By NHI Mgmt Group Editorial TeamDomain: AI SecuritySource: Arxan TechnologiesPublished October 29, 2025

TL;DR: Digital.ai’s 18th State of Agile Report says AI use in development rose from 68% to 84% in under two years, and Arxan Technologies notes that only about half of those organisations report proper guardrails, showing that delivery speed is now outrunning governance and operating-model maturity. The real issue is not adoption, but whether AI-assisted workflows remain accountable, measurable, and bounded by trusted controls.


At a glance

What this is: This analysis argues that AI is moving agile delivery into a fourth wave where agentic workflows are already changing how teams plan, coordinate, and measure work, but governance is lagging behind adoption.

Why it matters: For IAM, NHI, and broader security practitioners, the shift matters because autonomous planning systems and AI-driven workflows introduce new identity, authorisation, auditability, and oversight questions that existing operating models were not built to answer.

By the numbers:

👉 Read Arxan Technologies' analysis of the fourth wave of software delivery and AI governance


Context

AI-assisted software delivery is no longer an experimental edge case. As organisations embed AI into planning, estimation, coordination, and execution, the governance gap becomes more visible because the system is no longer just producing code, it is influencing how work is prioritised and routed. For security leaders, the primary question is how to preserve accountability when automation starts shaping decisions that were once human-led.

The article’s core point is that speed has become the easy part, while control, measurement, and oversight are the harder problems. That intersects with identity governance because AI-enabled delivery depends on trusted access, auditable actions, and bounded delegation, especially when agentic AI begins to operate inside delivery workflows rather than alongside them.


Key questions

Q: How should security teams govern agentic AI as it moves into production?

A: Security teams should govern agentic AI as a class of non-human identity, not as a generic application feature. That means assigning ownership, scoping permissions tightly, logging every tool action, and revoking access on a defined lifecycle. Production rollout should require clear approval points for high-risk actions and continuous monitoring for drift.

Q: Why do AI-driven delivery programmes need stronger auditability?

A: Because once AI can trigger or coordinate work, teams need to know not only what changed but why it changed and under whose authority. Auditability proves that recommendations were traceable, actions were authorised, and outcomes can be reviewed after the fact. Without it, automation can outpace accountability.

Q: What breaks when delivery metrics focus only on speed?

A: Speed-only metrics hide whether AI-assisted work is actually improving business outcomes. Teams may see higher throughput while missing misaligned priorities, duplicated effort, or low-value automation. A useful governance model pairs velocity with outcome measures, so leadership can judge whether acceleration is producing better decisions.

Q: Should AI planning tools be treated like privileged non-human identities?

A: Yes, when they can initiate actions, call tools, or move work through a delivery workflow. In that case, they deserve the same scrutiny applied to other privileged non-human identities: scoped permissions, separation of duties, logging, and periodic review. That framing prevents governance gaps from hiding inside convenience features.


Technical breakdown

What agentic AI changes in delivery pipelines

Agentic AI goes beyond simple assistance. An agent can select actions, call tools, and decide timing within a defined runtime, which means it can influence planning, triage, sequencing, and execution in a delivery pipeline. That changes the control surface from a single user session to a chain of delegated decisions. In governance terms, the challenge is not just output quality but whether the agent’s permissions, data access, and action scope remain bounded and attributable. As autonomy increases, the environment needs stronger identity binding, policy enforcement, and audit trails around each delegated step.

Practical implication: treat AI agents as governed runtime actors and bind their actions to explicit permissions, logs, and policy checks.

Why measurement breaks when delivery accelerates

When throughput rises, traditional Agile metrics often become less useful because they describe motion, not value. Faster cycle times can hide weak alignment between delivery work and business outcomes. The article’s visibility paradox reflects a common control problem: organisations can see more activity, but not necessarily better decisions. This is especially relevant when AI is recommending or triggering work, because the governance layer must answer not only what happened, but whether the action was appropriate, traceable, and connected to an approved objective.

Practical implication: pair delivery metrics with outcome-linked controls so AI-assisted work can be evaluated for value, not just speed.

Governed autonomy in software planning

Governed autonomy means allowing AI systems to take bounded actions while keeping human oversight, auditability, and policy constraints intact. In this model, the system can coordinate tasks, suggest priorities, or trigger workflows, but it should not operate as an unbounded decision-maker. The security issue is similar to privilege design in IAM and NHI programmes: once a system can act, the organisation must define what it may act on, when it may escalate, and how those decisions are reviewed. Without that boundary, automation becomes opaque delegation.

Practical implication: define explicit approval thresholds and escalation boundaries before expanding AI into workflow orchestration.


NHI Mgmt Group analysis

Agentic AI in delivery pipelines should be treated as a governance and identity problem, not just a productivity upgrade. Once an AI system can sequence tasks, call tools, or trigger workflows, it begins to behave like a delegated actor with runtime authority. That introduces the same questions identity teams already face with service accounts and workloads: what can it do, how is it authenticated, and where is the audit trail. Practitioners should assume the control model must expand with the autonomy model.

Visibility paradox is the right named concept for this wave of delivery change. Organisations can now generate more telemetry, more recommendations, and more execution data, yet still struggle to determine whether work is aligned to business value. The article shows that acceleration does not solve governance, it exposes weak measurement. For security and risk teams, that means outcome traceability must become a design requirement, not a retrospective reporting exercise.

Agentic planning expands the identity perimeter of software delivery. When AI starts coordinating actions inside planning and delivery platforms, identity no longer applies only to users. It extends to the systems that propose, initiate, and sequence work. That makes policy enforcement, delegated authorisation, and action attribution part of the same governance conversation. Teams that do not model AI systems as bounded actors will struggle to enforce accountability across the workflow.

The market is moving from assistive AI to orchestrated AI, and that shift will pressure governance frameworks first. The article’s phased model shows that organisations are already advancing from basic assistance to coordinated agent workflows. That does not eliminate human oversight, but it does change where oversight must sit. NHI, IAM, and security leaders should expect stronger demand for policy-bound automation, traceable delegation, and runtime controls that work across planning and execution systems.

Named concept: governed autonomy. This is the practical boundary the article implies, where AI systems are allowed to act only within explicit policy, logging, and human accountability constraints. It is the difference between automation that accelerates delivery and automation that silently widens risk. Practitioners should use governed autonomy as the design test for every new AI workflow.

What this signals

Governed autonomy will become a design requirement as more delivery platforms embed AI that can recommend or trigger actions. Teams should expect control expectations to shift from simple usage policy to runtime authorisation, auditability, and escalation design, with identity teams pulled into delivery governance more directly.

The practical signal for practitioners is that AI adoption will keep accelerating, but the differentiator will be whether organisations can prove decision quality. That makes outcome-linked telemetry, delegated access reviews, and policy-bound workflows essential for any programme that wants AI to improve delivery without weakening accountability.


For practitioners

  • Define AI action boundaries Map every AI-assisted workflow to a specific set of permitted actions, escalation conditions, and approval requirements before expanding usage beyond simple assistance.
  • Add auditability to delegated work Require logs that show which agent proposed or triggered each action, what data it used, and which human or policy approved the final outcome.
  • Measure outcomes, not just throughput Tie delivery metrics to business-value indicators so AI-driven acceleration can be assessed for quality, not only speed or volume.
  • Review delegated access for AI systems Inventory any AI system that can call tools or initiate workflows, then validate that its permissions are bounded like other privileged non-human identities.

Key takeaways

  • The article’s core warning is that AI adoption is outpacing the governance model around it.
  • The visible pressure point is not only speed, but the loss of clear outcome measurement and delegated accountability.
  • Security and identity teams should model agentic AI as bounded runtime authority and enforce auditability before expanding use.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST AI RMF, NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST AI RMFGOVERNThe article centres on AI governance, oversight, and accountability in delivery workflows.
NIST CSF 2.0GV.OC-03Outcome visibility and governance alignment are central to the article’s visibility paradox.
NIST SP 800-53 Rev 5AU-2Agentic workflows need event logging and traceability for delegated actions.
NIST Zero Trust (SP 800-207)Zero Trust principles support continuous verification for delegated AI actions.

Map AI delivery metrics to business outcomes and review governance objectives alongside operational metrics.


Key terms

  • Agentic AI: Autonomous AI systems capable of planning, deciding, and taking actions — including calling APIs, writing code, and orchestrating other agents — with minimal human oversight. Agentic AI introduces new NHI risks as agents must authenticate to external services.
  • Governed autonomy: A state in which an AI or machine workflow can act with limited human intervention while remaining inside explicit policy, authorization, and audit boundaries. It is not the same as free-running autonomy, because the organisation can still explain and constrain what the system is allowed to do.
  • Visibility Paradox: A condition where organisations collect more operational data but still struggle to determine whether the work being done is the right work. In AI-enabled delivery, it describes the gap between faster execution and weaker outcome measurement, which makes governance harder, not easier.
  • Delegated Runtime Agency: The ability of a software system to make and execute choices at runtime using permissions, tools, or secrets that were granted to it. In AI security, this becomes a governance issue when the system can behave like an operator without being held to operator-grade controls.

What's in the full article

Arxan Technologies' full article covers the operational detail this post intentionally leaves for the source:

  • The full report’s survey breakdown shows how AI adoption varies across delivery functions and organisational maturity levels.
  • The source article includes the phased model for moving from AI assistance to agentic orchestration inside Agile workflows.
  • It also outlines the specific governance guardrails Digital.ai says it uses for traceable, contextual AI recommendations.
  • Readers will find the article’s full discussion of how teams are redefining value measurement as delivery automation expands.

👉 Arxan Technologies' full post covers the survey findings, the phased AI adoption model, and the delivery governance implications in more detail.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and identity lifecycle controls. It is designed for practitioners who need to govern delegated access and runtime authority across modern environments.
NHIMG Editorial Note
Published by the NHIMG editorial team on September 3, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org