By NHI Mgmt Group Editorial TeamBased on Cyera: “Cyera Becomes One of the Top 10 Fastest-Growing Companies, Powering the New Era of AI and Data Security” (November 5, 2025)

TL;DR: A 2025 AI Data Security Readiness report found 76% of respondents view autonomous AI agents as the hardest to secure, while enterprises have now been helped to discover and secure over 4 million agents, according to Cyera. That gap matters because identity, data, and AI controls are converging faster than most governance models can track.


At a glance

What this is: Cyera argues that the surge in AI agents is stretching legacy data security controls, with autonomous agents emerging as the hardest risk class to secure.

Why it matters: For IAM and security teams, this matters because agent identity, data access, and authorisation context are converging, forcing governance to move beyond static data controls.

By the numbers:

  • Cyera says autonomous AI agents are the hardest to secure for 76% of respondents in its 2025 AI Data Security Readiness report.
  • Cyera says its platform has protected more than 530 million identities.

Context

AI agent security is becoming a data control problem because agents do not just consume information, they act on it, transform it, and move it through workflows at machine speed. Once that behaviour is allowed to scale, data security posture management on its own is no longer enough to explain or constrain risk.

Cyera frames the issue as a shift from visibility into data alone toward visibility into how AI models and agents interact with that data. For IAM and governance teams, the practical question is no longer whether sensitive data can be found, but whether access, use, and response conditions are intelligible when the actor is an AI agent.


Key questions

Q: How should security teams govern sensitive data used by AI systems?

A: Security teams should treat AI as a data consumer that needs policy boundaries, not just authentication. Classify sensitive data, define which datasets may enter AI workflows, and monitor outputs, logs, and downstream reuse. If governance stops at login, the organisation can approve access while still losing control of the data itself.

Q: Why do AI coding agents make application security harder to govern?

A: AI coding agents increase risk because they can generate large volumes of code quickly, often optimised for function over security. They also replicate insecure patterns, propagate shared thread context, and create a false sense of trust in generated output. Governance must shift toward explicit requirements, runtime validation, and repeatable review gates.

Q: What breaks when data classification is incomplete in AI environments?

A: When classification is incomplete, policy enforcement becomes unreliable because the security stack is operating without a trustworthy view of the data estate. AI systems can then see, combine, or surface information that the organisation never intended to expose. The practical failure is not just bad reporting, but weak guardrails and unexpected reachability.

Q: Should AI security be managed separately from IAM and data protection?

A: No. AI security becomes practical only when it is absorbed into existing identity and data governance. The same entitlement reviews, access approvals, and data classification rules that govern other sensitive systems need to apply to AI retrieval paths as well.


Technical breakdown

Why data security posture management is not enough for AI agents

Data security posture management, or DSPM, is built to find and classify sensitive data, then expose where it resides and who can reach it. AI agents complicate that model because access is no longer only a matter of location or permission. Agents can query, combine, and reuse data inside dynamic workflows, so the control boundary shifts from static discovery to runtime context. If the security model stops at finding sensitive data, it misses how agent behaviour changes the effective exposure of that data once an AI system starts acting on it.

Practical implication: expand control coverage from data location to data use by AI agents.

How identity context changes the meaning of data access

Cyera's framing joins identity and data because the same dataset can be safe or risky depending on which identity, including an AI agent, is using it. That matters for authorisation models that assume stable human users or predictable service accounts. An agent can appear legitimate while still creating an inappropriate interaction pattern, especially when the model has business context that exceeds the original access assumption. The technical problem is not only whether the agent authenticated, but whether the resulting data use fits the intended purpose and risk boundary.

Practical implication: evaluate agent access decisions in the same workflow as data classification and authorisation.

What unified AI and data security platforms are trying to close

Cyera's description of a unified platform reflects a broader architecture trend: enterprises want one place to see data exposure, agent activity, and policy enforcement. In practice, that means combining classification, detection, and response across cloud, SaaS, databases, and AI ecosystems. The architectural challenge is that these environments generate different signals, but the governance question is the same: which interactions are appropriate, and which should be blocked or investigated. The value is not centralisation for its own sake, but a control plane that can reason across identities, prompts, and sensitive records at the same time.

Practical implication: design policy enforcement so AI, data, and identity signals can be evaluated together.


NHI Mgmt Group analysis

AI agent growth exposes a data control boundary problem, not just a visibility problem: The article shows that enterprises can now discover and classify enormous data estates, yet still struggle to govern what autonomous systems do with that data. That gap matters because AI agents create risk through use, not just storage or location. The practitioner conclusion is that data security programmes have to account for runtime behaviour, not only static exposure.

Agent-intent ambiguity is becoming the new governance gap: The article's most important signal is that security teams can see the agent and still not know whether the interaction is appropriate. That is not a tooling shortfall alone, it is a policy problem. A named concept here is agent-use ambiguity: the condition where an organisation can classify the data but cannot reliably judge whether an AI agent's access pattern fits the business purpose. The practitioner conclusion is that data classification without use-policy context will increasingly understate risk.

AI security and identity governance are converging because the actor is no longer passive: Traditional IAM assumptions work best when identities request access and then wait for humans or scheduled jobs to act. AI agents break that rhythm because they can initiate, chain, and repeat data interactions at runtime. That means the control issue is not merely privilege assignment but behavioural containment across the agent, the data, and the workflow. The practitioner conclusion is that AI governance and identity governance now need shared enforcement logic.

Speed of discovery does not equal speed of control: The article highlights rapid scanning and large-scale discovery, but scale only helps if governance can follow the same pace. That is where many programmes still break: they find sensitive information and connected actors faster than they can validate whether those relationships are acceptable. The practitioner conclusion is that the next maturity step is not broader discovery, but faster policy decisions tied to the actual interaction path.

Autonomous AI agents are not just another machine identity class: They are decision-making actors that can change how data is accessed and used within a session. OWASP-NHI, NIST-CSF, and OWASP-AGENTIC each matter here because the risk spans identity lifecycle, access permissions, and agent behaviour. The practitioner conclusion is that teams should stop treating AI agents as an overlay on data security and start treating them as governed actors in the access model.

From our research library:

What this signals

Agent-use ambiguity: Security teams are moving past the question of whether they can find sensitive data and into the harder question of whether an AI agent's interaction with that data is acceptable. That shift changes the operating model for governance because control now has to evaluate use, not only possession or location.

A practical programme response is to align data classification, agent telemetry, and identity policy in the same review cycle. If those signals stay separated, teams will continue to discover risk faster than they can decide what the agent is actually allowed to do.


For practitioners

  • Map AI agent data interactions Inventory which models and agents can reach sensitive data, which prompts they process, and which downstream workflows they trigger. Separate mere data discovery from actual use paths so governance reflects runtime behaviour, not only storage locations.
  • Bind authorisation to agent purpose Define acceptable agent actions by business purpose, data class, and workflow context, then enforce those rules where the agent requests or transforms data. Treat a legitimate login as insufficient if the interaction itself is outside policy.
  • Unify classification with runtime detection Correlate data classification signals with agent telemetry, prompt activity, and access events so inappropriate use patterns can be seen in context. This reduces the blind spot between knowing where data lives and knowing how it is being used.
  • Review AI governance alongside IAM governance Bring IAM, data security, and AI governance owners into the same decision path for agent access policies, escalation thresholds, and exception handling. The key issue is shared accountability for what an agent is allowed to do with sensitive data.

Key takeaways

  • AI agents change the control problem because they act on data, not just access it.
  • Discovery at scale does not resolve governance if teams cannot judge whether an agent's runtime use is appropriate.
  • The strongest response is to connect identity, data classification, and policy enforcement in one operating model.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and CSA Cloud Controls Matrix set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseAI agents blur access boundaries and can misuse assigned privileges at runtime.
Recommendation — Constrain agent privileges and monitor runtime actions for identity and privilege abuse.
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIAI agents and their supporting identities can inherit access beyond the use case.
Recommendation — Review agent-related identities for excess privilege and remove access not tied to purpose.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article centres on governing who or what may interact with sensitive data.
Recommendation — Align data access permissions with role, purpose, and runtime authorisation context.
NIST SP 800-53 Rev 5IA-9 — Identification and Authentication (Non-Organizational Users)Agent and platform access often depends on machine and external identity authentication.
Recommendation — Apply machine authentication controls to AI agents before granting data access.
CSA Cloud Controls MatrixIAM — Identity and Access ManagementThe article spans cloud data, AI ecosystems, and identity governance in one control plane.
Recommendation — Use IAM controls to govern which AI agents can access and act on sensitive data.

Key terms

  • Data Security Posture Management: Data Security Posture Management, or DSPM, is the continuous discovery and monitoring of where sensitive data lives, how it is exposed, and where policy gaps exist. Its value rises when it feeds remediation rather than generating findings alone, especially in environments where AI expands the number of data paths.
  • AI Agent Governance: AI Agent Governance is the set of policies, controls, and oversight practices used to direct how autonomous software agents behave. It defines allowed actions, approval paths, identity boundaries, logging, monitoring, and accountability so agent decisions remain traceable, constrained, and aligned with business, security, legal, and ethical requirements.
  • Agent-Use Ambiguity: The condition where an organisation can identify the data and the agent, but cannot confidently determine whether the agent's use of that data is appropriate. It is a governance gap that appears when classification exists without enough context to evaluate runtime intent or acceptable behaviour.
  • Runtime Policy Enforcement: Runtime policy enforcement evaluates a request at the moment it is executed instead of relying only on preconfigured permissions. For AI agents, this allows decisions to reflect current context, target sensitivity, and behavioural signals rather than static assumptions.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org