TL;DR: Fortune’s 2026 Cyber 60 list spotlights 20 early-stage cybersecurity companies, and Zenity’s inclusion reflects how quickly AI agent security and governance have moved into mainstream enterprise concern, according to Zenity. The practical issue is not recognition itself but the widening gap between how agents behave at runtime and how current IAM and security controls are built to govern them.
At a glance
What this is: This is a recognition announcement that also signals how AI agent security is becoming a mainstream governance problem as enterprises deploy agents across SaaS, cloud and endpoint environments.
Why it matters: IAM and security teams need to treat AI agents as governed identities because their access, tool use and runtime behaviour can outgrow controls designed for static users or conventional service accounts.
Context
Fortune’s 2026 Cyber 60 list is a market signal, not just an award. In this case, the article uses that recognition to argue that AI agent security and governance are moving from niche concern to enterprise planning topic.
AI agents are not just another workload class. They invoke tools, touch multiple environments, and can act across SaaS, cloud and endpoint surfaces, which means the governance model has to follow the agent’s behaviour rather than assume static entitlement patterns.
Key questions
A: A useful DLP audit checklist should cover the full data path, not just one control layer. Start with data classification, then verify access controls, encryption, alerting, and incident handling across SaaS, cloud, and endpoint tools. Add clear review criteria, regular updates, and integration with operational workflows so the checklist drives action rather than becoming a static compliance document.
Q: Why do autonomous AI systems create more identity risk than normal automation?
A: Normal automation follows a fixed path, but autonomous systems can interpret goals, choose actions, and continue without waiting for a person. That makes intent less predictable and review cycles less useful. The risk increases when the system can broaden scope or trigger actions that affect data, money, or compliance.
Q: What breaks when discovery and posture management do not cover AI agents?
A: Blind spots appear immediately. Security teams lose track of which agents exist, which tools they invoke, and which environments they can reach, so policy enforcement becomes partial and incident response cannot reconstruct the full path of activity. Governance without discovery is incomplete by design.
Q: How do security teams know if AI governance is working?
A: Look for evidence that access decisions are reviewable, permissions are revocable, and exceptions are not becoming permanent. If the team cannot explain who owns an AI workflow, what it can reach, and when its access was last reviewed, governance is incomplete. Control maturity shows up in traceability, not adoption volume.
Technical breakdown
Why AI agent security needs runtime governance
AI agents change state during execution, not just at provisioning time. That matters because their access is often contextual, tool-dependent and short-lived, which makes static entitlement review an incomplete control model. The practical problem is not simply who created the agent, but what the agent can do once it starts selecting actions and invoking tools across environments. Security programmes that only track accounts, roles or apps miss the runtime layer where misuse happens. Practical implication: govern agent access at execution time, not only at onboarding or review time.
Practical implication: Shift controls from periodic entitlement review to runtime authorisation and activity monitoring for each agent session.
How multi-environment agent activity expands identity risk
The article points to agents operating across SaaS, cloud and endpoint environments. That cross-surface reach creates governance coupling because a single agent identity may inherit different trust assumptions in each environment while using the same access path. The result is a larger blast radius if policy is inconsistent or discovery is incomplete. For identity teams, the key question is whether each environment can independently inventory, authorise and audit agent activity without relying on a common assumption that the agent will behave predictably. Practical implication: align policy enforcement and auditability across all environments where agents are allowed to act.
Practical implication: Map each agent to every environment it can reach and verify that policy, logging and response are consistent across those boundaries.
Why agent discovery matters before control design
Zenity’s positioning around discovery and posture management reflects a basic governance reality: you cannot secure what you cannot inventory. In agentic environments, undiscovered agents, hidden integrations or loosely governed tool connections create blind spots that undermine policy enforcement and incident response. The issue is broader than configuration management because the identity itself may be dynamic, embedded or delegated through another platform. Practical implication: discovery must be the first governance layer for AI agents, otherwise later controls operate on an incomplete identity map.
Practical implication: Build a complete inventory of agents, tools and connected environments before attempting to enforce access policy or response workflows.
NHI Mgmt Group analysis
AI agent security is becoming an identity governance category, not a feature add-on. The article frames Fortune recognition as validation of a broader market shift: enterprises now need controls for agents that access tools, move across environments and act continuously. That is an identity problem because the unit of governance is no longer just a user or service account, but an actor whose access changes as the task changes. Practitioners should treat agent security as a core identity domain.
Runtime behaviour is the real governance boundary for agents. Traditional IAM assumes access can be provisioned, reviewed and certified against a stable description of the subject. AI agents break that assumption because the relevant risk appears while the task is running, when tool choice, context and execution path can diverge from the original approval. The implication is that entitlement models alone are too late in the control chain for agentic systems.
Cross-environment visibility is now a prerequisite for control consistency. The article highlights SaaS, cloud and endpoint coverage, which points to a common failure mode in agent programmes: policies exist, but not everywhere the agent can act. That creates uneven enforcement and blind spots in audit trails. The practitioner conclusion is simple: if an agent can cross environments, governance must cross environments with it.
Named concept: agentic control plane drift. This is the gap between where an agent is authorised and where it actually operates once tool use begins across multiple environments. It grows when discovery, policy and telemetry are managed in separate silos. The operational consequence is inconsistent authorisation logic, which forces security teams to rethink how they define the control plane for AI agents.
Recognition is a market signal, but the governance burden remains technical. Fortune Cyber 60 visibility indicates that agent security is now a category with buyer attention and vendor momentum. That does not reduce the governance challenge; it confirms it. Security leaders should assume more agent deployments, more integrations and more pressure to prove control coverage across the full agent lifecycle.
From our research library:
- Gartner predicts that more than 50% of successful cyberattacks against AI agents through 2029 will exploit access control weaknesses.
- Read next: AI Agent Authorisation Guide
What this signals
Agentic control plane drift: security teams now need to assume that an agent may be authorised in one system and operational in another, which makes cross-environment consistency a governance requirement rather than a reporting nicety. Discovery, policy and telemetry have to move together or the control plane fragments.
The programme implication is that identity teams should stop treating AI agents as isolated use cases. Once agents can invoke tools across SaaS, cloud and endpoint environments, the practical boundary becomes runtime authorisation, full inventory and enforceable auditability across every place the agent acts.
For practitioners
- Inventory every AI agent and connected tool Create a single inventory that includes agents, delegated tools, connected SaaS applications, cloud services and endpoint integrations. Without that map, policy enforcement and incident response will miss hidden access paths.
- Apply runtime authorisation to agent actions Do not rely on onboarding approval alone. Require policy checks at the moment an agent selects a tool or initiates a sensitive action, especially where the same identity can operate across multiple environments.
- Standardise audit trails across environments Make sure agent activity logs, policy decisions and response workflows are consistent in SaaS, cloud and endpoint stacks so investigators can reconstruct what the agent did from end to end.
- Review blast radius by agent task Assess each agent by the maximum access it can reach during a task, not just the role it was assigned at creation. This is where over-permissioned agents become a governance problem.
Key takeaways
- AI agent security is now a governance issue, not just a product category, because agents can act across multiple environments and change risk at runtime.
- The article’s central signal is that discovery, policy enforcement and auditability must follow the agent across SaaS, cloud and endpoint surfaces.
- Identity teams should focus on runtime authorisation and complete inventory before expanding agent deployments further.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | The article centres on how AI agents accumulate and exercise access across environments. |
| Recommendation — Apply ASI03 to govern agent privileges at runtime and limit tool reach by task. | ||
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | The piece highlights agents receiving broader access than their task requires. |
| NHI-06 — Insecure Cloud Deployment Configurations | The article references SaaS, cloud and endpoint coverage, making misconfiguration a control concern. | |
| Recommendation — Scope each agent to least-privilege access and revoke unused permissions across environments. Review cloud and SaaS agent deployment settings for policy gaps and inconsistent enforcement. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Agent governance depends on entitlements and authorisations being aligned to actual runtime use. |
| Recommendation — Align entitlements with actual agent activity and remove authorisations that exceed task need. | ||
| NIST Zero Trust (SP 800-207) | Policy Enforcement Point — Policy Enforcement Point | Agentic access needs decisions enforced where the action occurs, not only at provisioning time. |
| Recommendation — Place authorisation checks at the point of agent action and verify policy enforcement across environments. | ||
Key terms
- AI Agent Security Risk Review: An AI agent security risk review is an internal assessment that tests what a deployed agent can actually be made to do, who owns it, and whether its behavior fits bank risk policy. It goes beyond documentation to examine live tool use, data access, and governance accountability before or after deployment.
- Runtime Authorisation: Runtime authorisation is the practice of deciding access while a task is in progress, rather than only at provisioning time. It matters for NHIs because credentials and entitlements can change risk mid-session, especially when automation or AI agents interact with sensitive systems.
- Agent Inventory: A governed record of every AI agent in use, including who created it, who can invoke it, what data it can reach, and what actions it can trigger. Without a current inventory, security teams cannot judge whether agent access still matches the business purpose.
- Agentic Control-Plane Drift: The gradual expansion of an AI workflow from a narrow task into broader infrastructure authority. The risk is not simply that the agent acts quickly, but that the control plane starts absorbing tenant creation, secrets, integrations, and source control into one trust boundary.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 25, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org