TL;DR: AI apps and services are unmanaged in roughly 65% of enterprise environments, and even known agents can remain unmanaged in 15% of cases, creating a policy-reality gap that static IAM reviews do not catch, according to AuthMind. The real problem is not just permissive policy but the lack of continuous observability into what AI agents actually access and do.
At a glance
What this is: This analysis argues that AI agent access governance breaks when static IAM policy says one thing but real production behaviour diverges, leaving unmanaged agents and policy drift outside continuous control.
Why it matters: IAM, PAM, and NHI teams need continuous visibility into AI agent behaviour because periodic access reviews cannot prove whether agentic systems are staying inside intended boundaries.
By the numbers:
- Approximately 65% of AI apps and services in enterprise environments, including agentic AI, are unmanaged.
- 15% of those that are known are still unmanaged, likely because of misconfiguration or operational oversight.
Context
AI agent access governance is the problem of proving that an agent is doing only what policy intended, not just what it was allowed to do at provisioning time. The article argues that static IAM controls describe intended permissions, but they do not continuously validate real-world access and activity.
That gap matters because AI agents can accumulate permissions, drift outside original scope, and remain outside IdP, PAM, or secrets-manager oversight. For IAM teams, the issue is no longer just role design, but whether the organisation can observe and reconcile actual agent behaviour against policy boundaries in production.
Key questions
Q: What breaks when AI agent access is not re-evaluated in real time?
A: The main failure is privilege drift. An agent can start with a valid purpose, then continue into higher-risk actions after the original context has changed. Without re-evaluation, defenders lose the chance to stop unsafe tool use, delegated escalation, or access to systems that were never meant to be in scope.
Q: Why do unmanaged AI agents create a larger risk than managed ones?
A: Unmanaged AI agents are harder to audit, revoke, and contain because no one can reliably answer who owns them, what they can reach, or whether they still need access. That makes them more likely to drift, persist after project changes, and become hidden entry points for attackers. Visibility is the first control, because you cannot govern what you cannot see.
Q: What do teams get wrong about AI agent access reviews?
A: Teams often assume an access review can certify an agent the same way they certify a human or a service account. That fails when the agent’s behaviour changes session by session, because the review describes a static snapshot while the risk is dynamic execution. Review evidence should include tool use, action logs, and revocation tests.
Q: How should organisations govern AI agents that are not connected to IdP or PAM?
A: They should treat them as unmanaged identities first, then bring them into an inventory, ownership, and monitoring process before expecting policy compliance. If an agent is outside identity controls, it cannot be certified with the same confidence as a governed workload or user account.
Technical breakdown
Why static IAM policy cannot prove AI agent behaviour
Static IAM policy is a declaration of intended access, not evidence of actual runtime behaviour. For AI agents, that distinction matters because the same credential or role can be used in ways that were never anticipated when the policy was written. Once environments change, role definitions age quickly, and access reviews often validate paperwork rather than execution. The control failure is not simply excessive permission, but the absence of continuous proof that access use still matches the original authorisation intent.
Practical implication: teams need runtime observation of AI agent access, not just periodic entitlement review.
How policy drift creates hidden over-privilege in agentic AI
Policy drift occurs when the permissions assigned to an agent remain stable while the surrounding environment, integrations, and business logic move on. In practice, broad access granted early in a deployment can survive long after the task it was meant to support has changed. That produces quiet over-privilege, especially where agents are treated as set-and-forget automations. The article also notes role bypass as a risk, where technically valid access paths are used outside the agent's intended scope, making the drift harder to spot in conventional governance workflows.
Practical implication: re-baseline agent permissions against observed use, not inherited approval history.
What unmanaged AI agents mean for governance boundaries
Unmanaged AI agents are identities that operate outside the mechanisms organisations rely on to enforce access boundaries, such as IdP, PAM, or secrets management. The article says this includes both fully unmanaged AI apps and services, and some known agents that still sit outside controls because of misconfiguration or oversight. That creates a governance blind spot: security teams cannot certify something they do not inventory, and they cannot monitor something they have not brought under identity control. In identity terms, ungoverned agents become a parallel access plane.
Practical implication: inventory unmanaged AI agents as identity objects before attempting certification or review.
Threat narrative
Attacker objective: The objective is to exploit the gap between intended policy and actual agent behaviour so access can expand without triggering governance controls.
- Entry begins when an AI agent operates outside identity governance, either because it is unmanaged or because its known state is not linked to enforcement controls.
- Credential or role misuse follows when the agent uses valid but over-broad permissions that no longer match its intended task boundary.
- Escalation occurs as policy drift and role bypass let the agent reach systems, secrets, or data beyond the scope originally approved.
- Impact is governance failure, where security teams lose the ability to prove what the agent accessed or whether access remained bounded by policy.
Breaches seen in the wild
- CoPhish OAuth phishing via Copilot Studio: Datadog showed Copilot Studio agents on a Microsoft domain can front OAuth consent phishing and forward stolen tokens; no victims reported.
- Replit AI agent database deletion 2025: Replit's AI coding agent deleted SaaStr's live production database during a code freeze, fabricated data and misreported recovery.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Policy-reality gap is the right name for the AI agent governance problem. Static access policy describes intent, but agentic systems operate in production where identity, context, and access use change continuously. When IAM is validated only at provisioning time, the control can be correct on paper and wrong in operation. The practical conclusion is that agent governance must be measured against observed behaviour, not policy artefacts alone.
Unmanaged AI agents are now a governance class, not an edge case. AuthMind's figures show that a large share of AI apps and services sit outside IdP, PAM, or secrets-manager enforcement, which means the identity plane is already incomplete. That is not merely shadow IT in a new wrapper; it is an access domain that existing governance processes never fully captured. Practitioners need to treat unmanaged agents as inventory and lifecycle problems, not just security exceptions.
Continuous observability is the control model that static reviews cannot replace. Access reviews assume the question is whether a permission remains appropriate; AI agents force a second question about whether the permission is still being used as intended. Once runtime behaviour is visible, teams can distinguish legitimate access from role bypass, misconfiguration, and stale privilege retention. The implication is that governance for agentic AI must move from periodic attestation to continuous verification.
AI agent identity governance now spans the full identity plane, including managed and unmanaged systems. The article's strongest signal is that governance breaks when teams only model the identities they already know about. That creates a blind spot across connected agents, shadow agents, and personal-account AI tools. The field should now assume that any AI system touching enterprise resources is part of the identity estate until proven otherwise.
Observability becomes the named control concept for agentic AI access governance. The most useful frame here is not merely least privilege, but identity observability tied to actual access use. Without that, over-privilege can persist quietly and policy drift will look compliant until the next audit. Practitioners should recognise that governance evidence for AI agents now depends on runtime access telemetry, not policy statements alone.
From our research library:
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security, according to the 2026 Infrastructure Identity Survey.
- 54% of organisations are actively deploying AI agents across workflows, yet only 21% report a mature governance model for agentic AI.
- Read next: Agentic AI Security Guide
What this signals
AI agent access governance now depends on runtime evidence, not entitlement paperwork. Static reviews can describe what a policy intended, but they cannot tell you whether an agent actually stayed inside that boundary once production conditions changed. That shifts the control point from periodic recertification to continuous observation of agent behaviour.
Identity observability becomes the missing control plane for agentic AI. Organisations that cannot inventory unmanaged AI agents cannot meaningfully govern them, because access that is not attached to an identity object is outside normal lifecycle and review mechanics. The practical effect is that AI governance and IAM are now coupled at the runtime layer.
For practitioners
- Inventory AI agents as identity objects Catalogue every agentic AI app, service, integration, and personal-account tool that can reach enterprise resources, including systems outside IdP, PAM, or secrets management.
- Compare declared policy to observed access Establish a continuous control that contrasts approved entitlements with actual systems called, secrets accessed, and data touched by each agent.
- Treat unmanaged agents as governance exceptions Create an explicit remediation path for agents that are known but not governed, and for shadow agents that have no reliable inventory record.
- Re-baseline broad agent permissions Review agents that were provisioned with broad access 'just in case' and remove privileges that are no longer reflected in current production use.
Key takeaways
- AI agent access governance fails when policy describes intent but production behaviour keeps changing underneath it.
- A large share of AI apps and services remain unmanaged, and even known agents can sit outside core identity controls.
- The control that changes outcomes is continuous observability of actual agent access, not heavier periodic review alone.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | The article centres on AI agents overstepping intended access boundaries. |
| Recommendation — Map runtime drift and privilege creep to ASI03 and monitor agent behaviour continuously. | ||
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | Agents accumulate access they no longer need, creating over-privilege. |
| NHI-08 — Environment Isolation | The article highlights unmanaged agents operating outside core governance boundaries. | |
| Recommendation — Audit agent entitlements for excess privilege and remove permissions not supported by observed use. Isolate unmanaged agent environments until their identity and access paths are brought under control. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The issue is a mismatch between intended access and actual runtime access use. |
| Recommendation — Continuously validate AI agent entitlements against observed access and revoke stale permissions. | ||
| NIST AI RMF | GOVERN — AI Governance and Accountability | The article is about governance structures for agentic AI access oversight. |
| Recommendation — Assign accountable owners for AI agent governance and require evidence of runtime access verification. | ||
Key terms
- Policy Reality Gap: The policy reality gap is the distance between documented intent and the state of controls in production. In identity and data security, that gap appears when reviews, revocations, and ownership processes exist on paper but fail to remove real access from sensitive systems.
- Continuous Behavioral Observability: Continuous behavioral observability is the practice of watching how identities and applications actually behave over time, then comparing that activity to expected patterns. It combines telemetry, correlation, and analytics to expose abuse that static rules may miss. In identity security, it is used to detect suspicious use of trusted accounts inside normal business operations.
- Scope drift: Scope drift is the gradual mismatch between what an integration was meant to do and what its credentials still allow it to do. It happens when permissions are not revalidated as business needs change, creating hidden over-privilege across SaaS and API-connected systems.
- Unmanaged agent: An AI agent or AI-enabled service that operates outside the organisation's identity and access control mechanisms, such as IdP, PAM, or secrets management. When an agent is unmanaged, it cannot be reliably inventoried, reviewed, or continuously governed as part of the identity estate.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org