TL;DR: As agentic systems begin to initiate actions, retrieve data, and make decisions across connected environments, SACR’s research says data security, identity context, and runtime control are converging into one operating model, with Cyera named as a leading platform in that category. The core shift is that governance assumptions built for static prompts and passive data flows no longer hold when AI can act on data in motion.
At a glance
What this is: This is an analysis of how agentic AI security is merging with data and identity control, with the key finding that governance now has to cover autonomous systems that initiate actions and use sensitive data in real time.
Why it matters: IAM, NHI and security teams need to treat agent behaviour, data access and runtime enforcement as one control problem because agentic systems break assumptions built for passive prompts and static entitlements.
Context
Agentic AI security is the problem of governing AI systems that do more than answer prompts. In this article, Cyera argues that autonomous and semi-autonomous agents now initiate actions, retrieve data and chain tasks across enterprise systems, which means traditional data and identity controls no longer operate as separate planes.
The governance gap is not simply exposure of sensitive data. It is the loss of a stable boundary between data classification, identity context and live execution, so security programmes have to understand how AI systems are acting on information, not only where the information is stored.
Key questions
Q: How should security teams govern agentic AI that can execute IAM tasks?
A: Start by treating the agent as an NHI with bounded authority, explicit ownership, and revocation procedures. Require human approval for high-risk actions, log every decision path, and enforce least privilege at the workflow level. If the agent cannot be audited or rolled back, it is not yet ready for autonomous IAM execution.
Q: Why do DSPM and DLP still matter for agentic AI security?
A: DSPM and DLP remain foundational because agentic systems still depend on data visibility and policy enforcement. DSPM tells you what the sensitive data is, who owns it and where it is exposed. DLP applies those rules as data moves. In agentic environments, that same foundation has to feed AI-specific governance and runtime control.
Q: What are the signs that a data security programme is not ready for agentic AI?
A: Common warning signs are low visibility into where data lives, weak lineage tracking, and limited control over how data is used by agents. If discovery and classification are incomplete, teams cannot tell which data is sensitive, who can reach it, or whether an agent is acting on stale or untrusted inputs.
Q: How do identity controls change when AI systems start chaining tasks?
A: Identity controls have to shift from provisioning-time entitlement checks to live task-aware enforcement. When AI systems chain actions, the relevant question is whether the current action matches the agent’s authorized purpose and data context. That requires continuous evaluation of identity context, not just a one-time approval.
Technical breakdown
Why agentic AI changes the control plane
Agentic AI differs from prompt-response AI because the system can decide what to do next, not just generate text. In the article’s framing, agents can initiate actions, retrieve data and collaborate with other agents, which makes the control problem about runtime behaviour rather than static access. That changes how security teams think about trust: the question is no longer only whether a model can see data, but whether it can use, transform and propagate that data across systems in ways the original policy did not anticipate.
Practical implication: Treat agent execution as a governed identity and data path, not as a simple application feature.
How DSPM and DLP become part of agentic AI security
The article places DSPM and DLP inside the same operating model as AI security because visibility and enforcement need to follow the data, not stop at storage boundaries. DSPM gives sensitivity, ownership and exposure context. DLP then enforces policy as data moves through endpoints, SaaS and networks, including when an AI system is involved. In agentic environments, that combination becomes the foundation for deciding what an agent may access, how that access is interpreted and when runtime intervention is required.
Practical implication: Use data classification and DLP policy as inputs to AI governance, not as separate after-the-fact controls.
Why identity context matters in runtime enforcement
Cyera’s article ties identity context to runtime control because agentic systems often act on behalf of users, roles or service contexts that shift during execution. That makes simple allow-or-deny logic too blunt for the environment described here. A security decision now has to account for what the agent is doing, what data it is touching and whether the request aligns with the intended business task. The architecture implication is that identity signals must inform enforcement while the action is still in progress, not only at provisioning time.
Practical implication: Design runtime policy so identity context can shape agent decisions before sensitive data is exposed.
Breaches seen in the wild
- DeepSeek database exposure 2025: An unauthenticated DeepSeek ClickHouse database exposed over a million log lines with plaintext chat history and API keys in 2025.
- Microsoft SAS token exposure 2023: An over-permissive Azure SAS token in a Microsoft AI GitHub repo exposed 38TB, including workstation backups and Teams messages, for 3 years.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Agentic AI security collapses the old separation between identity and data governance. The article’s central point is that autonomous systems now act on information, not just display it, so data security tools and identity controls cannot remain parallel programmes. Once agents can initiate actions and chain tasks, the real control question becomes who or what is authorised to move sensitive data through a live execution path. Practitioners should treat that as one governance plane, not two.
Static control models fail when behaviour is runtime-driven. DSPM and DLP were built for visibility and enforcement around known data states, but agentic systems create decisions inside the session. That means security teams must re-evaluate assumptions about when policy is applied, how intent is inferred and where enforcement belongs in the stack. The practical conclusion is that governance has to move closer to execution.
Identity context becomes the missing bridge for AI governance. The article is strongest when it shows that classification alone is not enough because an agent’s access depends on who it is acting for, what it is doing and whether the data use is aligned with the task. This is where identity governance, data lineage and runtime control converge. The practitioner takeaway is that AI security programmes need identity-aware enforcement, not just data awareness.
Agentic data security is the right name for a new control problem. SACR’s framing points to a broader market shift: enterprises are no longer securing a model layer, a data layer and an identity layer separately, but a single adaptive control loop. That is a useful concept because it captures the operational reality of agents interacting with business data at machine speed. Practitioners should adopt programme language that reflects that convergence before controls fragment again.
From our research library:
- Only 23% of IT leaders were very confident in their organisation's ability to manage security and governance for GenAI deployments, according to a 2025 Gartner survey of 360 IT leaders.
What this signals
Agentic AI security will force IAM and data security teams to share one control vocabulary. The article points to a programme shift where classification, identity context and runtime enforcement are no longer separable concerns. For practitioners, that means agent governance has to be designed as part of identity architecture rather than bolted onto data protection after the fact.
Adaptive runtime controls will matter more than static policy statements. Once agents can initiate actions and chain tasks, the main risk is not just data exposure but uncontrolled use of sanctioned access. Security teams should prepare for policy decisions that happen during execution, not only at setup time.
For practitioners
- Map agent data paths end to end Inventory where copilots, embedded assistants and task-driven agents can read, transform and forward sensitive data across systems.
- Bind data classification to agent permissions Use data sensitivity, ownership and exposure context to determine which datasets an agent may touch during a live task.
- Add runtime policy to AI workflows Enforce contextual blocking, redaction or warning controls while prompts, retrievals and outputs are still in flight.
- Review shadow AI and unsanctioned agents Continuously discover agents and copilots that can access business data without a documented governance path.
Key takeaways
- Agentic AI changes the governance problem because systems can now initiate actions and move sensitive data, not merely produce responses.
- The article’s core claim is that data visibility, identity context and runtime enforcement now need to operate together or governance breaks down.
- Practitioners should rework AI controls around live execution paths, because static controls built for passive prompts will not contain agent behaviour.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI02 — Tool Misuse | Agentic systems in the article initiate actions and chain tasks across tools. |
| ASI03 — Identity & Privilege Abuse | The article hinges on identity context shaping what agents may access and do. | |
| Recommendation — Map agent workflows to ASI02 and restrict tool use to task-scoped, policy-approved actions. Apply ASI03 controls to bind agent privileges to task context and prevent privilege drift. | ||
| CSA MAESTRO | Agentic AI threat modeling | The topic is agentic AI governance and runtime control across connected systems. |
| Recommendation — Use MAESTRO to model agent behaviour, data access and runtime enforcement as one control surface. | ||
| NIST AI RMF | GOVERN — AI Governance and Accountability | The article is about programme design for governing AI behaviour and accountability. |
| Recommendation — Establish AI governance roles and accountability before deploying agentic systems into business workflows. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Identity context and authorization are central to controlling agent access to sensitive data. |
| Recommendation — Align agent entitlements with PR.AA-05 so access is authorized by context and purpose, not default trust. | ||
Key terms
- Agentic AI Security: Agentic AI security is the discipline of securing autonomous AI systems that can take actions, use tools, and chain decisions without direct human approval at each step. It covers identity and access management for AI agents, prompt injection defence, tool call governance, credential scoping, and runtime monitoring. As agentic systems acquire real-world authority, API access, file writes, workflow triggers, the security model must treat them as non-human identities with explicit lifecycle controls, not trusted processes.
- Data Security Posture Management: Data Security Posture Management, or DSPM, is the continuous discovery and monitoring of where sensitive data lives, how it is exposed, and where policy gaps exist. Its value rises when it feeds remediation rather than generating findings alone, especially in environments where AI expands the number of data paths.
- Runtime Protection: Runtime protection is a control model that observes application behavior while software is running and blocks unsafe actions as they occur. In Java estates, it helps distinguish active exploit paths from dormant vulnerable code, which is essential when patching is delayed or impossible.
- Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org