TL;DR: Human risk management is moving from compliance scoring to predictive control, and Living Security Human Risk Management Platform’s HRMCon 2025 session says agentic AI is now central to measuring behavior, prioritising interventions, and automating routine remediation across 200+ risk indicators and 60+ integrations. The governance challenge is no longer visibility alone but accountability for autonomous actions, shadow AI, and the identity and access signals that shape human risk.
At a glance
What this is: This is an analysis of how human risk management is shifting toward predictive, AI-assisted governance, with agentic AI expanding both the detection surface and the accountability problem.
Why it matters: It matters because IAM, PAM, and NHI programmes increasingly intersect with AI-driven decisions, so practitioners need controls that govern behavior, access, and autonomous action together.
By the numbers:
- Organizations using Living Security's Unify platform saw their population of risky users drop from 43% to 21% over the last year.
- Users spent an average of 60% less time in a risky state after completing action plans.
- The platform's independently validated results showed a 98% decrease in data-loss exposure time.
Context
Human risk management has moved beyond awareness training and policy checklists. The practical problem is that many organisations can measure participation, but not whether risk is actually falling, especially when identity data, threat telemetry, and user behaviour are fragmented across tools. In that environment, predictive control becomes more valuable than retrospective reporting, and the identity dimension starts to matter because access patterns often reveal the earliest signs of risky behaviour.
This article frames that shift through agentic AI, which introduces a second problem alongside human risk: autonomous systems can act, nudge, or remediate in ways that affect access, data exposure, and accountability. That is directly relevant to IAM, PAM, and NHI governance because AI agents increasingly behave like privileged digital actors inside business workflows. The starting position described here is now becoming typical for mature programmes, not exceptional.
Key questions
Q: How should security teams govern AI agents that can access enterprise systems?
A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring. The control set should include inventory, task-bound credentials, audit trails, and revocation paths. If an agent can call tools or touch production systems, it belongs in the same governance model as service accounts and other machine identities.
Q: Why do agentic AI systems create hidden cost and risk exposure?
A: Because one user request can fan out into multiple model calls, evaluations, and tool invocations that are invisible in aggregated billing. That same complexity also hides unsafe behaviour, so down-sampling traces reduces assurance at the same time it trims cost. The result is a combined governance and budget problem.
Q: What breaks when shadow AI is not included in identity governance?
A: When shadow AI is excluded, the organisation loses discovery, ownership, and enforcement at the same time. Unmanaged local agents can access cloud and SaaS resources without being enrolled in policy, which means no one can attest to their privileges or revoke them cleanly. The first failure is visibility, and the second is accountability.
Q: Who is accountable when an AI agent causes a security incident?
A: Accountability should sit with the business owner, the system owner, and the security function together, because agent behaviour crosses operational boundaries. Organisations need a defined owner for approval, monitoring, and retirement, plus audit evidence that shows what the agent accessed and why.
Technical breakdown
From behavioural scoring to predictive risk orchestration
Traditional HRM programmes usually rely on static indicators such as phishing clicks, policy breaches, or training completion. Predictive HRM adds correlation across behaviour, identity and access, and threat intelligence so that the system can update risk continuously rather than on a quarterly cycle. In practice, this means the control plane shifts from reporting what users did to estimating what they are likely to do next. The technical challenge is not the score itself, but the quality, normalisation, and timeliness of the signals feeding it.
Practical implication: connect IAM, endpoint, email, and SIEM data before expecting predictive risk scoring to change outcomes.
Agentic AI creates an accountability layer above human risk
Agentic AI changes HRM because the system is no longer observing only people. Autonomous agents can recommend, execute, or amplify actions that affect access, notifications, or remediation, which creates a governance layer above the usual user-risk model. The key issue is accountability: if an AI agent makes a decision that leads to exposure, ownership may span the model owner, the permissions administrator, and the policy framework that allowed the action. That makes auditability and escalation design core controls, not afterthoughts.
Practical implication: define approval boundaries and audit trails for any AI action that can alter access, data handling, or user-facing policy enforcement.
Shadow AI is an identity and access problem, not just an awareness problem
Shadow AI emerges when employees use unapproved tools, browser extensions, API calls, or embedded workflows that bypass normal visibility. This is difficult to manage with awareness training alone because the risky object is not the user’s intent, but the hidden AI pathway interacting with credentials and data. From an identity perspective, these systems may consume tokens, inherit user access, or operate with delegated permissions that security teams never mapped. That makes the problem closer to unmanaged NHI sprawl than to classic human misuse.
Practical implication: inventory AI-enabled access paths and treat unsanctioned agents or extensions as unmanaged identities until proven otherwise.
Threat narrative
Attacker objective: The objective is to exploit hidden AI-enabled workflows and credentialed access paths to expose data, bypass oversight, or create unassigned accountability for harmful actions.
- Entry occurs when users deploy shadow AI through browser extensions, API calls, or embedded workflows that bypass standard monitoring and governance.
- Escalation happens when those AI workflows inherit or consume access tied to human credentials, expanding the effective permission boundary without formal review.
- Impact follows when autonomous or semi-autonomous actions create data exposure, compliance gaps, or accountability failures that security teams cannot trace cleanly.
NHI Mgmt Group analysis
Predictive HRM is becoming an access-governance discipline, not a training discipline. The article shows that the market has moved past counting completions and toward correlating behavior, identity, and threat signals. That is materially closer to access governance than awareness training because the programme now influences who gets flagged, nudged, or remediated. For IAM and GRC teams, the lesson is that behaviour analytics must be treated as a governed control plane, not a reporting layer.
Agentic AI introduces a new non-human risk class inside human risk programmes. Once agents can recommend or execute actions, they become operational actors that need boundaries, auditability, and lifecycle oversight. That intersects directly with NHI governance because these systems may inherit credentials, tokens, or delegated access. The specific governance concept here is agent accountability drift: the gap that appears when AI actions affect access or data but responsibility is spread across too many owners to enforce cleanly. Practitioners need to assign ownership before scaling agentic workflows.
Shadow AI is the same governance problem as unmanaged NHI sprawl, just with a different interface. Browser extensions, embedded workflows, and API-driven assistants can operate outside standard detection and approval paths while still touching enterprise data. The risk is not merely unsanctioned usage but hidden access pathways that bypass lifecycle control. That means the control question is not whether employees are using AI, but whether the organisation can map, authorise, and revoke the identities behind those interactions.
The market is signalling that human risk platforms will be judged on operational outcomes, not awareness metrics. Boards will increasingly care about measurable reductions in risky behaviour, data-loss exposure, and response time rather than training completion. That shifts investment toward integrations, continuous monitoring, and remediation automation. Organisations that cannot evidence outcome-based control will struggle to distinguish mature HRM from improved awareness reporting.
Agentic AI will force convergence between IAM, PAM, and human risk governance. The session’s key message is that risk now moves across people, systems, and AI-mediated actions in one flow. Static role models and periodic reviews are insufficient when decisions happen continuously. Practitioners should expect HRM, identity governance, and AI governance to converge into a single control conversation.
What this signals
Human risk programmes are likely to be audited on their ability to reduce exposure, not just report it. That means integration quality and response latency will matter as much as scoring models, especially where AI assistants and delegated workflows touch credentials. The programme signal to watch is whether risk remediation is shortening exposure windows across identity and data pathways.
Agent accountability drift: this is the control gap that appears when AI decisions affect security outcomes but responsibility is spread across too many teams to enforce cleanly. The practical response is to align governance for human actions, delegated access, and AI-driven remediation under one review model.
As agentic workflows expand, the identity boundary will matter more than the model boundary. Security leaders should expect pressure to inventory AI-mediated access the same way they inventory service accounts and privileged bots, because unmanaged AI interactions can become hidden persistence paths.
For practitioners
- Build a unified risk data layer Connect IAM, endpoint, email security, SIEM, and data loss telemetry so behavioural scoring has enough context to predict risk instead of merely describing it.
- Define approval boundaries for AI-driven actions Document which AI recommendations can auto-execute, which require human review, and which must be blocked until a manager or control owner signs off.
- Inventory shadow AI access paths Identify browser extensions, embedded copilots, API calls, and delegated workflows that can consume enterprise credentials or data without central oversight.
- Treat AI agents as governed identities Apply lifecycle ownership, audit trails, and revocation logic to any agent that can touch systems, data, or policy decisions.
Key takeaways
- Human risk management is shifting from activity tracking to predictive governance, which changes the control model for IAM, GRC, and security operations.
- Agentic AI adds an accountability problem that looks a lot like unmanaged non-human identity risk once systems can act on their own.
- Teams that can map identity, behaviour, and AI-driven actions into one governance model will be better positioned to reduce exposure and defend the programme to leadership.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST AI RMF | GOVERN | The article centers on governance, accountability, and oversight for agentic AI in security workflows. |
| OWASP Agentic AI Top 10 | N/A | Agentic AI risk surfaces include shadow AI, tool misuse, and agent accountability gaps. |
| OWASP Non-Human Identity Top 10 | NHI-01 | AI agents inheriting credentials or delegated access create non-human identity governance exposure. |
| NIST CSF 2.0 | PR.AC-4 | The article’s governance model depends on least privilege and controlled access paths. |
| NIST SP 800-53 Rev 5 | AC-6 | Least-privilege controls are central to limiting agent and human access in predictive HRM. |
Review identity and access assignments for users and agents, then remove standing access that is not justified.
Key terms
- Human Risk Management: The practice of managing how people interact with security controls, especially under pressure, distraction, or deception. It combines training, policy, and friction management so identity systems are still usable enough that users do not bypass them in day-to-day work.
- Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
- Agent Accountability: Agent accountability is the ability to explain, verify, and review what an AI agent did and why it did it. For security teams, it means the agent’s decisions are traceable to evidence, scope, and ownership, so failures can be corrected instead of merely observed.
- Behavioral Contagion: A pattern where users change their own security behaviour after observing how AI systems are allowed to operate. If an organisation grants AI broad access or rapid autonomy, people may infer that the same boundaries are less important for human workflows too.
What's in the full article
Living Security Human Risk Management Platform's full blog covers the operational detail this post intentionally leaves for the source:
- The full session context from HRMCon 2025, including how Jinan Budge and Graham Westbrook framed market maturation and analyst validation.
- The underlying Forrester Wave and Cyentia references that support the reported outcome metrics and market positioning.
- The detailed examples of predictive HRM workflows, including the 60-80% routine remediation automation model.
- The specific recommendations for building data foundations and AI governance frameworks before scaling agentic workflows.
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps security practitioners connect identity controls to the operational risks created by autonomous systems and delegated access.
Published by the NHIMG editorial team on August 21, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org