By NHI Mgmt Group Editorial TeamDomain: AI SecuritySource: MindPublished December 30, 2025

TL;DR: Agentic AI is moving security decisions across identity and data at machine speed, and MIND argues that traditional siloed controls will not keep pace as agents provision access, move data, and act without human approval. The practical shift is toward adaptive governance that treats identity, intent, and sensitivity as one control problem rather than separate ones.


At a glance

What this is: This is an independent analysis of MIND's 2026 predictions, which argue that agentic AI is collapsing the separation between identity security and data security.

Why it matters: It matters because IAM, PAM, data security, and GRC teams will need to govern autonomous actions, not just authenticated users, across human, non-human, and AI-driven workflows.

👉 Read Mind's 2026 predictions on agentic AI, identity, and data security


Context

Agentic AI is changing the control boundary that identity teams have relied on for years. When a software system can decide, act, and transmit data across applications without a human approving every step, the old split between who has access and what data is being touched becomes too narrow to govern risk properly.

MIND's core point is that identity, data, and automation are converging into the same security problem. That creates direct implications for IAM, PAM, data security, and policy enforcement, because the question is no longer only whether access is valid, but whether an autonomous action is acceptable in context.


Key questions

Q: How should security teams govern data access for agentic AI workflows?

A: Security teams should treat data access as part of the agent’s decision boundary, not as a separate storage problem. Scope access by use case, classify the datasets that influence actions, and verify that policies can constrain runtime behaviour as agents select tools and next steps. The goal is to prevent an agent from turning broad data reach into uncontrolled action.

Q: Why do agentic AI workflows break traditional DLP assumptions?

A: Traditional DLP assumes predictable human behaviour, manual review and time to intervene. Agentic workflows compress all three assumptions because agents can retrieve, transform and share data in seconds. That means the control question shifts from detecting data movement to deciding whether the move should have been authorised at all.

Q: What do organisations get wrong about governing AI use?

A: They often separate AI governance from IAM and lifecycle management, even though AI adoption depends on who can access tools, what data those tools can reach, and how access ends. A policy that ignores procurement, revocation, and exception management will miss the identities that create the risk.

Q: Who is accountable when an AI agent accesses sensitive data it was not meant to use?

A: Accountability sits with the team that approved the agent, its connectors, and its policy boundaries, not with the runtime behaviour alone. Organisations need ownership for intent, permissions, monitoring, and validation so they can prove whether the agent stayed inside its approved purpose. Without that, audit and regulatory response become retrospective guesswork.


Technical breakdown

Why agentic AI breaks identity and data silos

Traditional security separates authentication, authorization, and data inspection into different control layers. Agentic AI collapses those layers because the system can initiate actions, chain tool use, and move sensitive information within one workflow. That means the identity of the acting entity, the data it touches, and the intent behind the action all matter at the same time. Static role models and one-time approvals struggle when the actor is a software system that can change behaviour mid-session. Practical implication: security teams need unified policy decisions that evaluate identity, data sensitivity, and runtime context together.

Practical implication: security teams need unified policy decisions that evaluate identity, data sensitivity, and runtime context together.

Why deterministic controls fail against AI agents and data flows

Rule-based controls work best when behaviour is predictable. Agentic AI is not predictable in that sense, because it can choose actions dynamically, adapt to context, and generate output that is not explicitly scripted. In practice, that breaks simple allow and deny logic, especially when the same agent can access SaaS apps, cloud services, email, and on-prem data in a single chain. The result is not just false positives or false negatives. It is policy drift, where enforcement lags behind what the system is actually doing. Practical implication: teams should move toward context-aware authorization and runtime monitoring for high-risk AI workflows.

Practical implication: teams should move toward context-aware authorization and runtime monitoring for high-risk AI workflows.

What policy-aware AI workflows need at runtime

The article points to a future where security is embedded into the workflow itself rather than bolted on afterwards. That means policy must travel with the action, not sit in a separate admin console after the fact. For identity practitioners, this is the same architectural shift seen in zero standing privilege and just-in-time access, except now the actor may be an AI agent rather than a person or service account. The control objective becomes continuous accountability for actions, decisions, and data handling. Practical implication: define runtime guardrails for agents, including least privilege, context checks, and event logging for every privileged action.

Practical implication: define runtime guardrails for agents, including least privilege, context checks, and event logging for every privileged action.


Threat narrative

Attacker objective: The objective is to abuse trusted automation so that sensitive data can be accessed, moved, or exposed without the kind of oversight that would catch a human actor.

  1. Entry occurs when an AI agent gains delegated access to SaaS, cloud, or internal systems as part of an automated workflow.
  2. Escalation happens when over-privileged credentials or weak guardrails let the agent chain actions across identity and data domains without effective human review.
  3. Impact follows when the agent exposes sensitive data, drifts from policy intent, or triggers unauthorized downstream actions at machine speed.

NHI Mgmt Group analysis

Identity and data can no longer be governed as separate risk planes. Agentic AI collapses the old operating model where IAM answered who could act and data security answered what was being touched. When a software entity can decide and execute across both domains, control ownership has to converge as well. That means identity governance, data classification, and runtime policy must be evaluated together, not by separate teams in separate tools. Practitioner conclusion: build one policy chain that covers actor, action, and data context.

Adaptive policy is becoming the replacement for Boolean risk logic. Static rules were designed for systems that behave predictably, but agentic workflows introduce context shifts, chained actions, and non-deterministic behaviour. The result is not just more false alerts, but enforcement that arrives too late to matter. This is where the named concept of identity-data convergence risk becomes useful: the failure mode is not bad authentication alone, it is fragmented governance across identity and data domains. Practitioner conclusion: move high-risk AI workflows to context-aware controls and event-based review.

Trusted autonomy will depend on runtime accountability, not post-event review. The article correctly frames the CISO's role as enabling innovation safely, but that only works if every privileged AI action is traceable and bounded at runtime. In practice, this is where IAM, PAM, and AI governance meet. Controls aligned to NIST AI RMF GOVERN and MAP, plus OWASP Agentic AI Top 10 concerns around tool misuse and agent hijacking, become relevant as design inputs. Practitioner conclusion: require runtime logs, scoped privileges, and explicit ownership for each autonomous workflow.

Regulation will force organisations to answer who acted, what data was used, and why. That question set is already incompatible with siloed security controls that cannot correlate identity, action, and data lineage. The compliance burden will fall hardest on organisations that still separate IAM, DLP, and AI governance into disconnected operating models. NIST CSF and AI RMF both point toward integrated accountability, while identity teams will need to support audit-ready evidence across autonomous workflows. Practitioner conclusion: design for evidence collection now, before regulators ask for it.

What this signals

Identity-data convergence risk: the emerging failure mode is not simply more access, but more control planes that cannot reason about the same autonomous action at the same time. Programmes that still split IAM, PAM, DLP, and AI governance will struggle to prove why an agent was allowed to act, what it touched, and whether that action was acceptable in context.

Security leaders should expect runtime policy, evidence collection, and delegated access reviews to become core requirements for AI governance. The practical benchmark is no longer whether a workflow is automated, but whether its privileges, logs, and data boundaries can survive audit scrutiny under NIST AI RMF and OWASP Agentic AI Top 10 expectations.

The most useful near-term move is to align agent identity controls with existing NHI governance patterns, especially task-scoped access, offboarding, and rotation discipline. Where those controls are weak today, agentic AI will amplify the gap rather than hide it.


For practitioners

  • Define an AI agent identity inventory Catalogue every agent, service account, token, and delegated workflow that can act without direct human approval. Tie each one to an owner, purpose, privilege scope, and data domain so the programme can distinguish sanctioned automation from shadow AI.
  • Apply just-in-time privilege to autonomous workflows Replace persistent access with task-scoped permissions for high-risk AI actions, especially where agents can reach SaaS, cloud, and on-prem systems. Review whether each workflow can complete with ephemeral credentials rather than standing access.
  • Enforce context-aware policy at runtime Add decision points that combine identity, data sensitivity, and behavioural context before privileged actions execute. This is more effective than relying on static allowlists when agents can chain tools and change behaviour within one session.
  • Instrument autonomous actions for auditability Log every privileged action, tool call, and data movement step performed by an agent so incident response can reconstruct the full chain. Correlate identity events with data events and workflow events in the same monitoring path.

Key takeaways

  • Agentic AI turns identity and data into one governance problem, because autonomous systems can act and move information in the same workflow.
  • The risk is not only over-privilege, but policy drift and runtime ambiguity that static IAM and DLP controls cannot reliably absorb.
  • Security teams should move toward context-aware authorization, task-scoped access, and auditable runtime controls for every autonomous workflow.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10The article centers on agent hijacking, tool misuse, and autonomous workflow risk.
NIST AI RMFGOVERNThe article’s governance theme is accountability for AI actions and decisions.
NIST CSF 2.0PR.AC-4Identity and access control are central to governing agent and data access.
NIST SP 800-53 Rev 5AC-6Least privilege is the main control for reducing over-privileged AI actions.
MITRE ATT&CKTA0006 , Credential Access; TA0010 , ExfiltrationThe threat pattern includes credential abuse and unauthorized data movement.

Map AI workflow abuse to credential access and exfiltration tactics for detection planning.


Key terms

  • Agentic AI: Autonomous AI systems capable of planning, deciding, and taking actions — including calling APIs, writing code, and orchestrating other agents — with minimal human oversight. Agentic AI introduces new NHI risks as agents must authenticate to external services.
  • Identity-data convergence: The operational linking of identity governance signals with data discovery and classification signals. It allows security teams to see not only who has access, but whether that access reaches sensitive or regulated data, which is essential for defensible remediation and certification.
  • Runtime Policy Enforcement: Runtime policy enforcement evaluates a request at the moment it is executed instead of relying only on preconfigured permissions. For AI agents, this allows decisions to reflect current context, target sensitivity, and behavioural signals rather than static assumptions.
  • Session-scoped privilege: Access that exists only for the current task or execution window and is removed when the session ends. For autonomous or agentic systems, this reduces standing privilege but also shifts the burden to runtime controls, because the identity may not persist long enough for traditional review cycles.

What's in the full article

Mind's full article covers the strategic argument and trend framing this post intentionally leaves at a higher level:

  • How the vendor expects AI regulation to shape accountability, explainability, and data protection expectations in 2026
  • The detailed case for moving from rule-based controls to adaptive risk models across identity and data workflows
  • Examples of how autonomous agents can create subtle policy drift without triggering obvious breach alerts
  • The vendor's view on how CISOs should embed trust into AI workflows while preserving business speed

👉 Mind's full article expands on the five predictions, including regulatory pressure, autonomous workflow risk, and the shift to adaptive controls.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, secrets management, and identity lifecycle controls. It helps practitioners design accountable access models that fit human, non-human, and agentic environments.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org