By NHI Mgmt Group Editorial TeamBased on Zenity: “Zenity Sets the Foundation for Guardian Agents with Continuous, Contextual Security” (March 23, 2026)

TL;DR: AI agent risk evolves across configuration, runtime behavior, memory, and tool use, so snapshot scans and stateless prompt analysis miss multi-step attacks and stale exposure states, according to Zenity. The governance shift is from periodic monitoring to continuous, contextual risk assessment that can track agent behaviour as it changes.


At a glance

What this is: This is Zenity’s case for continuous, contextual security for AI agents, arguing that agent risk changes in real time across posture, runtime behaviour, memory, and tool use.

Why it matters: It matters because IAM, SecOps, and AI governance teams cannot treat AI agents like static accounts or one-time scans if they want timely control over access, behaviour, and exposure.


Context

AI agent security is not a snapshot problem. Once an agent can rewrite instructions, update memory, and change how it behaves during a session, a one-time posture check becomes obsolete almost immediately.

The governance gap is that many teams still assess agent risk as if it were static, even though permissions, connectors, and runtime decisions shift as the agent works. That is the wrong model for AI agent identity and access.

This article argues for continuous contextual security as the baseline for enterprise AI agent governance, which places the control problem squarely in live behaviour, not just configuration state.


Key questions

Q: What breaks when AI agent security relies on snapshot scans?

A: Snapshot scans go stale as soon as an agent changes memory, permissions, connectors, or runtime behaviour. That means the control can describe yesterday’s state while the agent is already operating in a different one. Teams lose the ability to see how exposure develops across interactions, which is where the real risk sits.

Q: Why do AI security programs need continuous risk assessment rather than periodic reviews?

A: AI environments change quickly as models, prompts, data sources, and deployment patterns evolve. Periodic reviews often miss drift in controls, unapproved use cases, and new compliance gaps. Continuous risk assessment helps security teams detect issues early, keep governance evidence current, and maintain assurance that AI systems remain within approved operating boundaries.

Q: What are the signs that AI governance is failing in the enterprise?

A: Common warning signs include rapid growth in AI use without matching policy coverage, sensitive files being copied into personal accounts, and a large share of AI apps carrying high or critical risk. Another indicator is weak visibility into who is using which tools and what data they are sending. If teams cannot answer those questions, governance is not working as intended.

Q: How should teams respond when agent context and tool use create active risk?

A: Teams should treat correlated posture, runtime, and environmental signals as the trigger for action, not isolated alerts. When tool invocation and context changes line up with exposure, the issue is no longer theoretical. The response should prioritize containment of the active agent path and review of the linked control surface.


How it works in practice

Why snapshot posture scans miss AI agent risk

Snapshot posture scanning records a moment in time, then assumes the state stays close enough to remain useful. For AI agents, that assumption fails because exposure can change as instructions, memory, permissions, and connected tools change during execution. Stateless prompt analysis also misses attacks that only become visible after several turns or events. The result is a security view that can be accurate when captured and wrong by the time it is acted on.

Practical implication: shift from point-in-time review to event-driven monitoring of agent state and behaviour.

How runtime behaviour and memory change the identity problem

AI agents are not just consumers of access. They can update context, alter execution paths, and use memory to carry prior state into later actions. That means identity risk is no longer limited to who authenticated at the start of the session, but also what the agent remembers, what it decides next, and which connectors it invokes. In identity terms, the control surface expands from issuance to live use.

Practical implication: govern agent memory, tool invocation, and session context as part of the access model.

Why multi-step prompt injection and tool misuse need correlated signals

Multi-step prompt injection and tool misuse often look harmless in isolation. The real risk appears only when posture, session activity, and environmental signals are correlated into one risk object. That correlation is what turns disconnected events into a defensible security decision. Without it, teams can see exposure and behaviour separately but fail to understand when they intersect into an active incident path.

Practical implication: correlate posture and runtime telemetry before triaging agent risk or escalating response.


NHI Mgmt Group analysis

Continuous context is the right unit of control for AI agents. AI agent behaviour changes during execution, so static scans and one-off approvals are structurally too small to govern the risk. The field needs to treat state, memory, connectors, and runtime actions as one moving control surface. Practitioner implication: build governance around live agent state rather than configuration snapshots.

Snapshot governance assumes the wrong persistence model. Traditional access review and posture practices assume there is a stable state to review after the fact. That assumption weakens when an agent can alter context, invoke tools, and shift exposure inside the same session. Practitioner implication: move control points upstream to runtime observation and correlated event handling.

Agent context is now part of the security perimeter. When instructions, memory, and tool access all influence behaviour, the perimeter is no longer just identity proofing or connector inventory. Continuous, contextual security becomes a governance requirement because risk emerges from the interaction of those elements, not any single one alone. Practitioner implication: align AI agent governance with operational telemetry, not policy documents alone.

Real-time risk correlation is the differentiator that matters. Teams do not need more disconnected alerts about agents. They need risk objects that connect posture, runtime behaviour, and environment changes into a single decision view. That is the only way to prioritise what is actively becoming dangerous. Practitioner implication: invest in correlation logic that maps exposure to live agent action.

AI agent governance is converging with identity lifecycle discipline. The same lifecycle questions that matter for humans and NHIs now matter for agents: what they can access, how that access changes, and when the control state no longer matches reality. The difference is speed and volatility. Practitioner implication: treat agent governance as lifecycle management under continuous change.

From our research library:

What this signals

Continuous contextual security is the right response to a control problem that changes faster than review cycles. AI agent governance fails when teams rely on snapshots of posture or permissions, because those states can change while the session is still active. The practical shift is from periodic certification to live correlation of what the agent can do and what it is doing.

Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security, according to the 2026 Infrastructure Identity Survey. That gap shows policy maturity is lagging far behind deployment, which means most programmes are still trying to govern volatile behaviour with static controls.


For practitioners

  • Adopt event-driven agent monitoring Replace periodic posture scans with event-driven ingestion that tracks configuration, permission, MCP, and connector changes as they happen.
  • Correlate posture and runtime telemetry Create unified risk objects that combine posture, runtime activity, and environmental signals so teams can see when exposure becomes active behaviour.
  • Review agent memory and instruction mutation paths Identify where agents can rewrite instructions, retain context, or carry stale state into later actions, then place controls around those transitions.
  • Prioritise multi-step attack paths Tune triage to spot prompt injection, gradual data exfiltration, and tool misuse that only become obvious across multiple interactions.

Key takeaways

  • AI agent security cannot rely on one-time scans because behaviour, memory, permissions, and tool use can all change during a session.
  • The article’s core evidence is that disconnected signals and snapshot analysis miss multi-step attacks and leave teams with stale exposure data.
  • Practitioners should move governance to continuous correlation, where posture and runtime behaviour are assessed together before risk decisions are made.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseThe article centres on AI agent behaviour, access, and evolving privilege during runtime.
ASI02 — Tool MisuseZenity highlights tool invocation and multi-step misuse as core AI agent risks.
Recommendation — Correlate agent context and privileges to detect identity and privilege abuse as it emerges. Monitor tool invocation paths for misuse that only appears across multiple agent interactions.
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationThe article ties agent security to evolving access state and control over connected systems.
NHI-05 — Overprivileged NHIZenity’s analysis focuses on agent access that can exceed intended scope during execution.
NHI-08 — Environment IsolationThe article discusses interactions between agents, users, sessions, and enterprise systems.
Recommendation — Enforce strong authentication boundaries for agent access and re-evaluate them as runtime context changes. Review agent permissions for excess scope and remove standing access that outlives the task. Separate agent execution environments so context and access changes do not bleed across sessions.
NIST AI RMFGOVERN — AI Governance and AccountabilityThe piece is about governance of AI systems whose risk changes over time.
Recommendation — Assign governance ownership for live AI risk monitoring, escalation, and accountability.

Key terms

  • Continuous contextual security: A security model that updates risk using live identity, runtime, and environment signals instead of periodic snapshots. For AI agents, it means the control plane follows changing permissions, memory, connectors, and tool use so governance reflects current behaviour rather than a stale posture view.
  • Stateful threat detection: Stateful threat detection evaluates behaviour across a session instead of treating each request as independent. For AI agents, that means preserving context across prompts, memory updates, and tool calls so an attack that looks harmless in one step can be recognised as malicious when the sequence is complete.
  • Agent Memory: Agent memory is the stored context an AI agent uses across sessions or tasks. In governance terms, it is controlled state, because the memories an agent retains can influence future actions, permissions use, and the safety of subsequent decisions.
  • Runtime correlation: Runtime correlation is the practice of joining identity state changes with security activity while an investigation is still active. It lets teams evaluate whether access use matches expected behaviour, which is more useful than reviewing entitlement records after the fact.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 6, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org