TL;DR: Generative AI is expanding both attack capability and defensive opportunity, with Living Security Human Risk Management Platform arguing that security teams must move from reactive detection to predictive controls across behavior, identity, and threat signals. The broader lesson is that AI security now depends on governing both people and AI agents, not just filtering prompts.
At a glance
What this is: The article argues that generative AI changes security from reactive detection to predictive risk management across human and machine activity.
Why it matters: It matters because IAM, NHI, and security teams now have to govern AI agents, verify access behavior, and reduce identity-driven exposure before incidents occur.
By the numbers:
- 80% of identity breaches involved compromised non-human identities such as service accounts and API keys.
- Only 5.7% of organisations have full visibility into their service accounts.
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface.
Context
Generative AI security is no longer just about blocking bad prompts or spotting malicious output. The harder problem is governance: understanding which humans, AI tools, and non-human identities can access data, make decisions, or trigger actions in enterprise workflows. In that sense, the primary keyword here is generative AI security, but the control challenge quickly becomes identity, access, and oversight.
Living Security Human Risk Management Platform frames the issue around predictive defense, where behaviour, identity, and threat intelligence are correlated before an incident occurs. That approach is directionally sound because AI agents and human users can both become attack surfaces, especially when access is broad, persistent, or poorly monitored. For most organisations, that starting point is still immature rather than typical.
Key questions
Q: How should security teams govern AI agents that can access enterprise systems?
A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring. The control set should include inventory, task-bound credentials, audit trails, and revocation paths. If an agent can call tools or touch production systems, it belongs in the same governance model as service accounts and other machine identities.
Q: Why do generative AI tools create non-human identity risk?
A: Generative AI tools create NHI risk because they often have access to corporate data, APIs, and workflows while operating outside traditional user-account models. The risk is not only prompt misuse. It is also the access identity behind the tool, the secrets it uses, and whether the organisation can see and constrain its reach.
Q: What do teams get wrong about AI security awareness training?
A: They treat it as a substitute for governance. Training helps people spot phishing, deepfakes, and suspicious AI behaviour, but it cannot fix excessive permissions, missing logs, or unclear ownership. Effective programmes pair awareness with access control, verification steps, and measurable behavioural signals.
Q: How can organisations reduce the risk of deepfake-driven social engineering?
A: They can reduce risk by combining user education, high-assurance verification, approval segregation, and incident escalation rules. The goal is to make it difficult for a convincing fake to move directly from perception to action. Any process that depends on belief alone is too easy to exploit.
Technical breakdown
How generative AI changes the security attack surface
Generative AI introduces two simultaneous changes. First, it lowers the cost of attack by helping adversaries produce convincing phishing, deepfakes, malware variants, and prompt manipulation at scale. Second, it expands the enterprise attack surface because AI tools, copilots, and agents may access data and systems with permissions that were not designed for autonomous or semi-autonomous use. The technical issue is not the model alone, but the surrounding control plane: who can prompt it, what data it can retrieve, which tools it can invoke, and how its actions are logged. That is why AI security and identity governance converge quickly.
Practical implication: Map AI-enabled workflows to identity, data, and logging controls before allowing them into production.
Why predictive security depends on correlated signals
Predictive security works by combining multiple weak signals into a stronger risk picture. In practice, that means correlating user behaviour, identity events, threat intelligence, and system telemetry rather than treating each source as an isolated alert stream. For generative AI environments, this matters because risk often emerges as a pattern, such as unusual prompt volume, abnormal access paths, or an AI agent touching data outside its expected context. Machine learning helps establish baselines, but the control value comes from correlation and triage, not from automation alone. Without that layer, teams stay stuck in reactive detection.
Practical implication: Build detection pipelines that combine identity, behaviour, and threat data into a single reviewable risk signal.
Human-in-the-loop controls for AI agents and users
Human-in-the-loop control means a person remains accountable for high-risk decisions even when AI performs the initial analysis or execution. That model is important because AI agents can act quickly, but speed without governance creates exposure if approvals, auditability, or escalation paths are unclear. In identity terms, AI agents should be treated as governed entities with bounded permissions, monitored actions, and explicit ownership. This is especially relevant when agents are allowed to access sensitive records, generate code, or trigger operational responses. The control objective is not to slow every action, but to prevent unreviewed authority from spreading.
Practical implication: Assign explicit owners, bounded scopes, and approval thresholds for every AI agent that can act on enterprise systems.
Threat narrative
Attacker objective: The attacker aims to convert trust in generative AI into access, deception, and downstream control over data or decisions.
- Entry begins when attackers use generative AI to create convincing phishing, synthetic identity artefacts, or manipulated prompts that evade human suspicion.
- Escalation occurs when the attacker exploits trusted access paths, compromised accounts, or AI-enabled workflows to reach data, tools, or decision points with broader privileges.
- Impact follows when the attacker steals information, corrupts model output, or uses the trusted workflow to enable fraud, exfiltration, or operational manipulation.
NHI Mgmt Group analysis
Predictive security is becoming the only defensible posture for AI-heavy enterprises. Traditional detect-and-respond models assume the attacker leaves a clean trail after the fact. Generative AI collapses that assumption by increasing attack speed, content quality, and scale at once. Security programmes that correlate behaviour, identity, and threat signals can intervene earlier, which is why predictive control is now a governance issue, not just an analytics preference.
AI agents must be treated as governed identities, not just application features. Once an agent can access data, invoke tools, or trigger actions, it begins to function like a non-human identity with security consequences. That brings the article into direct contact with NHI governance, especially around ownership, lifecycle, and privilege scope. The field needs clearer policy for AI agent accountability, because ungoverned agent access quickly becomes a shadow identity problem.
Human risk management is strongest when it extends into machine behaviour. The article is right to connect people and AI systems, because attackers exploit the seam between them. A trained employee can still be manipulated by a synthetic voice, while an overly trusted agent can become the execution path for misuse. The named concept here is AI-human trust leakage: when trust built for human collaboration is inherited by machine-driven actions without adequate controls. Practitioners should treat that leakage as a measurable governance failure.
Security teams should stop framing AI governance as a training-only problem. Awareness matters, but training cannot compensate for broad permissions, weak logging, or unclear ownership. The broader market signal is that AI governance is converging with identity governance, secrets management, and behavioural analytics. That convergence will favour programmes that can define accountable access, not just educate users.
Generative AI raises the value of continuous verification across the entire workflow. Static approval models struggle when prompts, outputs, and tool calls happen in rapid sequence. The practical conclusion is that organisations should align AI governance with Zero Trust principles, especially where data access or action execution is concerned. Continuous verification is becoming the baseline for both human and machine participants.
What this signals
AI governance will increasingly be judged by identity discipline. As generative AI systems move from assistance to action, security teams will need proof that each agent, integration, and workflow has a bounded identity, a known owner, and a revocation path. That is the real control plane shift behind AI security maturity.
The practical signal is that monitoring alone will not be enough. Organisations will need to pair behavioural analytics with access governance, task-scoped permissions, and lifecycle controls so AI-enabled workflows do not become unmanaged execution paths.
For practitioners
- Define AI agent ownership and scope Assign every production AI agent a named business owner, an explicit task boundary, and a documented approval path for high-risk actions. This is the minimum control needed to prevent unmanaged machine behaviour from becoming shadow AI.
- Correlate identity, behaviour, and threat signals Join identity events, user behaviour telemetry, and threat intelligence into a single risk workflow so analysts can spot pattern-based attacks earlier. Separate alert streams hide the chain that predictive security is supposed to reveal.
- Test for synthetic social engineering exposure Run phishing and deepfake simulations against finance, service desk, and executive workflows to measure whether verification steps actually work under pressure. Use the results to tighten challenge-response procedures, not just to increase awareness scores.
- Limit AI agent tool access to task-scoped permissions Use least privilege for every model, agent, and integration that can retrieve data or trigger actions. Review whether any agent can reach systems it does not need, especially where secrets, customer records, or code repositories are involved.
Key takeaways
- Generative AI increases both offensive scale and defensive opportunity, which makes governance the real security differentiator.
- AI agents behave like non-human identities when they access data or invoke tools, so identity controls must extend beyond people.
- Predictive security works only when behaviour, identity, and threat data are correlated into a single governance model.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 address the attack and risk surface, while NIST AI RMF, NIST AI 600-1, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | The article covers agent behaviour, prompt abuse, and governed tool use in AI workflows. | |
| NIST AI RMF | GOVERN | The article centres on accountability, oversight, and governance for AI-enabled decision paths. |
| NIST AI 600-1 | The article addresses generative AI risks, training data, and security operations. | |
| NIST CSF 2.0 | PR.AC-4 | The piece repeatedly returns to access scope and identity-controlled workflows. |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege is central to reducing AI workflow abuse and overbroad access. |
Map AI agent workflows to agentic risk patterns and restrict tool access to bounded, reviewable actions.
Key terms
- Generative AI Risk: Generative AI risk is the possibility that a model or its users will expose data, produce unsafe output, or influence decisions in ways the organisation did not intend. In practice, the risk spans confidentiality, integrity, and governance because the model can be used correctly and still create harm through misuse or over-trust.
- Human Risk Management: The practice of managing how people interact with security controls, especially under pressure, distraction, or deception. It combines training, policy, and friction management so identity systems are still usable enough that users do not bypass them in day-to-day work.
- AI Agent Identity: The digital identity used by an autonomous AI agent to authenticate to external systems, APIs, and services. Managing AI agent identities is an emerging and rapidly evolving area of NHI security.
- Synthetic Identity: A synthetic identity is a software-based actor that can authenticate, request access, and execute actions without being a human user. In practice, this includes AI agents, bots, service accounts, tokens, and other machine identities that need clear ownership, scope, and revocation.
What's in the full article
Living Security Human Risk Management Platform's full blog covers the operational detail this post intentionally leaves for the source:
- Specific examples of AI-powered phishing, deepfake, and malware scenarios used to illustrate human-risk exposure.
- Operational guidance on using machine learning to correlate behaviour, identity, and threat intelligence across security workflows.
- Examples of synthetic data use in security model training without exposing sensitive information.
- Additional context on how Human Risk Management is positioned for AI agents and employee behaviour programs.
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps security practitioners build the controls needed to govern human and AI-driven access with greater discipline.
Published by the NHIMG editorial team on August 21, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org