TL;DR: AI agents expose a deeper security flaw: most organisations still cannot reliably classify sensitive data or determine who and what can access it, according to Sentra. The decisive control is continuous data readiness, because visibility without classification leaves AI governance blind to the real exposure, and OWASP research says 68% cannot distinguish human from agent activity.
At a glance
What this is: This analysis argues that the real AI security problem is not agent count, but incomplete visibility into sensitive data and the identities that can reach it.
Why it matters: For IAM and security teams, it reframes AI governance around continuous classification, access context, and privilege scope across human, service, and agent identities.
By the numbers:
- According to OWASP's 2026 research, 68% of organizations cannot reliably distinguish human activity from AI agent activity.
- According to Sentra, 97% of non-human identities carry excessive privileges in the typical enterprise.
- According to Sentra, the typical enterprise operates roughly 100 non-human identities for every human identity.
- According to Sentra, greater than 98% classification accuracy is achievable at petabyte scale when data is continuously discovered and classified.
👉 Read Sentra's analysis of why AI agents expose the data governance gap
Context
AI agent visibility is a governance signal, but it is not the control boundary. The deeper problem is that most enterprises still do not know what sensitive data they hold, where it sits, or which human, service, and machine identities can already reach it. In that environment, AI simply accelerates exposure that existed before the first agent was deployed.
The article’s primary point is that data classification must come before AI governance. That matters to IAM, PAM, and NHI teams because access reviews and least-privilege programmes cannot be effective if the underlying data estate is unclassified, stale, or continuously changing through cloud, SaaS, and collaboration platforms.
Key questions
Q: How should security teams govern AI agents that can access enterprise systems?
A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring. The control set should include inventory, task-bound credentials, audit trails, and revocation paths. If an agent can call tools or touch production systems, it belongs in the same governance model as service accounts and other machine identities.
Q: Why do AI agents make IAM and NHI risk harder to manage?
A: AI agents can request tools, call APIs, and even create new infrastructure at machine speed, which multiplies identity events and privilege decisions. That means the control plane must handle autonomous access as a normal workload pattern, not as an exception that can wait for manual approval.
Q: What breaks when sensitive data is not classified in GenAI pipelines?
A: Without classification, organisations cannot reliably decide what data is allowed into the model, what must be blocked, or what needs special handling after output. That creates compliance gaps and weakens incident response because teams cannot reconstruct what the AI system touched. Classification is the control that makes the rest of the governance stack enforceable.
Q: Who is accountable when an AI agent accesses sensitive data it was not meant to use?
A: Accountability sits with the team that approved the agent, its connectors, and its policy boundaries, not with the runtime behaviour alone. Organisations need ownership for intent, permissions, monitoring, and validation so they can prove whether the agent stayed inside its approved purpose. Without that, audit and regulatory response become retrospective guesswork.
Technical breakdown
Why AI agents expose data governance gaps
AI agents do not create new data sensitivity, but they do remove the delay that once limited exposure. If an agent, application, or service account can reach a dataset, it can usually discover, aggregate, and act on that data far faster than a human review cycle can respond. The security issue is therefore not the agent itself, but the combination of unclassified data and broad access paths. In governance terms, AI turns latent exposure into active exposure because the control plane still assumes periodic review is enough.
Practical implication: treat every new AI access path as a data-governance event, not just an application rollout.
How data classification changes the identity question
Identity controls answer who can access something, but they cannot explain whether the thing should be sensitive in the first place. Continuous classification creates the missing context by linking data sensitivity to the identities, service accounts, applications, and agents that can reach it. That is why data security posture management becomes relevant to IAM and NHI governance: least privilege only works when privilege is measured against known data sensitivity, not against an incomplete inventory of permissions.
Practical implication: bind access reviews to classified data sets so privilege decisions reflect actual exposure, not raw entitlements.
Why point-in-time audits fail in AI-enabled environments
Traditional reviews assume data and access paths change slowly enough for scheduled checks to catch up. That assumption breaks when collaboration tools, data warehouses, copilots, integrations, and agents can create new reachability paths continuously. Once access changes faster than review cycles, the organisation loses the ability to tell whether a dataset is still protected, especially when sensitive content is spread across cloud, SaaS, and on-premises repositories. Continuous discovery and classification are therefore operational requirements, not reporting enhancements.
Practical implication: shift from periodic access audits to continuous data discovery, classification, and remediation workflows.
Threat narrative
Attacker objective: The attacker objective is to exploit unclassified sensitive data through legitimate access paths before governance catches up.
- Entry occurs when an AI agent, integration, or overprivileged service account gains access to a repository that was never classified as sensitive.
- Escalation follows when the actor can query, combine, or redistribute that data faster than security teams can review the access path.
- Impact occurs when sensitive records are exposed, copied into downstream AI workflows, or used without the organisation ever realising the dataset was high-risk.
NHI Mgmt Group analysis
AI visibility without data classification is a governance illusion: counting agents, copilots, and integrations tells practitioners little if they cannot classify the data those systems can reach. The article correctly shifts the control question from inventory to exposure. For IAM, PAM, and NHI programmes, that means privilege management must be anchored to data sensitivity, not just to the presence of an identity.
Continuous data readiness is the named concept this market now needs: data discovery, classification, and access evaluation must operate as a living control loop rather than a quarterly project. AI systems change the timing of risk, because they can consume and redistribute data continuously. Practitioners should treat continuous readiness as the operational baseline for DSPM, IAM, and NHI governance.
Unclassified data is now the primary failure mode behind overpermissioned identities: the usual story is that identities are excessive, but the deeper problem is that enterprises do not know which identities are excessive relative to which data. That is why the article’s framing matters for identity teams. Without classification, least privilege becomes an abstract policy instead of an enforceable boundary.
AI governance and identity governance are converging at the access layer: the same control failure can involve a human user, a service account, or an AI agent, because the security question is whether the actor can reach sensitive data. This makes agent identity, NHI oversight, and human access review part of one governance problem. Practitioners should align AI controls with identity lifecycle, entitlement review, and data classification together.
Visibility programmes will keep underperforming until they stop measuring the wrong asset: enterprises often optimise for counting assets that can act, but exposure is determined by the data that can be reached and reused. That is a stronger and more defensible security model for boards and auditors alike. Security teams should report on classified data coverage and access reachability, not just agent inventory.
What this signals
AI security programmes will increasingly be judged on whether they can prove data readiness, not whether they can count agents. The practical shift is toward continuous discovery, classification, and entitlement validation, because those are the controls that determine whether AI systems can touch sensitive content at all.
Continuous data readiness: the next control maturity step is to treat classification, access mapping, and remediation as one operating loop. That approach aligns naturally with NIST AI Risk Management Framework and with identity governance where service accounts and AI agents are part of the same access model.
For identity teams, the signal is clear. If access reviews still rely on spreadsheets or quarterly snapshots, AI will keep exposing the mismatch between assumed and actual exposure. Organisations should expect boards to ask for coverage metrics on classified data, not just counts of identities or tools.
For practitioners
- Implement continuous data classification Classify sensitive data across cloud, SaaS, collaboration platforms, warehouses, and on-premises repositories as an ongoing process, then tie access decisions to that classification.
- Map all identities that can reach sensitive data Build an access view that includes human users, service accounts, applications, and AI agents so entitlement reviews reflect real exposure rather than siloed inventory.
- Prioritise remediation on overpermissioned data paths Use classification results to remove redundant access, right-size privileges, and reduce reach into customer, HR, finance, and M&A data before AI workflows expand exposure.
- Measure AI governance by data coverage Report on the percentage of sensitive data that is classified, reviewed, and bound to access controls instead of reporting only the number of agents discovered.
- Align DSPM with IAM and NHI controls Connect data discovery outputs to entitlement review and least-privilege enforcement so access governance changes when the underlying data changes.
Key takeaways
- The central risk is not the number of AI agents, but the amount of sensitive data they can already reach.
- Research cited in the article shows a major confidence gap in non-human identity security, which supports the case for continuous rather than periodic governance.
- The control priority is to classify data first, then bind IAM, PAM, and NHI decisions to that classification.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-03 | Classification-driven access control addresses overpermissioned NHI exposure. |
| OWASP Agentic AI Top 10 | AI3 | Agent access to sensitive data depends on governing tool and data reach. |
| NIST CSF 2.0 | PR.AC-4 | Least-privilege access control is central to data reachability risk. |
| NIST AI RMF | MANAGE | AI RMF Manage covers operational controls that reduce data exposure risk. |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege is the direct control family for excessive access to sensitive data. |
Use MANAGE to continuously govern data access, monitoring, and remediation for AI systems.
Key terms
- Data Readiness: Data readiness is the degree to which data is clean, governed, accessible for the right purpose, and traceable back to a known source. For AI programmes, it covers lineage, retention, quality, and access controls, because poor data quality becomes a governance failure at runtime.
- Continuous Classification: An ongoing process that inspects data as it is created, stored, moved, and accessed so its sensitivity stays current. For scanned content, this usually means OCR and metadata analysis before policy decisions such as retention, sharing restrictions, or deletion can be applied.
- Data Access Governance: Data access governance is the practice of deciding who or what should reach specific data based on sensitivity, business purpose, and observed access paths. It combines classification, entitlement analysis, and review workflows so access decisions reflect exposure, not just permission status.
- Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
What's in the full article
Sentra's full article covers the operational detail this post intentionally leaves for the source:
- Continuous discovery workflow across cloud, SaaS, collaboration platforms, on-premises environments, and data warehouses
- The classification approach using more than 250 classifiers across 130 file formats for structured and unstructured content
- How access paths are mapped for humans, applications, service accounts, and AI agents as data moves into workflows
- The remediation sequence for right-sizing access, identifying stale data, and prioritising cleanup actions
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It gives security practitioners a practical way to connect identity controls to broader access risk.
Published by the NHIMG editorial team on August 19, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org