TL;DR: The key issue is not certification theater but whether existing identity controls can govern agentic AI at runtime when agents access data, invoke tools and make decisions across environments, according to Zenity research. Zenity says it has reached FedRAMP “In Process” status as it moves toward federal authorization for AI agent security, positioning visibility, governance, runtime detection and compliance reporting for regulated government environments.
At a glance
What this is: Zenity says its AI agent security offering has entered FedRAMP review, highlighting how federal deployments force runtime governance for agents that access data, invoke tools and make decisions across environments.
Why it matters: This matters for IAM and security teams because AI agents are not just another application surface, they create identity, privilege and control problems that traditional governance models were never designed to manage at runtime.
Context
AI agent governance becomes a federal problem when an agent can act across systems, call tools, and make decisions while handling government data. The control question is no longer whether an organisation can inventory the agent, but whether it can govern the agent's runtime behaviour, access scope and escalation paths.
Zenity's FedRAMP "In Process" status is best read as a signal that agentic AI security is moving into regulated procurement and compliance workflows. For federal agencies, that shifts the discussion from pilot risk to authorisation evidence, continuous oversight and operational accountability across deployments.
Key questions
Q: How should security teams govern AI agents that can access enterprise systems?
A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring. The control set should include inventory, task-bound credentials, audit trails, and revocation paths. If an agent can call tools or touch production systems, it belongs in the same governance model as service accounts and other machine identities.
Q: Why do AI agents create risk even when they stay within approved permissions?
A: AI agents can be authorised correctly and still produce harmful outcomes because permission is not the same as intent or behavioural appropriateness. If an attacker manipulates the session mid-flight, the agent may keep acting inside scope while exfiltrating data, taking destructive steps, or chaining actions that no human would have approved.
Q: What breaks when AI agent access is managed like standard IAM access?
A: What breaks is the assumption that access is stable, reviewable, and tied to a single human owner. AI agents can call tools, change scope, and execute within runtime workflows, so standard IAM review cycles may miss the real moment of risk. Governance needs to move closer to execution and delegated authority.
Q: What should organisations evaluate before deploying autonomous AI agents in production?
A: Organisations should evaluate whether the agent has least privilege, clear tool boundaries, auditable actions, and real time detection for adversarial behavior. They also need defined escalation paths when the agent encounters suspicious content. If those controls are missing, the deployment can amplify access risk faster than a human operated workflow.
How it works in practice
Why runtime governance is different for AI agents
AI agents are software entities that can select actions, invoke tools and change execution timing based on context rather than a fixed script. That matters because static IAM assumptions break when privilege is not only granted at provisioning, but exercised dynamically during a session. In federal environments, the security problem is not merely whether an agent is approved, but whether its runtime decisions can remain bounded across data access, tool use and cross-environment actions. Traditional controls built for deterministic applications do not see the same sequence of choices. The result is a governance gap between initial authorisation and actual behaviour.
Practical implication: Treat runtime behaviour as the control point, not just onboarding or approval.
What FedRAMP changes for agentic AI governance
FedRAMP review introduces a compliance frame that forces evidence, repeatability and auditability around how AI agents are secured in government environments. For agentic AI, this elevates questions about discovery, posture management, continuous detection and governance reporting, because regulators and agency buyers will want proof that controls operate after deployment, not just at certification time. The article also points to the use of Knox Systems' precertified platform as part of the authorisation path, which shows how deployment architecture can influence the speed and shape of federal approval. The important point is that authorisation now intersects with runtime governance for AI agents, not only infrastructure readiness.
Practical implication: Map your AI agent control evidence to authorisation workflows before federal deployment begins.
How OWASP Agentic AI and NIST guidance frame the risk
Zenity points to NIST guidance and the OWASP Top 10 for Agentic Applications, which is appropriate because the threat model is about agent behaviour, tool misuse and trust boundaries. In this context, the relevant concerns are not generic model quality issues, but identity and privilege abuse, uncontrolled access paths and unexpected actions taken through approved tools. That makes agentic governance a cross-cutting discipline spanning identity, detection, and policy enforcement. The best frameworks here help teams ask where an agent can act, what it can reach, and how those permissions are constrained over time. The central question is whether governance is tied to the agent's live behaviour or only to its initial registration.
Practical implication: Use agentic-AI threat models to test where tool access and decision authority exceed intended scope.
NHI Mgmt Group analysis
AI agent governance becomes an authorisation problem, not just an AI policy problem. Once an agent can access data, invoke tools and choose actions at runtime, the security question shifts from policy approval to active privilege control. That is why federal review matters: it forces organisations to prove that governance operates where the agent behaves, not just where it was registered. Practitioners should expect runtime control evidence to carry more weight than declarative policy.
Static identity assumptions do not survive autonomous execution paths. Least privilege is usually defined at provisioning time, but agentic systems can traverse multiple tools and environments in one task. That means the useful unit of governance is no longer a single entitlement record but the live boundary around what the agent can decide to touch. The implication is that identity programmes must evaluate behaviour, scope drift and tool invocation together.
Runtime detection and prevention are now core to federal AI governance. The article's emphasis on visibility, posture management and governance reporting shows where the market is heading: control planes that observe agent actions continuously instead of relying on one-time approvals. For federal teams, this validates the need to tie identity, telemetry and policy enforcement into one operating model. Practitioners should prepare for controls that measure what the agent actually did, not only what it was allowed to do.
AI agent security is converging with regulated procurement requirements. FedRAMP review does not make the governance problem go away, but it changes what buyers will demand as evidence. In regulated environments, the quality of identity controls increasingly determines whether AI capabilities can be deployed at all. The practical conclusion is straightforward: if an agent cannot be governed, it cannot be safely scaled in federal missions.
Identity and autonomy are now inseparable in regulated AI deployments. The rise of agentic AI means that inventory alone is no longer sufficient because the risk sits in the decisions the system can make after authorisation. That pushes security architecture toward continuous control of actions, not just accounts. Practitioners should plan for AI agent governance to become part of the standard identity governance surface.
From our research library:
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security, according to the 2026 Infrastructure Identity Survey.
- Read next: AI Agent Observability, Audit and Incident Response Guide
What this signals
Runtime governance is becoming the deciding control layer for AI agents. Federal review pressure means inventory is not enough unless it is tied to live enforcement over data access, tool invocation and action scope. Teams should expect authorisation discussions to move toward continuous evidence rather than one-time approval.
Agentic AI identity is now crossing from pilot risk into regulated operations. As soon as agencies need compliance reporting and continuous detection, the control model has to reflect what agents do after deployment. That pushes identity programmes to measure behaviour, not just enrollment.
Governance programmes built on fixed privilege assumptions will struggle here. A design that assumes access can be granted, reviewed and then left in place is too slow for agents that can act across systems in a single workflow. The practical shift is toward controls that constrain tool use at the moment of execution.
For practitioners
- Define runtime control boundaries for each agent Map what data, tools and environments each agent can reach after initial approval, then document where those boundaries are enforced and monitored.
- Build evidence for federal authorisation workflows Collect discovery, posture, detection and reporting artefacts that can satisfy procurement and compliance review rather than relying on policy statements alone.
- Separate agent inventory from action authority Record every agent in inventory, but evaluate whether its tool access and decision paths align with the minimum authority needed for the task.
- Test tool-use scenarios for scope drift Review cases where an agent can chain tool calls or move across environments in a single workflow, because that is where hidden privilege expansion appears.
Key takeaways
- AI agents change the governance problem because they can act at runtime, not just authenticate and wait for instructions.
- FedRAMP review raises the bar for evidence, making continuous oversight and reporting part of the security case for federal AI deployments.
- Security teams need to align inventory, tool access and runtime enforcement if they want agentic AI to move from pilot status to regulated use.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | The article centres on AI agents, runtime authority and misuse of granted access. |
| ASI02 — Tool Misuse | Tool invocation across environments is a core risk in the article. | |
| Recommendation — Constrain agent identity and privilege boundaries before tool use can expand scope at runtime. Audit which tools an agent can invoke and block combinations that exceed intended task scope. | ||
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | AI agents are NHIs here, and the article focuses on access that exceeds task need. |
| Recommendation — Review agent permissions for excess reach and reduce standing access to the minimum required. | ||
| NIST AI RMF | GOVERN — AI Governance and Accountability | FedRAMP review and federal deployment both require formal governance and accountability evidence. |
| Recommendation — Establish accountable AI governance processes that produce evidence for review and oversight. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The post is about controlling agent permissions and authorisations in use. |
| DE.CM-09 — Monitoring for Unauthorized Personnel, Connections, Devices and Software | Continuous detection is part of the article's operational control model. | |
| Recommendation — Align entitlements to task scope and continuously verify that AI agent access stays authorised. Monitor AI agent activity for unauthorised connections, tool use and access patterns that drift from policy. | ||
Key terms
- Agentic AI: Autonomous AI systems capable of planning, deciding, and taking actions, including calling APIs, writing code, and orchestrating other agents, with minimal human oversight. Agentic AI introduces new NHI risks as agents must authenticate to external services.
- Runtime Protection: Runtime protection is a control model that observes application behavior while software is running and blocks unsafe actions as they occur. In Java estates, it helps distinguish active exploit paths from dormant vulnerable code, which is essential when patching is delayed or impossible.
- FedRAMP Ready Status: FedRAMP Ready status is an early federal cloud security milestone that indicates a service has completed the readiness phase and is eligible for listing on the FedRAMP Marketplace. It helps buyers identify services that have begun formal review, but it is not the same as full authorization for federal deployment.
- Tool Invocation: Tool invocation is an action where an AI agent calls an external system such as a database, API, or file service. Each invocation should be treated as an auditable identity action because it is the point where the agent can move data, trigger changes, or widen its reach across the environment.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 6, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org