TL;DR: AI agents are already operating across enterprise systems with limited oversight, and Saviynt argues that 92% of organisations have limited or no visibility into their AI identities while 53% report agents exceeding intended permissions. The security model shifts from periodic review to continuous runtime authorisation because autonomous behaviour can outpace human-paced governance.
At a glance
What this is: This is a governance analysis of AI agent identity security, arguing that discovery, ownership, and continuous runtime authorisation must replace periodic IAM assumptions for autonomous systems.
Why it matters: It matters because IAM, IGA, PAM, and NHI teams now have to govern AI agents that act at machine speed across multiple resources without fitting human review cycles.
By the numbers:
- In fact, 92% of organizations report limited or no visibility into their AI identities.
- AI and other non-human identities now outnumber human identities by as much as 144 to 1.
- 53% of organizations report that AI agents exceed their intended permissions.
👉 Read Saviynt's analysis of AI agent identity governance and runtime controls
Context
AI agent identity governance is becoming a core identity security problem because autonomous systems are already accessing data, interacting with tools, and taking actions inside enterprise environments. The central gap is not whether AI will be used, but whether organisations can still govern what those identities can do once they are operating.
Traditional IAM assumptions break down when an identity can move across connected resources, expand its effective access during a session, and act without human approval at each step. For identity teams, the practical issue is how to define ownership, limit scope, and validate behaviour continuously when the actor is not a person.
The article frames this as a shift-left governance problem for AI, but the deeper issue is programme design: AI identities need discovery, lifecycle governance, and runtime authorisation together. That is typical of early-stage AI adoption across large enterprises, where shadow AI and inconsistent control ownership are already outpacing formal governance.
Key questions
Q: How should security teams govern AI agents that can access enterprise systems?
A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring. The control set should include inventory, task-bound credentials, audit trails, and revocation paths. If an agent can call tools or touch production systems, it belongs in the same governance model as service accounts and other machine identities.
Q: Why do AI agents create more risk than traditional automation?
A: AI agents create more risk because they can interpret context, choose actions, and invoke tools autonomously. Traditional automation follows fixed rules, but an agent can be manipulated into using its own authority in unintended ways. That makes permission scope, tool boundaries, and monitoring more important than model accuracy alone.
Q: What are the signs that AI governance is failing in the enterprise?
A: Common warning signs include rapid growth in AI use without matching policy coverage, sensitive files being copied into personal accounts, and a large share of AI apps carrying high or critical risk. Another indicator is weak visibility into who is using which tools and what data they are sending. If teams cannot answer those questions, governance is not working as intended.
Q: How do AI agent access reviews differ from human access reviews?
A: AI agent access reviews should focus on runtime behaviour, ownership, and the scope of delegated tool use, not employee lifecycle events. Human reviews assume stable job roles and enduring entitlements. Agent reviews must instead ask whether the agent still exists, whether its tasks changed, and whether the access path is still justified for that specific execution pattern.
Technical breakdown
AI identity discovery and shadow AI inventory
Discovery is the prerequisite for governance because you cannot define ownership, scope, or risk if you do not know which AI identities exist. In this context, AI identities include agents, copilots, and tools connected to data sources or business systems. Shadow AI emerges when employees adopt tools outside approved processes and when developers embed AI into applications without central oversight. A usable inventory has to identify the identity, the data it can reach, the systems it touches, and the team responsible for it. That is an identity governance problem, not just an application discovery task.
Practical implication: build an authoritative AI identity inventory before attempting policy enforcement or access certification.
Why static permissions fail for autonomous AI agents
Static permissions assume access needs remain stable long enough for periodic review to be meaningful. Autonomous AI agents do not behave that way. They can use one legitimate connection to reach other systems or data, expanding effective access without a new human request. That makes authorization a runtime problem, not a provisioning problem. In identity terms, the unit of control shifts from a fixed entitlement to a continuously changing action path. This is why least privilege must be evaluated against actual agent behaviour, connected tools, and task context rather than only initial assignment.
Practical implication: treat AI agent access as dynamic and re-evaluate every connected path that could widen scope during execution.
Continuous authorization and intent-aware runtime control
Intent-aware runtime authorization checks whether an agent’s action matches the purpose for which it was granted access. That matters because valid credentials do not automatically mean every requested action is appropriate. The article also points to fine-grained access controls so an agent can use an authorised system without inheriting every object inside it. Together, those controls create a boundary between what the agent is allowed to do and what it is actually trying to do at runtime. For identity programmes, that is the practical bridge between governance policy and machine-scale execution.
Practical implication: pair runtime intent checks with fine-grained authorization so agents are constrained by both purpose and resource scope.
Threat narrative
Attacker objective: The objective is to expand effective access and action scope through trusted AI identities until human oversight no longer constrains the outcome.
- Entry occurs when employees or developers introduce AI tools and agents through sanctioned and unsanctioned channels, creating identities that can access enterprise data and systems.
- Escalation happens when an autonomous agent uses legitimate access to reach connected tools or resources beyond its original purpose without returning for human approval.
- Impact follows when the agent exceeds intended permissions and performs actions at machine speed across multiple systems, widening exposure before governance catches up.
Breaches seen in the wild
- Meta AI Instagram Account Takeover — 20,225 Instagram accounts hijacked via compromised Meta AI support chatbot with overprivileged access.
- Replit AI Tool Database Deletion — Replit vibe coding AI assistant deletes live production database and creates 4,000 fake user records.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
AI identity governance is now a first-class identity discipline, not an add-on to application security. The article is right to frame discovery, ownership, and runtime control as identity problems because AI agents already act like non-human identities with expanding reach. That means IAM, IGA, PAM, and NHI teams all need to share the same governance model instead of treating AI as a separate silo. The practitioner implication is simple: AI identities must enter the same governance inventory as service accounts, tokens, and privileged access.
Shadow AI creates a discovery problem before it creates a policy problem. You cannot certify, constrain, or terminate what you cannot enumerate. The fact that 92% of organisations have limited or no visibility into AI identities shows that most programmes are still operating blind, which is why governance gaps appear first as inventory failures. Practitioners should read this as a signal that discovery must be continuous and ownership must be explicit.
Periodic access review is a human control model that does not survive autonomous runtime behaviour. Access review processes were designed for access that persists long enough to be observed and certified. That assumption fails when an autonomous agent can gain, combine, and use access within a single operating window. The implication is not just to add more reviews, but to rethink whether review cadence can govern machine-speed execution at all.
Intent-aware runtime authorization is the right named concept for this problem space. It captures the shift from authorising an identity once to validating whether each action still matches the reason the identity exists. That aligns with OWASP Agentic AI Top 10 and NIST AI Risk Management Framework thinking, but the operational point is narrower: AI governance must inspect purpose, tool reach, and resource scope at runtime. Practitioners should treat this as the control layer that sits between policy and autonomous action.
AI and NHI governance are converging faster than most operating models admit. The article notes that AI identities and non-human identities are being discovered together, and that matters because the same control failures recur across service accounts, API keys, and agents. Organisations that still separate AI governance from NHI governance will miss shared patterns such as overprivilege, scope drift, and weak offboarding. The practical conclusion is to govern AI agents as part of the broader non-human identity estate, not as an isolated innovation track.
From our research:
- 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures, according to Ultimate Guide to NHIs.
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.
- That offboarding gap is why lifecycle governance belongs inside AI and NHI programmes, not beside them, and why Top 10 NHI Issues is a useful next resource.
What this signals
Intent-aware runtime authorization: this is the control pattern that will separate AI governance theatre from operational governance. As AI identities spread, the programme question becomes whether each action is evaluated against purpose and scope in real time, not whether the identity was approved months earlier.
The operational risk is not limited to AI itself. Non-human identity estates already suffer from excess privilege and weak offboarding, and the same governance failures will recur if AI agents are left outside the existing lifecycle model. That is why AI identity work should be folded into the broader NHI programme, with shared ownership and shared control language.
With 97% of NHIs carrying excessive privileges, according to the Ultimate Guide to NHIs, the problem is no longer inventory alone. AI agents add dynamic behaviour to an already overprivileged identity landscape, so teams should expect the next failure to come from scope expansion rather than simple credential theft.
For practitioners
- Inventory every AI identity and owner Create a live register of agents, copilots, and embedded AI tools that records system access, data reach, business owner, and technical owner. Reconcile it against approved tool lists and application inventories so shadow AI can be isolated quickly.
- Move AI access decisions to runtime Use intent-aware runtime authorization and fine-grained resource controls so an agent is checked while it acts, not only when it is provisioned. Align each allowed action to a declared purpose and a bounded resource set.
- Treat AI agents as first-class identities Bring agents into the same governance processes used for non-human identities, including lifecycle ownership, termination, and periodic review triggers. Do not leave them inside application teams with no accountable identity owner.
- Test for scope expansion paths Map how a single legitimate AI connection could reach additional systems, datasets, or tools without a new approval step. Prioritise the paths where an agent can silently expand beyond its original task.
Key takeaways
- AI agents change identity governance because they can act across systems at runtime, not just authenticate once and wait for review.
- Visibility is the current failure point, with most organisations still unable to see or own their AI identities clearly enough to govern them.
- The practical response is continuous runtime control, paired with explicit ownership and lifecycle management for every AI identity.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF, NIST Zero Trust (SP 800-207) and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | The article focuses on autonomous AI identities and runtime control. | |
| Recommendation: Map agent behaviour and tool use to OWASP agentic risk areas before broad deployment. | ||
| OWASP Non-Human Identity Top 10 | NHI-03 | Discovery, ownership, and lifecycle control are central to this article. |
| Recommendation: Inventory AI identities, assign owners, and enforce lifecycle controls for every agent. | ||
| NIST AI RMF | GOVERN | AI governance and ownership are the main programme themes. |
| Recommendation: Define accountability and oversight for AI identity decisions under GOVERN. | ||
| NIST Zero Trust (SP 800-207) | Section 2.1 | The article stresses continuous validation and limited trust for AI agents. |
| Recommendation: Apply zero trust principles to AI actions and revalidate access continuously. | ||
| NIST CSF 2.0 | PR.AC-4 | Least-privilege access and authorization are core to the analysis. |
| Recommendation: Align AI agent entitlements to PR.AC-4 and review them against task scope. | ||
Key terms
- AI Identity Scope: The set of resources, tools, and credentials an AI system can access in order to complete a task. Proper scope is narrower than generic user access because autonomous systems can chain actions quickly, making overbroad permissions far more damaging than in human-only workflows.
- Intent-aware runtime authorization: A control model that evaluates an action at the moment it is about to occur, using identity, context, policy, and inferred purpose. It is designed to stop AI agents and other non-human actors from taking approved access and turning it into unapproved behaviour during execution.
- Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
- Scope drift: Scope drift is the gradual mismatch between what an integration was meant to do and what its credentials still allow it to do. It happens when permissions are not revalidated as business needs change, creating hidden over-privilege across SaaS and API-connected systems.
What's in the full article
Saviynt's full blog post covers the operational detail this post intentionally leaves for the source:
- How its AI identity security workflow separates discovery, ownership, and runtime control into distinct steps
- How intent-aware runtime authorization is applied to agent actions in practice
- How the vendor describes continuous governance across creation, change, and termination of AI identities
- How its control plane is positioned for AI and NHI visibility across connected environments
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on September 5, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org