By NHI Mgmt Group Editorial TeamBased on Zenity: “Securing the AI That Runs the Enterprise: Zenity + ServiceNow SecOps” (March 24, 2026)

TL;DR: AI agents now access sensitive data, invoke workflows, and make multi-step decisions across enterprise systems, creating a non-deterministic risk model that traditional security playbooks were not built to handle, according to Zenity. The governance problem is no longer discovery alone, but controlling behaviour that changes at runtime and spans systems, permissions, and data flows.


At a glance

What this is: This is Zenity’s analysis of why AI agent security has to live inside SecOps, with the key finding that agents introduce dynamic, cross-system risk that static controls cannot keep up with.

Why it matters: IAM, IGA, PAM and security teams need to treat AI agents as governed identities with runtime behaviour, or they will miss privilege drift, risky integrations and hidden access paths.


Context

AI agent security is the discipline of governing software entities that can act, call tools and move across systems without behaving like static applications. In this article, the governance gap is that existing security models assume predictable access patterns, while agents can change their actions, dependencies and data use at runtime.

The article’s central claim is that SecOps must become the operating plane for agent security, because discovery alone does not control risk. For identity teams, that means the relevant question is not whether an agent exists, but whether its permissions, integrations, and lifecycle are continuously visible and enforceable.


Key questions

Q: What breaks when AI agent security is handled like ordinary application security?

A: Application security assumes a relatively stable workload boundary and a predictable request path. AI agents can select tools, access data, and continue executing in ways that change the path mid-workflow. When teams treat them like static apps, they miss the identity and authorisation layer where real risk appears.

Q: Why do AI agents create a different data security problem from standard user workflows?

A: AI agents can operate faster than human review, chain multiple tool calls, and move data across systems without a pause for approval. That means the control point must shift from after-the-fact monitoring to continuous enforcement, with identity, context, and destination all considered before data is released.

Q: What are the signs that AI posture management is failing?

A: Common signs include exposed notebooks, untracked models or datasets, inconsistent access policies, and security teams lacking a unified view of activity across tools and clouds. If suspicious configuration changes, unauthorized dataset use, or privilege escalation are not surfaced quickly, posture management is not keeping pace with the environment. That usually means risk is escalating silently.

Q: How should teams govern AI agents that run across multiple runtimes?

A: Teams should govern them with a shared trace schema, consistent evaluation criteria, and clear ownership for tool access. Portability changes the execution layer, but it does not remove the need to prove what the agent did, why it did it, and whether the behaviour stayed inside policy across environments.


Technical breakdown

Why static controls fail for autonomous AI agents

Static controls assume the identity, permissions and operational purpose of a system remain sufficiently stable to review and certify after the fact. AI agents break that model because they can invoke tools, select actions, and traverse workflows in ways that are not fully knowable at provisioning time. That creates a moving target for access governance: the risk is not only who the agent is, but what it becomes capable of during runtime. In identity terms, the control problem shifts from assigned access to observed behaviour.

Practical implication: govern agents with runtime context, not only provisioning records.

Deep visibility across agent inventory, permissions and dependencies

The article treats visibility as more than discovery. A useful inventory must connect an agent to its workflows, external systems, data sources, permissions, credentials and dependencies so security teams can understand how it behaves inside the environment. That matters because risk often emerges from the combination of components rather than any single one. For SecOps, the relevant technical object is not just an agent record, but an identity graph that shows what it can touch, what it depends on, and where it can drift.

Practical implication: map agents as identity graphs, not isolated objects.

Continuous posture management for changing agent behaviour

AI Security Posture Management for agents is essentially a continuous control loop. It looks for excessive permissions, unsafe prompt logic, risky integrations, drift, and compliance gaps as the agent and its environment change. This is a different operating model from periodic review, because the exposed condition can appear between review cycles. In practice, posture management becomes a live signal source for prioritisation, triage and containment inside SecOps, rather than a one-time assessment artifact.

Practical implication: feed agent posture signals directly into SecOps triage and prioritisation.


NHI Mgmt Group analysis

SecOps-native governance is the right control plane for AI agents because the risk is operational, not just architectural. The article’s central point is that agents do not sit still long enough for static security assumptions to remain valid. Once agents can invoke workflows, call APIs and change behaviour in context, the security model has to move into the operational workflow where investigations and remediation already happen. The practitioner conclusion is that agent governance must be embedded where risk is actually handled, not bolted on as a separate review process.

Continuous inventory is the minimum viable control, but inventory alone is not governance. Knowing an agent exists is useful only if the inventory also captures dependencies, data access, permissions and execution context. That is the difference between counting agents and governing them. The practitioner conclusion is that agent programmes should be measured by contextual completeness, not by raw asset counts.

Non-deterministic behaviour creates an identity blast radius that traditional access models do not describe well. AI agents can chain actions across systems, which means the impact of excessive privilege is not limited to a single application boundary. The governance issue is that the unit of risk becomes the agent’s possible action path, not just its configured role. The practitioner conclusion is to treat agent privilege as a dynamic exposure surface, not a static entitlement list.

AI agent security is converging with SecOps because risk signals now need to be prioritised, investigated and remediated continuously. The article shows a market direction where identity, posture and response are collapsing into one operational loop for autonomous systems. That trend favours programmes that can correlate context across environments, because isolated controls will not keep pace with cross-platform behaviour. The practitioner conclusion is to align agent governance with SecOps workflows rather than separate it into a niche control tower.

Policy consistency across environments matters more than platform locality for agent governance. The article explicitly pushes beyond one platform, which reflects a broader reality: agents live in SaaS, custom systems and endpoints, and their control model has to travel with them. That makes cross-platform metadata, consistent language and lifecycle coverage central to governance. The practitioner conclusion is to standardise control definitions before expanding agent deployment further.

From our research library:

What this signals

SecOps becomes the control plane for agent governance: once AI agents can invoke workflows and external systems, the useful control is no longer discovery alone but continuous prioritisation, triage and remediation inside the security operations process.

Agent inventory has to become contextual: teams need to know not just that an agent exists, but what it can access, what it depends on and how its behaviour changes as integrations and permissions evolve.

69% of security leaders agree identity management must fundamentally shift to address agentic AI systems, according to the 2026 Infrastructure Identity Survey, which is a strong signal that periodic review models will not be enough for autonomous workflows.


For practitioners

  • Define a SecOps operating model for AI agents Place agent inventory, risk scoring and remediation inside the workflow security teams already use for triage and incident handling.
  • Build a contextual agent inventory Track each agent’s workflows, topics, actions, APIs, integrations, identities, permissions, credentials, data sources and dependencies.
  • Continuously assess agent posture Look for excessive permissions, unsafe prompt logic, broken integrations, compliance gaps and drift as agents and their environments change.
  • Correlate agent signals across platforms Use common metadata and policy language so risk found in one environment can be compared and acted on consistently in another.
  • Treat agent lifecycle as an always-on control Govern creation, runtime, dependency change and retirement as one lifecycle rather than separate tickets owned by different teams.

Key takeaways

  • AI agents change the security problem from static access management to continuous governance of runtime behaviour.
  • The article’s core evidence is that agents now combine access, action and autonomy across business-critical workflows, which creates blind spots when controls stay disconnected from operations.
  • For practitioners, the practical response is to bring inventory, posture assessment and incident handling into the same SecOps loop.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10, OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseThe article centers on AI agents whose identity, permissions and runtime actions must be governed.
Recommendation — Apply ASI03 controls to constrain agent privilege and monitor runtime access escalation.
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe article highlights excessive permissions and cross-system access as the core agent risk.
Recommendation — Review AI agent entitlements for overprivilege and remove any access not required for the task.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsContinuous entitlement control is central to the SecOps governance model described here.
Recommendation — Govern agent permissions under PR.AA-05 and tie changes to continuous risk review.
NIST AI RMFMANAGE — AI risk managementThe article describes ongoing AI risk monitoring, prioritisation and response for agents.
Recommendation — Operationalise MANAGE activities to monitor AI agent risk continuously across the lifecycle.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementAgents with broad access can enable credential abuse and movement across systems.
Recommendation — Map agent misuse scenarios to TA0006 and TA0008 to improve detection and containment.

Key terms

  • SecOps-native governance: A governance model that embeds risk discovery, prioritisation and remediation into the security operations workflow. For AI agents, it means controls must sit where investigations and response already happen, because behaviour and exposure change faster than periodic review cycles.
  • Agent Inventory: A governed record of every AI agent in use, including who created it, who can invoke it, what data it can reach, and what actions it can trigger. Without a current inventory, security teams cannot judge whether agent access still matches the business purpose.
  • AI Security Posture Management: A governance approach for discovering and tracking AI assets such as models, agents, datasets, vector stores, and related infrastructure. It becomes useful only when inventory is connected to runtime exposure and the identity that can actually reach the data.
  • Non-deterministic system: A non-deterministic system does not produce reliably identical outcomes from identical inputs. In AI security, that means prompts, context, model updates, and tool connections can change the result, so assurance has to measure behaviour over time rather than assume fixed output patterns.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org