By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: Clarity SecurityPublished August 19, 2026

TL;DR: ISACA conference sessions showed GRC leaders shifting from checkbox compliance to continuous risk reduction, with AI governance, MCP risk, and audit evidence generation emerging as the clearest pressure points, according to Clarity Security. The industry’s control model is out of step with systems that can make decisions, expand access, and outpace point-in-time review cycles.


At a glance

What this is: This conference recap argues that AI governance, visibility, and continuous risk reduction are now central GRC priorities, not future concerns.

Why it matters: It matters because IAM, NHI, and governance teams must account for AI-driven access, incomplete evidence, and control models that were built for static identities.

By the numbers:

  • 1, ver 1,500 compliance, audit, technology, and security leaders gathered in San Diego for four days of sessions and workshops.
  • 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, sharing sensitive data, and revealing access credentials.
  • 96% of technology professionals identify AI agents as a growing security threat, and 66% believe this risk is immediate.

👉 Read Clarity Security's conference analysis on AI governance, MCP risk, and continuous compliance


Context

AI governance has moved from a specialist concern to a board-level governance problem because AI systems now sit inside decision paths, access paths, and evidence trails. That creates pressure on IAM and GRC programmes that were designed for static users, scheduled reviews, and clear accountability boundaries.

The article’s central claim is that compliance-first operating models are no longer sufficient when access, evidence, and control decisions change continuously. For identity teams, the important intersection is not just human access, but also NHI, agentic AI, and the auditability of delegated machine actions.


Key questions

Q: What breaks when GRC programmes rely on point-in-time compliance reviews?

A: Point-in-time reviews miss the changes that happen between audit snapshots, which means access can be approved on paper while remaining risky in practice. This fails most visibly in dynamic environments with AI agents, nested identities, and fast-changing entitlements. Continuous evidence, not periodic attestation, is required to show whether controls actually worked.

Q: Why do local AI agents complicate identity and access management?

A: They can retain legitimate permissions while changing timing, prioritisation, and action sequence outside human presence. That means the visible identity may remain stable even as the operational behaviour becomes autonomous. IAM teams then lose the simple link between user session, authorisation, and accountability.

Q: How should security teams turn access reviews into real risk reduction?

A: Security teams should use access reviews to remove dormant access, orphaned accounts, and privileges that no longer match the work being performed. The review should end with revocation or re-scoping, not just attestation. The goal is to reduce exposure, especially in production systems and high-risk applications where excessive access has immediate security impact.

Q: Who is accountable when AI-related access outpaces governance?

A: Accountability sits with the owners of identity, data, and platform controls together, because AI-related access problems cross programme boundaries. IAM, IGA, PAM, and security leadership must share responsibility for visibility, revocation, and ownership. If one team can create access but no team can remove it quickly, the control model is incomplete.


Technical breakdown

Why point-in-time compliance fails in continuous environments

Point-in-time compliance assumes the state you sample is representative of the state you govern. That assumption breaks when access is dynamic, identities are nested across human and non-human systems, and AI agents can make decisions between review cycles. Continuous compliance, by contrast, needs telemetry, lifecycle controls, and evidence generation tied to actual behaviour rather than annual attestations. The governance challenge is not only proving access existed, but proving it was appropriate throughout its lifetime.

Practical implication: replace static review artefacts with continuous evidence pipelines that track entitlement change, usage, and revocation.

MCP and agentic AI create a new access-control layer

Model Context Protocol connects AI agents to tools and data sources, which means the security question is no longer just what the model can say, but what the agent can do. Once an agent can call tools, fetch data, or trigger actions, it becomes a governance object with identity, authorisation, and audit requirements. Traditional IAM can authenticate a user or workload, but it does not automatically constrain agent delegation chains, tool permissions, or runtime context.

Practical implication: treat MCP-connected agents as governed identities and assign explicit tool scopes, logging, and revocation paths.

Continuous risk assessment depends on usable evidence

GRC programmes fail when they cannot reconstruct what happened, who had access, and whether controls operated as intended. In environments with federated, nested, human, non-human, and agentic identities, evidence generation becomes an identity problem as much as a reporting problem. The article’s MCP and audit themes point to a simple reality: if the control plane is fragmented, the audit trail will be fragmented too. That weakens both compliance confidence and incident response.

Practical implication: centralise identity and access evidence across human, workload, and agentic systems before auditors ask for it.


Threat narrative

Attacker objective: The objective is to exploit governance blind spots created by fragmented identity oversight and weak evidence generation, then use that gap to reach data or systems without timely challenge.

  1. Entry occurs when organisations accept broad AI and third-party integrations without fully modelling the access paths those tools create.
  2. Escalation follows when those integrations expand from simple automation into delegated actions against data, systems, or audit-relevant workflows.
  3. Impact appears as incomplete evidence, inappropriate access, and delayed detection of risk that was visible only after the fact.

NHI Mgmt Group analysis

AI governance has become an identity governance problem, not just a model-risk problem. The conference’s strongest signal was that AI is now embedded in access decisions, tool use, and evidence trails. That means GRC teams can no longer treat AI as a separate policy domain. IAM, PAM, and NHI controls must extend into AI delegation, tool permissions, and runtime authorisation if governance is going to reflect reality.

Continuous compliance is the named concept the industry now needs to operationalise. Point-in-time attestation cannot keep up with systems that change access and behaviour between reviews. The practical consequence is that audit programmes must shift from sampling states to tracking lifecycle evidence. In NIST CSF and NIST 800-53 terms, the control intent is familiar, but the operating model has changed. Practitioners should assume static evidence will be increasingly treated as incomplete evidence.

MCP introduces a control gap that most GRC programmes have not yet modelled. When AI agents use MCP to reach data and tools, the question is no longer whether the agent is approved, but whether each action path is authorised and attributable. That is a governance boundary many organisations have not defined. The right response is to classify these flows as first-class identities and constrain them with explicit lifecycle, logging, and approval boundaries.

Visibility is now the limiting factor in risk reduction. The article correctly links evidence generation problems to incomplete access visibility across human, NHI, and agentic identities. If the programme cannot produce defensible evidence quickly, risk decisions will remain slow and reactive. That is why continuous identity telemetry is becoming a governance prerequisite, not an operational luxury.

GRC teams should expect the market to move toward control-plane convergence. The organisations that can unify access review, evidence generation, and runtime identity signals will have a clearer operating picture than those relying on separate tools and manual reconciliation. For practitioners, that means re-evaluating whether their current governance stack can actually follow identity across human, workload, and agent-driven activity.

What this signals

Continuous compliance will become the default expectation for identity-heavy programmes. As AI, NHI, and human identities converge, audit evidence will be judged on freshness and completeness rather than on whether it exists at all. Teams that still rely on manual attestation will find that their evidence trails lag the pace of change, especially where delegated access is involved.

AI governance will increasingly be measured through identity telemetry. If an organisation cannot correlate agent actions with scoped access, it cannot defend its control model during review or incident response. The practical signal for practitioners is to invest in the identity data needed to follow every meaningful action path, not just the final approval state.

For identity programmes, the next control gap is likely to be delegated action visibility. That means the programme must track not only who or what was authenticated, but what it was allowed to do after authentication. The more agentic the environment becomes, the more this will resemble a continuous authorisation problem rather than a traditional access review problem.


For practitioners

  • Build continuous evidence pipelines Connect entitlement changes, access usage, and revocation events so auditors can verify control operation continuously rather than at a single review point.
  • Model AI agents as governed identities Assign explicit scopes to MCP-connected and other agentic workflows, including tool permissions, logging, and revocation paths before they reach production.
  • Unify human, NHI, and agentic access telemetry Correlate identity, privilege, and activity data across all three identity classes so evidence generation does not depend on manual reconciliation.
  • Reframe audit work around risk reduction Use review cycles to validate whether access and control changes actually reduce exposure, not just whether required checkboxes were completed on time.

Key takeaways

  • AI governance is now inseparable from identity governance because agentic systems create real access and evidence risks.
  • Point-in-time compliance models cannot keep up with dynamic identities, delegated actions, and continuously changing privilege.
  • Practitioners should move toward continuous evidence, scoped agent permissions, and unified visibility across human, NHI, and AI activity.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4Access governance and review gaps are central to the article's risk-reduction theme.
NIST SP 800-53 Rev 5AC-6Least privilege directly addresses the overbroad access and audit gaps discussed here.
NIST AI RMFGOVERNAI governance and accountability are the article's core AI security themes.

Map access reviews to PR.AC-4 and verify that approvals reduce exposure, not just close tickets.


Key terms

  • Continuous Compliance: Continuous compliance is the practice of keeping controls and evidence current as the environment changes, rather than proving compliance after a review cycle. For identity and NHI programmes, it means access, logging, and revocation must operate together in real time.
  • Agentic AI: Autonomous AI systems capable of planning, deciding, and taking actions — including calling APIs, writing code, and orchestrating other agents — with minimal human oversight. Agentic AI introduces new NHI risks as agents must authenticate to external services.
  • Identity Telemetry: Identity telemetry is the collection of signals generated by authentication, session, and access events across human and non-human identities. It becomes useful for governance when teams can baseline normal behavior and detect drift in source, privilege, or access frequency.

What's in the full article

Clarity Security's full article covers the operational detail this post intentionally leaves for the source:

  • Session-level examples of how GRC teams are reworking access review and continuous compliance workflows.
  • Practical discussion of MCP security and how audit programs should account for agentic access paths.
  • Details from Clarity Security's continuous risk assessment framing, including the Identify, Classify, Triage, Remediate model.
  • Conference-specific context from the sessions and conversations that shaped the article's conclusions.

👉 The full Clarity Security article expands on the GRC themes, access review challenges, and evidence-generation gaps discussed at ISACA.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It is designed for practitioners who need to connect identity controls to real operational and audit outcomes.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 21, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org