TL;DR: Twenty-three percent of organisations have already experienced AI incidents while 79% have no dedicated AI governance team, and 51% cannot identify all AI agents in their systems, according to Pathlock research. The governance problem is no longer theoretical: AI agents are already executing approvals and workflow actions faster than most control structures can trace or explain.
At a glance
What this is: Pathlock’s research says AI agents are moving into core business processes faster than governance, visibility, and accountability controls are being built.
Why it matters: This matters because AI agents are behaving like high-impact non-human identities, so IAM, PAM, GRC, and security teams need controls for authorisation, traceability, and investigation, not just access.
By the numbers:
- 23% of organizations have already experienced AI incidents requiring investigation and remediation.
- 79% of organizations have no dedicated AI governance team or officer.
- 51% aren’t confident they know all the AI agents operating in their systems.
- 52% cannot verify actions AI agents execute across business systems.
👉 Read Pathlock's full AI Governance Gap Report on AI agents and enterprise control risk
Context
AI agent governance is now an identity problem as much as an automation problem. The core issue is not whether agents can help with work, but whether enterprises can authorise, trace, and reverse actions when those agents are operating across finance, procurement, HR, and other business systems. Pathlock’s report shows that many organisations are granting machine actors privileges that resemble human business authority without giving them equivalent governance.
The first-order failure is visibility. If teams cannot inventory AI agents, verify their actions, or reconstruct end-to-end activity across systems, then access review and audit evidence become incomplete by design. That creates a control gap between IAM, GRC, and operational reality, especially where AI agents touch records, approvals, and backend data stores.
Key questions
Q: What breaks when an AI agent can act across multiple business systems?
A: Traditional helpdesk controls break because they assume a human can be held at the centre of the workflow. Once an agent can check eligibility, place an order, and notify other systems, entitlement scope and auditability become the real control points. If those are unclear, the workflow becomes difficult to contain or review.
Q: Why do AI agents need separate governance from ordinary automation?
A: AI agents need separate governance because they can make context-sensitive decisions and execute actions across multiple systems with delegated access. Ordinary automation usually follows fixed rules with clear triggers. Agents can expand into new paths, so governance must cover autonomy, reach, and recovery, not only job scheduling or task completion.
Q: How do security teams know if AI governance is working?
A: Look for evidence that access decisions are reviewable, permissions are revocable, and exceptions are not becoming permanent. If the team cannot explain who owns an AI workflow, what it can reach, and when its access was last reviewed, governance is incomplete. Control maturity shows up in traceability, not adoption volume.
Q: Who is accountable when an AI agent triggers a banking error or compliance breach?
A: Accountability sits with the institution that granted the agent access, defined its scope, and failed to govern its actions. Banking regulators will focus on whether the bank can prove effective oversight, traceability, and control over both human prompts and autonomous actions.
Technical breakdown
Why AI agents behave like high-risk non-human identities
AI agents differ from ordinary automation because they can select actions, call tools, and chain steps based on context rather than a fixed script. That makes them closer to policy-bound software identities than simple bots. In business systems, the risk is not only access but delegated decision-making. When an agent can create records, approve transactions, or update master data, the effective control surface shifts from authentication to authorisation, traceability, and rollback. Practical implication: define AI agents as governed identities with explicit ownership and scoped authority, not as generic automation.
Practical implication: classify AI agents as governed identities and assign explicit owners, scopes, and audit expectations.
How governance fails when agents cross business systems
Cross-system workflows break conventional control assumptions because the evidence needed to explain an action is distributed across multiple applications. A single AI-driven workflow can touch ERP, procurement, database, and ticketing systems in one sequence, making point-in-time logs insufficient. This is where end-to-end traceability matters: teams need to know what decision was made, which tool executed it, and which upstream context influenced it. Practical implication: correlate identity, transaction, and application logs so every AI agent action can be reconstructed across systems.
Practical implication: build cross-system traceability before expanding agent permissions into core workflows.
Why financial controls become the real test for AI agent governance
When AI agents can approve transactions or modify vendor records, they are no longer only an IT governance issue. They become part of financial controls, fraud prevention, and auditability. That shifts the question from whether an agent can act to whether the organisation can prove it should have acted. In practice, this requires least privilege, approval boundaries, and real-time exception handling that reflect business risk. Practical implication: treat AI agent access to financial and master data as privileged access, with tighter controls than ordinary application access.
Practical implication: apply privileged access discipline to AI agents touching financial and master data.
Threat narrative
Attacker objective: The objective is to cause or conceal business-impacting actions through agent-driven authority that normal governance cannot easily trace or challenge.
- Entry occurs when AI agents are embedded into finance, procurement, HR, or database-connected workflows with broad delegated access.
- Escalation follows when the agent is allowed to approve transactions, modify records, or execute multi-step workflows without clear human oversight.
- Impact appears as unauthorised or untraceable business actions that affect financial integrity, auditability, and incident response capability.
NHI Mgmt Group analysis
AI agents are becoming governed identities, not just automation tools. Once an agent can approve, modify, and execute business actions, the right control question is no longer whether the workflow is automated. It is who owns the identity, what authority it has, and how its actions are evidenced. This is where IAM and GRC converge. Practitioners should treat agent identity as a first-class governance domain rather than an extension of scripting or RPA.
Traceability debt is the hidden control gap in agentic environments. The report’s finding that many organisations cannot trace or verify AI actions end-to-end points to a structural weakness, not a monitoring problem. When evidence is split across systems, accountability breaks even if access was technically granted correctly. AI governance debt: the accumulated gap between how fast AI agents are deployed and how slowly verification, audit, and exception handling mature. Practitioners should reduce this debt before expanding agent scope.
Financial-system access makes AI agent governance a business assurance issue. Once agents can touch records, approvals, and backend databases, the question moves beyond cyber hygiene into financial control integrity and regulatory defensibility. That means the same rigor applied to privileged human access should extend to agent permissions, especially where transactions can be created or changed without a durable review trail. Practitioners should map AI agent authority to financial control points, not just technical roles.
Without a complete agent inventory, every governance claim is provisional. The report shows that many organisations do not know all the agents operating in their environments, which means access review and audit evidence are incomplete before investigation even starts. This undermines both security and compliance reporting. Practitioners should build a defensible inventory of AI agents before expanding autonomy, because you cannot govern what you cannot enumerate.
The market is moving toward identity-aware AI governance, not generic AI policy. Organisations are discovering that policy statements alone do not contain agentic risk if identities, privileges, and transaction rights remain loosely controlled. The discipline is shifting toward mechanisms that combine identity governance, privileged access, and forensic traceability. Practitioners should expect agent governance to be judged by control evidence, not policy intent.
What this signals
AI governance is converging with identity governance. As AI agents move into approvals, record updates, and cross-system workflows, the operational question becomes whether the organisation can assign ownership, scope authority, and reconstruct every action. Teams that already manage privileged access and identity lifecycle controls are better placed to extend those disciplines to agents than teams relying on policy statements alone.
Inventory will become the first practical control. If you cannot enumerate AI agents, every downstream control is weakened because you do not know what must be reviewed, monitored, or restricted. The near-term programme shift is toward discovery, classification, and review of agent-driven access paths, especially where business systems and sensitive data are involved. Use that inventory to identify where traceability must be improved first.
The likely control benchmark for the next phase is not whether an agent is allowed to act, but whether the organisation can prove who authorised that action and whether it stayed within a bounded business task. That is where identity governance, privileged access, and audit evidence will need to work as one control plane.
For practitioners
- Build a complete AI agent inventory Catalog every AI agent, its owner, its data sources, its tool chain, and the business actions it can perform. Tie each agent to a named business system and a review cadence so unknown agents do not remain outside governance. Use the inventory to drive access review and exception management.
- Restrict agent authority to task-scoped privileges Remove broad permissions from agents that create records, approve transactions, or access backend databases. Replace standing access with narrow scopes, explicit approval boundaries, and time-bound entitlements for the specific workflow step being executed.
- Correlate identity and transaction logs Join IAM, application, and workflow telemetry so investigators can reconstruct what the agent did, which systems it touched, and what input influenced the action. End-to-end traceability should be measurable across business systems, not inferred from isolated logs.
- Treat AI agent access as privileged access Apply PAM-style governance to any agent that can approve payments, alter vendor records, or write to sensitive databases. Require tighter review, stronger segregation of duties, and explicit business ownership for those permissions.
Key takeaways
- AI agents are now operating as governed identities, which makes access, authority, and traceability the real control problem.
- The reported 23% incident rate and widespread lack of visibility show that agentic risk is already operational, not hypothetical.
- Enterprises need inventory, task-scoped privilege, and cross-system traceability before AI agents move deeper into financial and operational workflows.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Agent inventory and authority mapping align with the report's visibility gap. |
| NIST AI RMF | GOVERN | The article centres on governance, accountability, and ownership for AI systems. |
| NIST CSF 2.0 | PR.AC-4 | The report highlights overbroad access and weak control over agent permissions. |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege is essential where agents can approve or modify records. |
| MITRE ATT&CK | TA0004 , Privilege Escalation; TA0009 , Collection; TA0010 , Exfiltration | Agent abuse can escalate into cross-system access, data collection, and business impact. |
Model agent-driven workflows against privilege escalation and collection paths to narrow monitoring and containment.
Key terms
- AI Agent Identity: The digital identity used by an autonomous AI agent to authenticate to external systems, APIs, and services. Managing AI agent identities is an emerging and rapidly evolving area of NHI security.
- AI Governance: AI governance is the set of controls used to discover, classify, approve, restrict, monitor, and revoke AI-enabled access. It connects identity, data, and policy so organisations can manage what AI can reach, what it can share, and when it should be stopped.
- Identity Traceability: Identity traceability is the ability to link each action back to a specific identity, authorisation path, and time window. It is essential when humans, service accounts, and AI agents all operate in the same environment and auditors need a defensible record.
- Session-scoped privilege: Access that exists only for the current task or execution window and is removed when the session ends. For autonomous or agentic systems, this reduces standing privilege but also shifts the burden to runtime controls, because the identity may not persist long enough for traditional review cycles.
What's in the full report
Pathlock's full research covers the operational detail this post intentionally leaves for the source:
- Survey methodology and respondent mix across IT, compliance, and security decision-makers.
- The five governance priorities Pathlock identifies for AI agent deployment.
- The full breakdown of where organisations allow AI agents to create records, approve transactions, and access databases.
- The report download includes the evidence base behind the investigation and accountability findings.
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, secrets management, and identity lifecycle controls. It is built for practitioners who need to connect identity control design to real-world governance and audit expectations.
Published by the NHIMG editorial team on July 30, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org