Join our Newsletter — 33% off our NHI Course
Home› Guides› Board and CISO Briefing: Agentic AI Identity Risk
Executive Briefing Governance, Risk & Compliance

Board and CISO Briefing: Agentic AI Identity Risk

← All guides
By Lalit Choda, NHI Mgmt Group Updated 26 September 2026 6 min read
On this page

AI agents are being given the keys to business systems faster than organisations are deciding who holds those keys. Agents now read and send email, change records, write and deploy code, and act on behalf of employees and customers. They do so with credentials, and those credentials determine what happens when an agent makes a mistake or is manipulated by an attacker. This briefing is for boards, executives and CISOs. It explains the risk in business terms, the questions leaders should ask, what good looks like, and where to invest first.

The risk in one paragraph

Every AI agent that takes action is a non-human identity: software holding access to systems and data. Unlike traditional automation, agents decide their own next steps and can be redirected by content they read, such as an email, a web page or a document. If an agent holds broad access, a single malicious instruction or an honest error can become a data breach, a fraudulent transaction or a production outage, carried out with legitimate credentials that look like normal activity. The model's intelligence does not set the size of the damage. The agent's access does.

Why this is a board-level issue now

  • Adoption is outpacing governance. Agents are introduced by business teams, developers and SaaS vendors, often without central review. Many are invisible to security teams.
  • Incidents are already happening.
    • A coding agent at PocketOS used an over-privileged token to delete a production database and its backups (analysis).
    • Attackers stole OAuth tokens held by an AI chatbot integration to reach data in over 700 Salesforce customer organisations (Salesloft Drift).
    • A compromised third-party AI tool connected by one employee led to exposure of customer data at Vercel (analysis).
  • Regulation is arriving. The EU AI Act's transparency obligations apply from August 2026, and high-risk system obligations follow in December 2027 and August 2028. Existing rules on data protection, operational resilience (such as DORA) and cyber security (such as NIS2) already apply to agents. See the Agentic AI Compliance Guide.
  • Accountability does not transfer to software. When an agent acts, the organisation remains responsible, and so do the executives who approved its deployment.

Five questions for the board to ask

  1. Do we know how many AI agents we have, and what they can access? A credible answer is an inventory with owners, not an estimate.
  2. Does every agent have a named, accountable owner? Agents without owners are not reviewed, and are not switched off when projects end.
  3. If one of our agents were hijacked tomorrow, what is the worst it could do? The answer depends on its permissions, not its instructions.
  4. Which agent actions require a human to approve them, and is that enforced by the system? Irreversible, financial and external actions should not rely on the agent following instructions.
  5. How quickly could we stop an agent and cut off all its access? The answer should be measured in minutes and have been tested.

What good looks like

AreaGood practice
VisibilityA complete, maintained inventory of agents and AI integrations, including those introduced by business teams and vendors
AccountabilityA named owner for every agent, and a policy that unregistered agents do not receive production access
AccessEach agent has its own identity and only the access its task needs, for as long as it needs it; no agent uses an employee's credentials or shared keys
OversightHuman approval enforced for high-impact actions; clear limits on what each agent may do on its own
TraceabilityEvery agent action can be traced to the agent and to the person or process it acted for
ResponseA tested ability to stop an agent and revoke its access quickly
Third partiesAI vendors, tools and integrations are assessed like other critical suppliers

Where to invest first

  1. Discovery and inventory: find the agents and AI integrations already in use, and the credentials they hold. See the Shadow AI and AI Agent Discovery Guide.
  2. Least privilege for agents: remove broad and administrative access, and give each agent its own identity. This reduces the impact of every other failure.
  3. Enforced oversight: approval gates for high-impact actions, built into the platforms agents use.
  4. Monitoring and response: attributable logging and a tested kill switch.
  5. Governance: an agentic AI security policy, ownership, and review processes aligned to existing identity governance. See the Agentic AI Security Policy Template.

Much of this extends existing identity and access management and non-human identity programmes rather than requiring a separate initiative. Organisations that already govern service accounts, API keys and secrets well are better placed.

Metrics to track

  • Number of agents and AI integrations discovered, and the percentage registered with an owner.
  • Percentage of agents running on their own identity (not human or shared credentials).
  • Number of agents with administrative or broad access.
  • Percentage of agents whose credentials are short-lived rather than static.
  • Percentage of high-impact actions covered by enforced human approval.
  • Time to stop an agent and revoke its access, measured in tests.
  • Agent-related incidents and near misses.

A 90-day plan for the CISO

  • Days 1 to 30: run discovery across identity provider OAuth grants, SaaS platforms, cloud accounts and developer environments; brief the executive team on findings; issue interim guidance that agents must not use personal credentials or admin roles.
  • Days 31 to 60: assign owners to every agent found; remove the riskiest access; agree an agentic AI security policy; define which actions require human approval.
  • Days 61 to 90: stand up an agent registry and approval route for new agents; establish logging and a tested process to stop an agent; baseline maturity using the Agentic AI Identity Maturity Model and set a 12-month target.

How NHI Mgmt Group can help

We provide independent NHI and agentic AI maturity risk assessments, business case development, programme initiation and board briefings. Our NHI Foundation Level Training Course includes an Agentic AI module for security and IAM teams. Contact us to arrange a briefing.

Related NHI Mgmt Group resources: Agentic AI Security Guide · AI Agents vs Agentic AI · Who Governs AI? · Governing the Invisible

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 26 September 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org