By NHI Mgmt Group Editorial TeamBased on Orca Security: “Getting Ready for the AI Era: A CISO’s Guide to AI Security Strategy” (February 11, 2026)

TL;DR: AI turns risk into a scale problem because engineers will generate more code, services, connections, and decisions faster than security headcount can grow, making attack surface expansion and automation the central issue, according to Orca Security. The editorial case is that security must shift from bolt-on controls to architecture, visibility, and workflow-level influence before AI practices harden.


At a glance

What this is: This is an argument that AI changes security from a control-count problem into a scale problem, because engineering speed and system growth can outpace traditional CISO operating models.

Why it matters: IAM, NHI and security teams need to treat AI-driven workflow growth as an identity and access design issue, not just a tooling discussion, because permissions, exposure and delegated actions will multiply faster than governance cycles.


Context

AI changes the security problem because it accelerates how quickly code, services, connections and decisions are created. That turns the issue into one of scale, where attack surface growth can outpace the organisation’s ability to govern access, review exposure and maintain control.

For identity programmes, the important question is no longer whether a model or workflow is clever. It is whether the surrounding identity, permission and data-access design can absorb a much higher rate of change without creating permanent exposure or delegated access sprawl.

This is especially relevant where AI is being wrapped into engineering workflows, because the access decisions move closer to runtime and the governance window gets shorter.


Key questions

Q: How should CISOs govern AI-enabled workflows before they become permanent attack surface?

A: Start by inventorying AI services, their credentials and the data they can reach. Then define explicit permission boundaries for each workflow, because the real governance problem is not the model itself but the access it inherits through connected systems, delegated actions and poorly separated identities.

Q: Why do access sprawl and AI workflows create more identity risk?

A: Because they multiply the number of places where credentials, approvals, and delegated actions can occur without clear ownership. AI-assisted workflows can accelerate access requests and routing, but governance often remains designed for slower human processes. That mismatch creates gaps in review, revocation, and accountability.

Q: What breaks when security teams rely on prompt filtering alone?

A: Prompt filtering breaks when the user can paste data through another route before inspection happens. Browser copy-paste, IDE extensions, API calls, and phone-tethered sessions often bypass content-only controls. That leaves organisations with partial enforcement and weak auditability, especially when the tool path is invisible to the security stack.

Q: How should organisations separate AI, service and human permissions in practice?

A: Use distinct identities for each role and avoid shared execution paths that let one actor amplify another’s access. Separation matters because AI-driven systems often chain actions across tools, and shared permissions make indirect privilege growth much harder to detect or govern.


Technical breakdown

Why AI turns identity governance into a scale problem

AI adoption changes the rate at which permissions are created, used and forgotten. When workflows can write code, call services, trigger deployments and make decisions faster than humans, the identity layer has to govern a much denser web of actions. That matters because the control problem is no longer one of isolated accounts or static entitlements. It becomes one of how identities, permissions and data paths are assembled inside fast-moving workflows. In practice, the organisation needs to know where authority is being inferred, delegated or reused rather than explicitly assigned.

Practical implication: Map AI-enabled workflows to the identities and permissions they actually consume, not just the applications they touch.

Visibility must precede AI controls

The article’s core operational point is that security teams cannot control what they cannot see. AI services, prompts, tools, plugins and connected systems should be treated like a new class of third-party dependency with direct access implications. Visibility here means understanding what data is reachable, what actions can be taken and which credentials sit behind each workflow. Without that inventory, security teams end up trying to govern AI through black-box assumptions, which is exactly how permanent access and undocumented exposure paths form.

Practical implication: Inventory AI services, their data access and their credentials before you evaluate any control layer.

Architecture is the control plane for AI-enabled identity

The article argues that security cannot rely on prompt filtering or isolated tool controls. In AI-heavy environments, architecture becomes the real control plane because it determines where permissions live, how identities are separated and whether actions require explicit intent. The useful design questions are about exposure, permission boundaries and whether one actor can indirectly inherit another actor’s authority. That is an identity governance problem as much as a security architecture problem, because poor separation turns speed into privilege sprawl.

Practical implication: Separate agent, service and human identities so that permissions do not collapse into one shared execution path.


  • Microsoft SAS token exposure 2023: An over-permissive Azure SAS token in a Microsoft AI GitHub repo exposed 38TB, including workstation backups and Teams messages, for 3 years.
  • DeepSeek database exposure 2025: An unauthenticated DeepSeek ClickHouse database exposed over a million log lines with plaintext chat history and API keys in 2025.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

AI changes the identity problem before it changes the threat model: the first-order issue is not smarter attackers, but faster production of code, services and delegated actions. That breaks the assumption that governance can keep pace with provisioning and review cycles. The implication is that identity programmes have to be designed around higher change velocity, not around the old cadence of periodic access governance.

Visibility is the prerequisite control for AI-era identity governance: if teams cannot see which AI services are in use, what they access and which credentials they hold, they cannot make sane authorization decisions. This is where NHI governance and cloud attack-surface management overlap. Practitioners should treat undocumented AI usage as a governance blind spot, not a tooling gap.

Ephemeral execution does not reduce governance pressure, it shifts it earlier: when AI-driven workflows can act inside development and production paths, the important control point moves to issuance and design time. Access review processes assume stable entitlements that persist long enough to be reviewed. AI-enabled workflows compress that window, so the programme has to focus on architecture, separation and explicit permission boundaries.

Prompt-level controls are not identity controls: filtering inputs or outputs does not answer who can act, what can be reached or how authority is inherited. That distinction matters because security teams often buy controls at the interaction layer while the real risk sits in identity, workflow and data-access design. The practitioner takeaway is to govern the execution path, not just the prompt surface.

Positive influence is becoming a security operating model, not a slogan: AI can embed security judgement earlier in engineering workflows, but only if the organisation rethinks where decisions are made. That shifts security from retrospective enforcement toward continuous participation in design and build pipelines. The field implication is that identity governance will increasingly be measured by how well it shapes workflow behavior before access becomes real.

From our research library:

What this signals

AI-era attack surface growth: the governance failure is not simply that more tools will be used, but that more identities, permissions and external connections will be created faster than review cycles can absorb. Security leaders should plan for control points that sit at design time and issuance time, not only at review time.

Identity separation becomes the practical boundary for AI governance: when agent, service and human permissions collapse into one execution path, organisations lose the ability to explain who acted, what was reached and why. That is a governance problem before it is a detection problem.

Access review models assume a privilege remains stable long enough to be certified, but AI-enabled workflows can create and consume access inside a much shorter window. The programme implication is to shift attention toward explicit boundaries, not retrospective certification.


For practitioners

  • Inventory AI-enabled workflows and connected services Document every AI service, agent-like workflow, plugin and external integration that can access code, data or infrastructure. Include the credentials, permissions and exposed endpoints behind each one so governance starts with a real attack surface map.
  • Separate identities for agents, services and humans Do not let AI-enabled automation inherit broad human permissions or share the same execution identity across systems. Assign distinct credentials and permission boundaries so one workflow cannot silently amplify another’s access.
  • Move security review upstream into design and build flows Embed governance checks where AI-enabled work is planned, coded, tested and deployed instead of waiting for post-hoc review. Focus on permission boundaries, exposed data paths and the point where decisions become execution.
  • Delay tool purchases until the risk boundary is clear Distinguish whether the real problem is external exposure, data access, permission sprawl or autonomous actions before buying AI security tools. Controls that do not match the actual risk will add process without reducing exposure.

Key takeaways

  • AI changes the security problem from controlling a fixed environment to governing a rapidly expanding identity and permission surface.
  • The article’s core warning is that engineering speed will outgrow security headcount unless architecture and visibility move earlier in the lifecycle.
  • The most important control shift is to separate identities, define permission boundaries and govern AI-enabled workflows before they harden into default practice.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIAI workflows inherit and amplify permissions, which makes overprivilege the central governance issue.
NHI-08 — Environment IsolationThe article stresses separating agents, services and humans so one workflow cannot inherit another's access.
Recommendation — Audit AI-connected workflows for excess permissions and reduce each identity to the smallest workable scope. Isolate AI, service and human execution paths so permissions do not blend across environments.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe post centres on who can access what as AI-driven activity expands the attack surface.
Recommendation — Review AI-related entitlements against PR.AA-05 and remove any permissions that are not explicitly required.
NIST SP 800-53 Rev 5IA-9 — Identification and Authentication (Non-Organizational Users)AI services and external integrations function as non-organisational actors that need governed authentication.
Recommendation — Apply IA-9 to authenticate AI-connected services and prevent uncontrolled delegated access.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementThe article's scale problem is an access expansion problem that increases credential abuse and movement paths.
Recommendation — Map AI expansion risks to TA0006 and TA0008 to prioritise identity paths most likely to widen blast radius.

Key terms

  • Attack Surface Expansion: Attack surface expansion is the growth in the number of reachable entry points, trust relationships, and exposed services that attackers can target. In modern applications, APIs, microservices, cloud services, and connected identities all add places where a vulnerability can become operationally important.
  • Workflow-Level Influence: Security control applied inside the operational path where work is designed, built and executed, rather than only after the fact. In AI-heavy programmes, this means shaping permissions, checkpoints and separation of duties before actions become runtime behavior.
  • Permission Boundary: A permission boundary is the enforceable limit on what an identity can do, regardless of how it behaves. For AI agents, this boundary matters more than session logs because it determines whether an action is possible in the first place.
  • Identity Separation: Identity separation is the practice of keeping human, workload and agent credentials distinct so each actor is individually attributable and governable. In agentic environments, it prevents borrowed credentials from collapsing accountability and makes revocation and investigation possible.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org