By NHI Mgmt Group Editorial TeamBased on JumpCloud: “JumpCloud Research Reveals AI Agents are Operating Without Governance in Critical Workflows” (May 5, 2026)

TL;DR: AI agents are in production at 72% of organisations, yet 92% say they cannot scale them safely and 66% grant them equal or greater access than human employees, according to JumpCloud’s Agentic IAM Pulse Report. The core problem is not adoption, but governance designed for static identities being applied to actors that can act without consistent human oversight.


At a glance

What this is: This is a JumpCloud research report showing that AI agents are already in production at scale, but governance, supervision, and kill-switch controls are lagging behind their operational use.

Why it matters: IAM, IGA, PAM, and NHI teams need to treat agent access as a governed identity problem now, because deployment speed is already outrunning manual oversight and human-centric control assumptions.

By the numbers:

  • 72% of organizations have AI agents in use, but 92% report serious limits in safely scaling their deployments.
  • 66% of organizations grant AI agents equal or greater system access than human employees.
  • 55% of organizations lack a centralized kill switch to cut AI agent access across all systems.
  • 53% of organizations now manage more non-human identities than human employees.

Context

AI agents are now being used in production, which means they are no longer experimental tools but active identities participating in business workflows. The governance problem is not whether organisations will adopt them, but whether identity, access, and accountability controls can keep pace with their runtime behaviour.

In JumpCloud's research, the central failure is a mismatch between agent capability and oversight. The report shows that many organisations are already giving agents meaningful access to systems and sensitive processes, while still relying on control models built for slower, human-paced administration.


Key questions

Q: What breaks when AI agents have broader access than their tasks require?

A: Over-privileged agents break segregation of duties, weaken auditability, and expand blast radius across transactions, data lookups, and workflow triggers. In banking, a single agent identity can act with more operational reach than any human reviewer can safely justify.

Q: Why do human-in-the-loop approvals fail to scale for production AI agents?

A: Human-in-the-loop approval fails at scale because it depends on people seeing and judging actions fast enough to matter. Once agents are embedded in production workflows, the approval layer becomes too slow and too selective to cover every high-risk action. Governance has to move earlier, with pre-authorised limits and enforced policy boundaries.

Q: How do security teams know if AI governance is working?

A: Look for evidence that access decisions are reviewable, permissions are revocable, and exceptions are not becoming permanent. If the team cannot explain who owns an AI workflow, what it can reach, and when its access was last reviewed, governance is incomplete. Control maturity shows up in traceability, not adoption volume.

Q: Who should be accountable for AI agent actions in enterprise systems?

A: Accountability should sit with the team that owns the agent, its policies, and the connected tools, not only with the person who typed the original prompt. When a software actor can send messages, update records, and move data across systems, responsibility must follow the governed identity and its enforcement layer.


Technical breakdown

Why AI agent access breaks static governance models

AI agents are not just another workload because they can act inside business processes, take sequential actions, and interact with systems in ways that look operationally human but are not governed like humans. That creates a control mismatch: access is often assigned at provisioning time, while the actual risk emerges at runtime, when agents can execute tasks beyond the assumptions used to approve them. In identity terms, the problem is not merely authentication. It is that authorisation scope, supervision, and revocation logic were designed for relatively stable subjects, not for actors that may change behaviour across sessions and use cases.

Practical implication: Practitioners need to model agent access around runtime behaviour, not around the initial approval state.

Why human-in-the-loop approval does not scale to production agents

Human-in-the-loop approval is useful in testing, but it becomes brittle once agents are embedded in financial reporting, HR provisioning, or other operational workflows. The report shows approval rates falling sharply as use cases move from experimentation into business-critical deployment, which means the oversight layer is thinning exactly where impact is highest. That is a structural issue, not a process failure. If every high-risk action still requires human attention, the programme does not scale; if it does not require human attention, then the programme has to move governance earlier in the lifecycle.

Practical implication: Governance must shift from runtime review to pre-authorised boundaries, policy constraints, and monitored escalation paths.

What the access paradox means for identity architecture

The access paradox is that many organisations are granting AI agents equal or greater access than employees while simultaneously saying they cannot scale them safely. That pattern suggests identity architecture is optimising for deployment speed rather than controllability. Once agent populations outnumber humans or become spread across multiple business systems, manual administration becomes insufficient and fragmented accountability becomes the norm. The result is not only over-permissioning but also loss of ownership, because no single control plane is responsible for the full agent lifecycle from creation to offboarding.

Practical implication: Identity teams should unify agent inventory, authorization, and offboarding into a single governed lifecycle.


Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

AI agent governance is now an identity architecture problem, not an AI experimentation problem. When 72% of organisations already have agents in production and 92% cannot scale safely, the issue is no longer pilot readiness. The control plane has to govern non-human decision makers as first-class identities, because business use has already moved beyond the sandbox. Practitioners should treat this as a core IAM and NHI design issue, not a niche AI oversight topic.

Human-paced approval models are collapsing under agent-paced execution. Access review, escalation approval, and supervision workflows assume an access state that persists long enough for a person to notice it. That assumption breaks when agents are active inside operational workflows and can be granted, use, and consume privilege faster than review cycles can react. The implication is that governance has to move to issuance, policy, and containment boundaries rather than relying on after-the-fact human checks.

Over-privileged AI agents create identity blast radius, not just policy noncompliance. The report's 66% access figure shows that many organisations are normalising access levels that exceed human counterparts. That is a governance debt because agent compromise or misuse can propagate through business systems with no corresponding accountability path. The named concept here is identity blast radius: the scope of damage created when a non-human identity is allowed to act more broadly than the programme can observe or constrain.

Accountability for agent actions is fragmenting into a control gap that identity leaders cannot ignore. Only 17% of organisations designate a security leader accountable for AI agent actions, while most accountability falls to IT by default. That is not a role chart problem alone. It means ownership of agent lifecycle, privilege decisions, and kill-switch authority is not yet mapped to a durable governance model. Practitioners should formalise ownership before agent volumes make manual accountability impossible.

The kill switch vacuum is the clearest sign that agent governance is still immature. If 55% of organisations cannot cut access across all systems from one place, then revocation is not a lifecycle control, it is a best-effort response. That matters because agent risk is defined by speed, scale, and propagation. A governed NHI programme needs centralized offboarding semantics, or access remains active long after the organisation believes it has been contained.

From our research library:

What this signals

Identity blast radius: agent governance is now shaped by how far an identity can act before the programme can observe and constrain it. When access is broader than supervision, the relevant control is not just review cadence but the size of the action surface each agent is allowed to touch.

A practical turning point for IAM and NHI teams is the move from manual administration to lifecycle governance that can inventory, authorize, and revoke agent access centrally. Without that shift, the control stack will continue to assume a human operator behind behaviours that are increasingly machine-timed.

The 70% figure from the 2026 Infrastructure Identity Survey is a reminder that agent access is already normalising faster than most governance programmes can absorb. That makes pre-authorisation, ownership, and central offboarding the decisive programme questions, not future-state aspirations.


For practitioners

  • Define agents as governed identities Create an inventory that treats every AI agent as a first-class identity with owner, purpose, scope, and lifecycle status recorded from day one.
  • Constrain agent access before production use Set pre-approved system boundaries, least-privilege scopes, and explicit escalation conditions before agents are allowed into financial, HR, or customer workflows.
  • Replace ad hoc approval with policy guardrails Use policy-based controls for high-risk actions so the agent can only operate inside bounded authority rather than depending on a human to approve each step.
  • Build a centralized offboarding path Ensure access can be revoked across all connected systems from one control point when an agent is retired, misbehaving, or no longer in scope.

Key takeaways

  • AI agents are already in production, but many organisations have not updated identity governance to match their operating speed or autonomy.
  • The most important gaps are over-privileged access, fragmented accountability, and the absence of a centralized kill switch.
  • IAM and NHI teams need a governed lifecycle for agents that starts with inventory and ends with revocation across all connected systems.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseThe article centers on agents receiving excessive access and weak control boundaries.
Recommendation — Apply ASI03 to constrain agent privileges to explicit, auditable business boundaries.
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIAgents are being granted equal or greater access than human employees.
NHI-01 — Improper OffboardingThe kill-switch gap shows offboarding and revocation are not centralized.
Recommendation — Review agent entitlements against NHI-05 and remove any access beyond task scope. Use NHI-01 to enforce centralized revocation when agents are retired or out of scope.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementThe report is about governing non-human access credentials and their lifecycle.
Recommendation — Apply IA-5 to manage agent credentials, rotation, and revocation through a controlled lifecycle.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe core issue is whether agent permissions are scoped and governed appropriately.
Recommendation — Use PR.AA-05 to define and enforce least-privilege permissions for every agent identity.

Key terms

  • Agentic IAM: Agentic IAM is identity and access management designed for environments where AI agents make independent decisions and take actions. It combines authentication, authorization, delegation, monitoring, and revocation so agent autonomy is constrained by policy, context, and accountability rather than open-ended system trust.
  • Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
  • Centralized kill switch: A centralized kill switch is a single revocation mechanism that can cut off an agent's access across systems, APIs, and downstream dependencies. It matters because production agents often hold many credentials or pathways at once, and manual disablement across separate tools is too slow to be reliable.
  • Human-in-the-Loop Approval: A review step where a person explicitly approves a high-risk access request before it is granted. It is most useful for exceptional privilege expansion, not for routine automation, because the goal is to catch unusual requests without turning every machine action into a manual process.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org