Celent has released a new report, entitled Identity and Access Management in Agentic Systems in two parts, the first covering banking and the second, the insurance sector.
Ask the Chief Information Security Officer (CISO) at a financial institution (FI) how many employees have access to the core banking or policy admin system and the answer comes back within the hour. Ask how many AI agents have access to the same systems, provisioned by whom, and acting under whose authority, and the honest response in many FIs today is silence.
Traditional Identity and Access Management (IAM) tooling has been designed for predictable integrations with actors demonstrating known and relatively narrow behaviours. It has not been designed to deal with large language models capable of taking actions its own designers cannot fully enumerate in advance and deciding in real time what to do next based on context that may include content it was never meant to trust.
Access deeper industry intelligence
Experience unmatched clarity with a single platform that combines unique data, AI, and human expertise.
The challenge is no rounding error
Machine identities now outnumber human ones across enterprise environments. Many are created by development teams with no formal policy governing how they’re reviewed or retired. Surveys of enterprise security leaders consistently find that the majority have no formal policy governing how AI identities are created, reviewed, or retired. A similarly large majority openly doubt that their existing IAM tooling can manage the risk agents now represent.
Celent argues that this is one of the reasons why many agentic AI use cases live today — drafting and fixing correspondence, summarising, generating first-pass content — sit in a category that is genuinely low-risk and correspondingly low-impact. It’s useful, but it’s not moving the needle on cost or capacity in the way agentic AI is supposed to. Extending and scaling agentic pilots into truly impactful areas is difficult when you don’t have a better approach to identity controls than sharing existing human credentials and access tokens with agents.
The case for extending IAM
This report makes the case for extending IAM into Agent Identity and Access Management (AIAM) — a discipline built around three questions traditional IAM was never designed to answer in combination: Who created the agent, whom does it represent, and what is it actually authorised to do? While related, AIAM addresses slightly different challenges than the emerging Know Your Agent (KYA) protocols, which are being designed to help recognise external agents knocking at the institution’s doors.
What’s Celent’s angle?
The report is structured around the practical architecture that follows from those three questions. It covers the agent identity lifecycle, including the shadow-agent problem created when business teams commission agents outside the identity function’s knowledge, and the case for the “digital identity twin” model most FIs are likely to converge on for agent ownership. It sets out why least privilege needs to move from a provisioning-time discipline to runtime authorisation, and walks through OAuth 2.0 Token Exchange (RFC 8693) as the emerging mechanism for issuing short-lived, task-scoped tokens rather than reusing standing permissions.
It addresses the multi-hop delegation problem created when agents spawn sub-agents — a genuine gap in existing privileged access management tooling — and the permissioning challenges that arise the moment a customer relationship involves more than one person, from joint accounts to a corporate representative with an authority ceiling.
Two external forcing functions are examined in detail because they arrive on timelines FIs don’t control: the EU AI Act’s Article 50 transparency obligations and Annex III high-risk provisions for credit scoring and mortgage affordability tools, and the payments industry’s fast-moving Know Your Agent protocols that will govern agentic commerce.
The report closes with five actions for the next twelve months. None of the five requires waiting for the standards landscape to settle.
Further information on how to access the full banking edition report is available via this link and for insurance, via this link.
