TL;DR: As AI agents multiplied across Kantar, the company needed systematic discovery, adversarial testing, and governance to keep pace with non-deterministic behaviour and emerging attack vectors, according to Noma Security. The broader lesson is that manual guardrails alone cannot govern fast-growing agent fleets, especially where access, data exposure, and policy coverage are already hard to measure.
At a glance
What this is: Kantar’s AI adoption story shows how quickly agent sprawl can outpace manual guardrails, creating a need for continuous discovery and adversarial testing.
Why it matters: For IAM, NHI, and AI security teams, the key issue is governance at the point where agents become operational actors that can access data, trigger actions, and bypass assumptions built for static systems.
By the numbers:
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%).
- 92% agree governing AI agents is critical to enterprise security, yet only 44% have implemented any policies to do so.
👉 Read Noma Security's analysis of Kantar's AI agent discovery and red teaming journey
Context
AI agent governance is no longer a future problem. Once employees can spin up agents across business units, security teams lose the comfort of a fixed asset inventory and face a moving target where the same system can behave differently from one run to the next. That changes the control question from "is this application approved" to "what does this agent do, what can it touch, and how do we know when it deviates?"
This article sits at the intersection of AI security and identity governance because agents are increasingly acting like non-human identities with access, permissions, and runtime behaviour that must be discovered and controlled. For practitioners, the operational challenge is not just model safety, but policy enforcement, visibility, and the ability to map agent activity to standards such as the NIST AI Risk Management Framework and OWASP Agentic AI Top 10.
Key questions
Q: How should security teams govern AI agents that can access enterprise systems?
A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring. The control set should include inventory, task-bound credentials, audit trails, and revocation paths. If an agent can call tools or touch production systems, it belongs in the same governance model as service accounts and other machine identities.
Q: Why do AI agents create more risk than traditional automation?
A: AI agents create more risk because they can interpret context, choose actions, and invoke tools autonomously. Traditional automation follows fixed rules, but an agent can be manipulated into using its own authority in unintended ways. That makes permission scope, tool boundaries, and monitoring more important than model accuracy alone.
Q: What do security teams get wrong about prompt guardrails?
A: Teams often treat prompt guardrails as if they were authorisation controls, but they are only one layer of defence. A model that filters unsafe language can still execute hidden instructions inside legitimate content if tool permissions are broad. Guardrails reduce exposure, but they do not replace separate approval checks for sensitive actions.
Q: Which governance evidence should compliance teams expect for AI agents?
A: Compliance teams should expect an inventory of agents, a record of what data they can access, mapped test results against known attack techniques, and a remediation trail for failed findings. That evidence shows whether policy is operating in practice, not just whether it exists on paper.
Technical breakdown
Why non-deterministic agent behaviour breaks manual review models
AI agents are not static workflows. They can vary output, tool use, and sequence of actions even when prompted in a similar way, which makes point-in-time review an incomplete control. That non-determinism creates a moving test surface: a control that passed yesterday may fail after a model update, prompt change, or new tool connection. Continuous adversarial testing is therefore not a luxury but the only way to exercise the actual runtime behaviour that users and attackers see.
Practical implication: replace one-time approval checks with recurring adversarial tests tied to each material agent change.
How AI security posture management maps the agent attack surface
AI security posture management, or AI-SPM, extends discovery into the AI layer by identifying agents, models, data sources, and the relationships between them. In practice, that gives security teams a current inventory of what exists, where it runs, and which datasets or systems it can reach. For agentic AI, discovery is governance because you cannot set policy against systems you have not found. This is where identity thinking matters: each agent has an operational footprint that must be tracked like a non-human identity with scope and accountability.
Practical implication: build an authoritative inventory of agents, connected data, and tool permissions before enforcing policy.
Why mapped adversarial testing matters more than generic red teaming
Generic red teaming can miss the attack techniques that matter in agentic systems, such as multi-turn prompt manipulation, data extraction across steps, or abuse of connected tools. Mapping tests to known attack techniques gives teams a repeatable way to compare findings, prioritise fixes, and show whether coverage improves over time. In a fast-changing AI environment, this also creates evidence for governance and audit, not just security engineering. The point is not to prove a model is safe forever, but to prove it has been tested against relevant abuse paths.
Practical implication: align agent tests to recognised attack techniques and track remediation as a governance metric, not just a bug list.
Threat narrative
Attacker objective: The objective is to exploit AI agents as an ungoverned access layer that can reveal data, trigger unauthorised actions, or erode trust in business outputs.
- Entry occurs when employees or business units create AI agents faster than central governance can inventory them, expanding the attack surface before controls are defined.
- Escalation follows when non-deterministic behaviour, broad data access, or connected tools let an agent reach data or systems beyond its intended scope.
- Impact is measured in leaked sensitive data, exposed confidential information, or agents behaving in ways that undermine trust and compliance.
NHI Mgmt Group analysis
AI agent sprawl creates a governance problem, not just a model-risk problem. Once business teams can deploy agents independently, the control surface expands faster than policy teams can classify it. The issue is not simply that models may be unsafe, but that the enterprise now has distributed, semi-independent actors with data access and tool reach. Practitioners should treat every agent fleet as a governed identity estate, not an isolated AI project.
Discovery is now a prerequisite for control in agentic environments. Security teams cannot enforce policy against systems they cannot enumerate, and agent inventories age quickly when employees can create new capabilities without central approval. AI security posture management gives the field a practical answer to that visibility gap. Practitioners should make discovery continuous, not episodic, and tie it to access review and data classification.
Agentic AI attack surface: the real risk is the combined effect of non-deterministic behaviour, hidden connections, and weak runtime governance. This is why the same agent can look harmless in a test and still leak data or reach unauthorised systems in production. The appropriate response is lifecycle control across discovery, testing, policy enforcement, and evidence generation. Practitioners should measure the whole operating envelope, not a single approval step.
Mapped adversarial testing is becoming a governance artefact, not just a security exercise. When tests are tied to recognised attack techniques, they create an auditable record of what was checked, what failed, and what changed after remediation. That matters for compliance teams, legal teams, and executives who need to understand whether policy coverage matches the actual risk. Practitioners should use test results as evidence for governance decisions, not only as engineering backlog.
The market is moving toward operational AI control planes that combine discovery, policy, and assurance. Point solutions that only add a guardrail or a scan do not solve the problem of fast-changing agent fleets. The direction of travel is toward repeatable workflows that connect AI security, identity governance, and auditability. Practitioners should expect agent governance to converge with identity and data control programmes.
What this signals
Agentic AI governance now needs the same discipline as identity governance. As agents begin to act like non-human identities, the security programme has to answer familiar questions in a new context: who owns them, what can they reach, how long does that access last, and how is misuse detected? The practical signal is that AI security, IAM, and data governance can no longer operate as separate workstreams.
Continuous assurance will replace static approval as the default operating model. A one-time sign-off is weak evidence when an agent can change behaviour after a prompt update, model swap, or new tool connection. Teams should align controls to runtime evidence and map those checks to the NIST AI Risk Management Framework and the OWASP Agentic AI Top 10.
Governance debt will accumulate fastest where discovery is incomplete. The longer agent inventories remain partial, the harder it becomes to explain policy coverage, audit access, or prove containment after an incident. For identity and security leaders, the forward move is to fold agent discovery into existing review cycles rather than bolt it on as a separate AI experiment.
For practitioners
- Build a live agent inventory Catalogue every AI agent, model, and connected data source across business teams, then assign ownership and review cadence. Without a current inventory, policy coverage will always lag deployment. Suggested anchor: live agent inventory.
- Tie policy enforcement to runtime behaviour Move beyond static guardrails by checking how agents actually behave under multi-turn prompts, tool calls, and data access attempts. Use those results to decide which agents can reach production. Suggested anchor: runtime behaviour.
- Adopt mapped adversarial testing for agents Test agent applications against recognised attack techniques so findings are repeatable, comparable, and auditable across releases. This is especially important where agents can access sensitive data or execute actions through external tools. Suggested anchor: recognised attack techniques.
- Align agent governance with identity controls Treat each agent as a non-human identity with scope, ownership, and review requirements. Connect agent discovery to access reviews, secret handling, and policy exceptions so governance is not isolated inside the AI team. Suggested anchor: non-human identity.
Key takeaways
- AI agents are expanding the attack surface faster than manual governance can keep up, especially when business teams deploy them independently.
- The strongest evidence of risk is not theoretical. Organisations are already seeing agents exceed scope, expose data, and outgrow visibility controls.
- Practitioners should treat agent discovery, runtime testing, and identity-style governance as linked controls, not separate initiatives.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and MITRE ATLAS address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | NHI-03 | The article centres on agent discovery, testing, and runtime governance risks. |
| NIST AI RMF | MANAGE | The post focuses on operational controls for AI risk and ongoing assurance. |
| NIST CSF 2.0 | PR.AC-4 | Agent access and scope control map to least-privilege and access governance. |
| MITRE ATLAS | TA0006 , Credential Access; TA0009 , Collection | The article references adversarial AI techniques that target access and data exposure. |
Use ATT&CK-style mappings to prioritise tests for prompt abuse, data collection, and tool misuse.
Key terms
- Agentic AI Security: Agentic AI security is the discipline of securing autonomous AI systems that can take actions, use tools, and chain decisions without direct human approval at each step. It covers identity and access management for AI agents, prompt injection defence, tool call governance, credential scoping, and runtime monitoring. As agentic systems acquire real-world authority — API access, file writes, workflow triggers — the security model must treat them as non-human identities with explicit lifecycle controls, not trusted processes.
- AI Security Posture Management: A governance approach for discovering and tracking AI assets such as models, agents, datasets, vector stores, and related infrastructure. It becomes useful only when inventory is connected to runtime exposure and the identity that can actually reach the data.
- Mapped Adversarial Testing: Mapped adversarial testing is the practice of running structured abuse scenarios against AI systems and aligning findings to known attack techniques. It turns red teaming into repeatable evidence, helping practitioners compare risk over time and show whether remediation is actually reducing exposure.
- Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
What's in the full article
Noma Security's full post covers the operational detail this post intentionally leaves for the source:
- Step-by-step explanation of how Kantar integrated AI discovery into developer and data science workflows.
- Examples of the adversarial test process used to catch multi-turn prompting issues before production release.
- Operational detail on how the security score improved from 65 percent to 85 percent across iterative testing.
- Discussion of how the team used dashboards to make findings actionable for developers and data scientists.
Deepen your knowledge
NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, secrets management, and workload identity. It gives practitioners a common control language for programmes that now need to govern agents as well as traditional identities.
Published by the NHIMG editorial team on July 24, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org