitGuardian’s State of Secrets Sprawl 2026 report found 28.65 million new hardcoded secrets were added to public GitHub commits in 2025 alone — a 34% year-over-year increase.
3. Prompt injection and tool poisoning. Because agents act on natural-language input, a malicious document or email can become an instruction. The EchoLeak vulnerability (CVE-2025-32711) against Microsoft 365 Copilot demonstrated zero-click data exfiltration through exactly this vector.
4. Insecure agent-to-tool plumbing. The Model Context Protocol (MCP), now the de facto standard for connecting agents to enterprise tools, was designed for interoperability first. Gartner analysts have cautioned that MCP’s flexibility means security mistakes can manifest without continuous oversight, and Gartner projects that 25% of enterprise GenAI applications will experience at least five minor security incidents per year by 2028.
5. Orphaned and shadow agents. Agents spun up for a pilot, forgotten, and left running with live credentials — the AI-era equivalent of the unmonitored service account that has featured in so many breach post-mortems.
What Indian regulators require
For Indian BFSI, this is no longer just a security conversation — it is a regulatory one. The message from every regulator is consistent: autonomy does not transfer accountability.
RBI — FREE-AI Report (August 2025). The RBI’s committee report on Responsible and Ethical Enablement of AI sets out seven guiding “Sutras,” including Accountability — stating that regulated entities should be accountable for the decisions of their AI systems regardless of the level of autonomy of those systems. It calls for board-approved AI policies, AI system inventories, model risk management, and controls for AI-specific threats such as data poisoning and adversarial attacks. While advisory today, it signals clear supervisory direction.
SEBI — AI Cybersecurity Advisory (May 2026). SEBI’s advisory to regulated entities mandates least-privilege access and Zero Trust Network Architecture for AI systems, and asks entities to prepare long-term plans covering autonomous and agentic mitigation. This builds on the SEBI (Intermediaries) Amendment Regulations, 2025, which hold regulated persons solely responsible for the outputs of AI tools — whether developed in-house or procured from vendors. SEBI CSCRF already requires monitoring of privileged access, API security controls, and SOC efficacy for existing entities.
IRDAI. Guidelines for insurers extend access-control, encryption, and anomaly-detection requirements to AI models used in underwriting and fraud detection.
The practical implication: if an AI agent in your environment misuses access, exfiltrates data, or executes an erroneous transaction, the regulatory liability sits with you — not with the AI vendor, and certainly not with the agent.
Securing agents like the privileged identities they are
The good news: the discipline for this problem already exists. It is Privileged Access Management — extended to a new identity class. A defensible agentic AI identity program covers five stages:
1. Discover and inventory. You cannot secure agents you don’t know exist. Build and maintain a live inventory of every AI agent, its owner, its purpose, and its entitlements — including pilots and shadow deployments. (This also directly satisfies RBI FREE-AI’s AI-inventory expectation.)
2. Assign ownership. Every agent needs a named human owner accountable for its access, behavior, and lifecycle — exactly as regulators expect.
3. Enforce zero standing privileges. Agents should hold no permanent entitlements. Access should be granted just-in-time, scoped to the specific task, and expire automatically. Secrets and credentials used by agents should be vaulted, rotated, and never hardcoded.
4. Monitor and contain. Agent sessions should be observable and auditable in real time, with the ability to detect anomalous behavior — an agent suddenly querying data outside its mandate — and a kill switch to terminate a rogue agent’s access instantly. Enforcement points such as CyberArk’s AI Agent Gateway sit between agents and the tools they call (including over MCP), applying privilege controls at the moment of action.
5. Decommission deliberately. When an agent is retired, its credentials, tokens, and entitlements must be revoked as part of a formal offboarding process — preventing the orphaned-agent problem before it starts.
Vendor ecosystems are converging on this model. CyberArk launched its Secure AI Agents Solution to apply identity security controls across the agent lifecycle; Microsoft’s Entra Agent ID brings agents under conditional access and identity protection; Okta has proposed protocols for cross-application agent access. The direction of the industry is unambiguous: AI agents are privileged identities, and they must be governed as such.
Where to start
Most BFSI organizations we speak with are somewhere between “we have pilots running” and “we don’t actually know how many agents we have.” Both are normal — and both are fixable. A practical first step is an agentic AI readiness assessment:
- Discover every AI agent and AI-integrated workflow in your environment
- Map each agent’s credentials, entitlements, and data access against least-privilege
- Identify hardcoded secrets and unmanaged tokens in agent configurations
- Benchmark your controls against RBI FREE-AI, SEBI CSCRF, and IRDAI expectations
- Produce a prioritized roadmap to bring agents under privileged access governance
As a CyberArk Gold Partner with deep implementation and managed-services experience in Indian BFSI — spanning PAM, machine identity, and secrets management — Unique Performance Techsoft helps regulated enterprises extend the identity security controls they already trust to the newest identity class in their environment.
Your AI agents are already working. The question is whether they’re governed.
Talk to our identity security team about an agentic AI readiness assessment.
