By NHI Mgmt Group Editorial TeamDomain: AnnouncementsSource: Arxan TechnologiesPublished November 19, 2025

TL;DR: Enterprise AI often lifts individual productivity without changing enterprise outcomes, and Arxan Technologies cites McKinsey data showing only 39 percent of organisations see meaningful financial impact at the enterprise level. The missing ingredient is workflow-level context, because intelligence scattered across tools becomes intelligence debt instead of coordinated decision-making.


At a glance

What this is: This article argues that AI only creates enterprise ROI when it is embedded in the workflow core, where planning, dependencies, and delivery decisions are made.

Why it matters: That matters to IAM and security practitioners because agentic systems need governed context, permissions, and accountability at the point of action, not just at the point of prompt.

By the numbers:

👉 Read Arxan Technologies' analysis of agentic AI ROI inside the workflow core


Context

Enterprise AI often fails to convert local productivity into durable business value because it is added as a feature rather than embedded in the workflow core. In practice, that means the system can assist with tasks but still cannot govern planning, sequencing, dependencies, or cross-team decisions, which is where enterprise ROI is actually created. This is increasingly relevant for AI governance and the identity of the systems acting inside business processes.

The governance gap is not just technical. When AI sits outside the operational loop, humans must supply context, notice changes, and reconcile competing priorities manually. That creates fragmented accountability and makes it harder to control what an AI system can see, decide, and do. For readers working on agentic AI or IAM-adjacent controls, the article’s starting position is typical of many enterprises: strong local gains, weak system-level impact.


Key questions

Q: How should security teams govern AI-enabled workflows that can act on their own?

A: Treat them as identity-governed execution paths, not just software features. Assign a named owner, define least-privilege access, log every tool call, and require revocation paths for credentials and tokens. If the workflow can touch production systems or sensitive data, its permissions must be reviewed with the same discipline used for privileged machine identities.

Q: Why do local AI productivity gains often fail to produce enterprise ROI?

A: Local gains stop at the task level, while enterprise ROI depends on coordination across planning, sequencing, and delivery. If AI cannot access the shared context that shapes those decisions, it only accelerates fragments of work. The organisation then gets faster drafting or analysis, but not better alignment, fewer dependencies, or more reliable execution.

Q: What are the signs that AI is operating outside the workflow core?

A: Common signs include repeated manual handoffs, duplicated context gathering, inconsistent priorities across teams, and AI outputs that help individuals but do not change delivery outcomes. If users still need to reassemble the same information before acting, the AI is augmenting tasks rather than participating in the system of work.

Q: How should security teams govern agentic AI that can execute IAM tasks?

A: Start by treating the agent as an NHI with bounded authority, explicit ownership, and revocation procedures. Require human approval for high-risk actions, log every decision path, and enforce least privilege at the workflow level. If the agent cannot be audited or rolled back, it is not yet ready for autonomous IAM execution.


Technical breakdown

Why feature-level AI hits an assistance ceiling

Feature-level AI improves isolated tasks, but it does not understand the surrounding system of work. An assistant can draft, summarise, or recommend actions, yet it still depends on a human to notice the change, provide context, and decide whether the output matters. In complex enterprises, that creates an assistance ceiling: more activity, but not more coordination. The problem is architectural, not just behavioural. If AI is not connected to planning objects, dependency graphs, and delivery signals, it cannot influence enterprise outcomes.

Practical implication: place AI where the decision context already exists, not only where end users can query it.

Embedded AI and the workflow core

Embedded AI works inside the operational system where plans, priorities, and constraints are already represented. That placement gives the model access to live context, such as capacity changes, downstream dependencies, and risk signals, so it can reflect the state of work rather than merely answer questions about it. This is the difference between a tool that helps with tasks and a system that shapes execution. Once AI participates in the workflow core, it becomes capable of influencing sequencing, escalation, and adjustment before work drifts.

Practical implication: integrate AI into workflow engines, planning systems, and delivery checkpoints where state changes are already tracked.

Intelligence debt in distributed AI deployments

Intelligence debt is the accumulation of smart but disconnected tools that cannot learn from one another or share context effectively. Each may improve a local process, but together they fragment decision-making and create more coordination overhead. That matters for governance because context loss is also control loss. If one system sees a risk and another does not, accountability becomes blurred and automation becomes harder to audit. The more AI is distributed without shared context, the more enterprises pay in oversight, reconciliation, and missed dependencies.

Practical implication: map where context is lost across tools and treat that gap as a governance debt, not a productivity issue.


NHI Mgmt Group analysis

Workflow context is the real control plane for enterprise AI. Local productivity gains do not create enterprise value if the system cannot see dependencies, priorities, and constraints together. That is why feature-level deployments stall at assistance and why embedded AI becomes the meaningful design choice. For identity and governance teams, the lesson is that decision context is part of the control surface, not a convenience layer.

Intelligence debt is the right name for disconnected AI tooling. The article describes a common enterprise pattern: multiple AI capabilities that are individually useful but collectively unable to coordinate. That creates governance overhead, because decisions must be reconciled across systems instead of being made in one context-rich workflow. The practitioner conclusion is that AI architecture should be reviewed for shared state, auditability, and lifecycle control, not just model performance.

Agentic AI changes the identity problem because the system is no longer only assisting humans. Once AI can interpret context and take the next step in a workflow, it needs governed access to the same planning and delivery data that humans use. That makes identity, privilege, and action scope central to the operating model. For IAM and PAM teams, the implication is to treat agent permissions as part of business process design.

Enterprise AI ROI will increasingly depend on governance maturity, not model novelty. The market is moving toward task-specific agents inside enterprise applications, which means the differentiator is no longer whether AI can generate output. It is whether organisations can let AI act with enough context to improve outcomes while still preserving oversight, traceability, and approval boundaries. Practitioners should assess whether their current controls can support workflow-native AI safely.

From our research:

What this signals

Workflow-native AI will force IAM teams to think beyond user roles. Once agents participate in planning and execution, the real question becomes which process states they can observe and alter. That demands stronger linkage between identity, policy, and business workflow than most current deployments provide, especially where shared context determines whether an action is safe.

Context loss is now a measurable governance risk, not an abstract architecture concern. When an AI system cannot see the dependency chain behind a decision, organisations accumulate reconciliation work and audit gaps. The governance response is to treat shared state, logging, and approval boundaries as first-class control requirements rather than implementation details.

Agentic AI is pushing enterprises toward access design that mirrors process design. That means aligning permissions to the smallest meaningful unit of work and ensuring that escalation paths reflect real operational boundaries. For teams assessing future-state controls, the question is whether the current identity model can support context-aware action without expanding standing privilege.


For practitioners

  • Define the workflow core first Identify the planning, prioritisation, and delivery systems where enterprise decisions are actually made, then determine which AI functions belong inside those systems rather than around them.
  • Map shared state and context boundaries Document which data elements an AI system must see to make a correct recommendation, and where context is intentionally withheld for privacy, segregation, or policy reasons.
  • Treat AI permissions as process design Align access rights, approval paths, and human override points to the workflow step the agent supports, not to a generic user role model.
  • Measure coordination, not just speed Track whether AI reduces dependency slippage, priority drift, and manual reconciliation across teams, because those are the outcomes that determine enterprise ROI.

Key takeaways

  • AI that improves only individual tasks will not deliver enterprise-scale value if it remains outside the workflow core.
  • The key governance challenge is context sharing, because disconnected AI tools create intelligence debt and audit friction.
  • Agentic AI makes identity and privilege design part of business process architecture, not a separate control layer.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and MITRE ATLAS address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST AI RMFGOVERNThe article is about governance for AI operating inside business workflows.
OWASP Agentic AI Top 10A1Agentic systems need controls for misuse of context and action scope.
NIST CSF 2.0PR.AC-4Workflow-native AI depends on access permissions aligned to business processes.
NIST SP 800-53 Rev 5AC-6Least privilege is central when AI can act in operational workflows.
MITRE ATLASTA0004 , Privilege Escalation; TA0006 , Credential AccessAI systems that act on context can be targeted through access and privilege abuse.

Assign governance ownership for workflow-native AI and define approval, accountability, and oversight boundaries.


Key terms

  • Workflow Core: The workflow core is the part of an enterprise system where planning, prioritisation, sequencing, and delivery decisions are made. It is where business value becomes operational. For AI governance, this is the control zone that determines whether intelligence merely assists tasks or actually shapes outcomes.
  • Intelligence Debt: Intelligence debt is the accumulation of AI tools that are individually useful but collectively disconnected from one another and from shared context. The result is more coordination effort, weaker auditability, and repeated manual reconciliation. It is a governance problem as much as an architecture problem.
  • Workflow-native AI governance: Workflow-native AI governance means placing AI inside the normal operating workflow while keeping the same rules for access, logging, approval, and accountability. The idea is to avoid a second trust model for AI. In practice, it asks whether the control plane still matches the way work actually happens.
  • Session Boundary: A session boundary is the point where a browser interaction starts and ends, along with the controls that prevent state from leaking between tasks. In NHI governance, it is the practical line that determines whether cookies, tokens, and form data remain confined to one approved workflow.

What's in the full article

Arxan Technologies' full article covers the operational detail this post intentionally leaves for the source:

  • How Digital.ai Agility Sage is positioned inside planning and portfolio workflows rather than as a standalone assistant
  • Examples of the specific planning, capacity, and dependency structures the vendor says Sage can interpret
  • The article's explanation of how workflow placement is intended to improve alignment, not just individual productivity
  • The vendor's own framing of where agentic AI fits within enterprise agility and delivery

👉 Arxan Technologies' full article expands on workflow placement, planning context, and the role of Digital.ai Agility Sage

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance and machine identity security for practitioners who need to connect access control to real operational workflows. It helps security teams translate identity principles into controls that fit modern automation and agentic systems.
NHIMG Editorial Note
Published by the NHIMG editorial team on September 3, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org