By NHI Mgmt Group Editorial TeamBased on Lasso Security: “AI Governance Challenges in the Age of Agentic AI” (May 14, 2026)

TL;DR: Agentic AI governance shifts the risk from what a system says to what it can do, because agents can query databases, trigger workflows, call APIs, and update records in one sequence, according to Lasso Security. Static AI policies were built for outputs, not machine-speed actions, and that assumption now fails.


At a glance

What this is: This is Lasso Security’s analysis of why AI governance built for chatbots breaks when agentic systems can act across connected systems in a single runtime sequence.

Why it matters: It matters because IAM, PAM, and governance teams now have to control what autonomous systems can do, not just what they say, and static policy reviews are too slow for machine-speed execution.


Context

Agentic AI governance breaks when the control model assumes conversation is the end state. Once an AI system can query databases, trigger workflows, call external APIs, and update records in one runtime sequence, the governance problem shifts from content review to action control.

That matters for identity governance because the agent is no longer just producing text. It is acting with access, across multiple connected systems, and traditional review cycles cannot reliably see or stop those actions after execution begins.


Key questions

Q: What breaks when AI governance only monitors prompts and outputs?

A: Prompt and output monitoring misses the moment where the real risk occurs, which is execution. An agent can produce a harmless-looking response while still calling APIs, updating records, or chaining actions across systems. Governance that stops at the conversation layer cannot see the blast radius created by runtime action.

Q: Why do autonomous agents force teams to rethink AI governance and accountability?

A: Because the action sequence now happens at machine speed, human review no longer sits inside the decision window. By the time someone sees the result, the agent may already have completed multiple steps across connected systems, so accountability must shift to runtime control and continuous visibility.

Q: How do security teams know if AI governance is working?

A: Look for evidence that access decisions are reviewable, permissions are revocable, and exceptions are not becoming permanent. If the team cannot explain who owns an AI workflow, what it can reach, and when its access was last reviewed, governance is incomplete. Control maturity shows up in traceability, not adoption volume.

Q: What happens when an AI agent is allowed to delegate across other agents and tools?

A: The blast radius grows quickly because one compromised instruction chain can propagate through downstream agents and systems before monitoring notices. Traditional human-centric oversight has no reliable frame of reference for this kind of non-human delegation, so the chain needs explicit runtime supervision.


Technical breakdown

Why output monitoring fails for agentic AI

Output monitoring assumes the security question is whether the model said something accurate, safe, or appropriate. Agentic systems change that unit of control: the relevant event is not the response, but the action chain that follows. When an agent can call tools, move through APIs, and write back to systems of record, a policy that only inspects prompts and responses is blind to the part of the session that creates risk. In practice, this means the old trust boundary sits too high in the stack. The governance problem is no longer conversational correctness; it is whether runtime authority is constrained at the point of execution.

Practical implication: move governance controls to the action layer, not just the prompt and response layer.

Why agent inventory becomes a governance control

The article’s central operational point is that enterprises cannot govern what they cannot inventory. Agentic environments change rapidly because agents are being built across repositories, cloud platforms, and low-code environments at the same time, and their connected tools can shift without a visible application redesign. A live inventory is therefore not just an asset register. It is the only way to understand which agents exist, what models they use, what systems they can reach, and where access has drifted beyond intent. Without that picture, risk ranking and policy enforcement are both incomplete.

Practical implication: treat agent discovery and live inventory as a prerequisite for any enforceable governance programme.

Why fragile intent testing matters in non-deterministic systems

Agentic systems are non-deterministic, so the same agent may behave differently depending on conversation history, tool state, or model version. That makes single-turn checks insufficient because many failures emerge only under sustained, adaptive pressure. The article describes fragile intent as the point where guardrails can be overcome through persistence rather than brute force. This is a materially different test from classic application security, where a predictable exploit pattern can be matched to a stable rule. Here, the governance challenge is to find where the agent can be coaxed into unsafe action paths before those paths become operational reality.

Practical implication: use multi-turn adversarial testing to probe where agent intent breaks under realistic pressure.


Threat narrative

Attacker objective: The attacker aims to turn legitimate agent access into fast, compound business actions across connected systems before governance catches up.

  1. Entry occurs when an agent is granted access to connected systems such as databases, workflows, APIs, or record-update tools as part of normal deployment.
  2. Escalation happens when the agent inherits broader authority than the task requires and can combine multiple actions in one uninterrupted runtime sequence.
  3. Impact follows when compromised or misdirected agent behaviour propagates across systems before human oversight can intervene, creating multi-system business damage.
  • Meta Muse agent hijack 2026: An undocumented Muse setting let local malware hijack Meta's personal AI agent, steal its authentication material and abuse user access.
  • postmark-mcp malicious MCP server 2025: A fake Postmark MCP server on npm quietly BCC'd every email AI agents sent through it to an attacker, using victims' own Postmark tokens.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Runtime governance is the real control boundary for agentic AI: policies written for conversational systems do not control systems that can execute actions across multiple tools in one session. The problem is not policy intent but timing, because agent decisions now happen inside the same runtime window as the action itself. Practitioners should treat execution-time control as the primary governance boundary.

Live inventory is a governance requirement, not a reporting feature: enterprises cannot prioritise or enforce policy on agents they cannot see. When agents are created across repositories, cloud services, and low-code platforms, point-in-time inventories become stale almost immediately. The practitioner conclusion is that discovery must be continuous or it is operationally meaningless.

Fragile intent is the named concept that explains why static guardrails fail: an agent can appear safe under one prompt and unsafe under sustained, adaptive interaction. That means the failure mode is not a single bad input but a collapse of intent under runtime pressure. The implication for teams is to validate behaviour under realistic multi-turn conditions, not rely on a one-shot policy check.

Least privilege is being redefined by machine-speed execution: access that looks acceptable at deployment can become excessive once an agent chains queries, workflow calls, and record updates in sequence. The governance question is no longer who approved the access, but whether the approved scope still makes sense when actions happen faster than human review. Practitioners should reassess privilege at the point of use.

Agent-to-agent orchestration expands blast radius beyond human monitoring assumptions: when one agent delegates to another, the trust chain is no longer human paced or easily auditable. Conventional monitoring was built around user-initiated actions and cannot reliably interpret instructions passing between non-human actors. The practitioner conclusion is that delegation chains need explicit runtime oversight, not inherited trust.

From our research library:

What this signals

Runtime control becomes the governance line item that matters: when agents can act across databases, APIs, and workflows, policy has to follow execution rather than precede it. Teams that keep treating AI governance as an acceptable-use problem will miss the point where action becomes consequence.

Agent discovery will become a prerequisite for defensible AI oversight: the governance model only works when every agent, its model, and its connected tools are visible in one live inventory. Without that, risk prioritisation and enforcement both collapse into guesswork.

Fragile intent is now the right test lens for agentic risk: static controls cannot enumerate every way a non-deterministic system can be manipulated. Security teams need sustained adversarial testing that mirrors how real attackers gradually steer agent behaviour.


For practitioners

  • Build a live agent inventory Track every agent across repositories, cloud platforms, low-code tools, models, APIs, and system prompts so changes are visible when code does not change.
  • Move policy enforcement to runtime Bind guardrails to the tools, data sources, and decision points the agent actually uses, instead of relying on prompt and output review.
  • Test for fragile intent continuously Run single-turn and multi-turn adversarial testing to see where an agent can be pushed from safe behaviour into unsafe action paths.
  • Review delegated access by actual task scope Reassess whether an agent’s connected systems and write permissions exceed the smallest scope required to complete its current task.

Key takeaways

  • Agentic AI changes the governance problem from what a system says to what it can do across connected systems.
  • Static policy and output review are too slow for systems that can query, call, and write in one uninterrupted runtime sequence.
  • The control model now has to combine live inventory, runtime enforcement, and adversarial testing for fragile intent.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseThe article centers on agents inheriting and using access beyond intended scope.
ASI08 — Cascading FailuresThe post describes how one agent action can propagate across connected tools and systems.
Recommendation — Map runtime agent access to ASI03 and constrain privileges at execution time. Use ASI08 to test how a single compromised agent step can cascade downstream.
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIAgentic systems inherit broad access that often exceeds the task they actually perform.
Recommendation — Apply NHI-05 to reduce agent permissions to the smallest task-scoped access.
NIST AI RMFGOVERN — AI Governance and AccountabilityThe article is fundamentally about governance structures for agentic AI systems.
Recommendation — Use GOVERN to assign ownership and oversight for agentic AI decisions and access.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsRuntime access and entitlement scope are the core governance issues in the article.
Recommendation — Apply PR.AA-05 to review and constrain agent entitlements at the point of use.

Key terms

  • Agentic AI: Autonomous AI systems capable of planning, deciding, and taking actions, including calling APIs, writing code, and orchestrating other agents, with minimal human oversight. Agentic AI introduces new NHI risks as agents must authenticate to external services.
  • Fragile intent: The point at which an agent can be manipulated into acting outside its intended scope through persistence, context shifts, or pressure. This is an operational concept, not a model-quality score, and it is especially relevant when the agent has access to real enterprise systems.
  • Runtime Enforcement: Runtime enforcement is the practice of blocking malicious behaviour while software is running, rather than only detecting it after the fact. It monitors process activity, network actions, and privilege changes so a live attack can be interrupted at the point of execution.
  • Agent Inventory: A governed record of every AI agent in use, including who created it, who can invoke it, what data it can reach, and what actions it can trigger. Without a current inventory, security teams cannot judge whether agent access still matches the business purpose.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org