TL;DR: AI agents are spreading across enterprise SaaS, cloud, and endpoint environments, with more than 80% of Fortune 500 companies already deploying autonomous systems, according to Zenity; Gartner naming Zenity a Cool Vendor in Agentic AI TRiSM reflects a wider shift. The security problem is no longer prompt filtering, but governing what agents can access, decide, and do in real time.
At a glance
What this is: Zenity argues that Gartner’s Agentic AI TRiSM signal marks a shift from prompt-focused controls to governance of what AI agents can access, decide and do across enterprise environments.
Why it matters: This matters because IAM, PAM and NHI programmes must treat AI agents as runtime actors with live tool and data access, not as static software features that can be governed after deployment.
Context
Agentic AI governance is the discipline of controlling what AI agents can access, which tools they may invoke, and how their actions are monitored across an enterprise stack. The gap here is that conventional security tooling was built for static applications and human-driven workflows, not runtime actors that can chain actions across systems.
Zenity frames Gartner’s TRiSM recognition as evidence that the market is moving toward agent-centric security rather than prompt-only filtering. For identity teams, the real question is whether current governance models can keep pace with autonomous systems that cross SaaS, cloud and endpoint boundaries.
The article also points to a larger identity problem: once an agent can decide and act at runtime, entitlement, observation and prevention have to move earlier in the lifecycle. That is typical of the current market direction, not an edge case.
Key questions
Q: What breaks when AI agents are not governed at runtime?
A: Without runtime governance, an agent can shift behaviour after provisioning and still execute actions that were never reviewed in context. That is where tool chaining, MCP connections, and rapid decision-making become dangerous. Static approval cannot stop a live change in intent, so teams lose control at the point of action.
Q: Why do AI agents create different access review risks than ordinary cloud workloads?
A: AI agents change the review problem because they combine machine speed, delegated permissions, and dynamic invocation patterns. Teams need to review both who can invoke the agent and what the underlying service account can reach. If those layers are not separated, access reviews miss the real blast radius and can give false confidence about control coverage.
Q: What are the signs that AI governance is failing in the enterprise?
A: Common warning signs include rapid growth in AI use without matching policy coverage, sensitive files being copied into personal accounts, and a large share of AI apps carrying high or critical risk. Another indicator is weak visibility into who is using which tools and what data they are sending. If teams cannot answer those questions, governance is not working as intended.
Q: How should IAM teams govern humans, NHIs, and AI agents in one programme?
A: Start by separating the control assumptions for each actor type. Humans need authentication and access review, NHIs need lifecycle control and secret governance, and AI agents need runtime scope enforcement because their tool use can change during execution. One programme can cover all three, but the policy model cannot treat them as interchangeable identities.
Technical breakdown
Agentic AI TRiSM is about runtime governance, not prompt filtering
Agentic AI TRiSM shifts the control plane from text inspection to runtime governance of an actor that can select tools, sequence actions, and continue execution without waiting for human approval. Prompt filters only inspect one input, but an agent can transform a benign prompt into a chain of tool calls, data access, and external actions. That changes the security object from a message to an execution path. The practical issue is not whether a prompt looks safe, but whether the agent can be constrained before it reaches sensitive data or privileged actions.
Practical implication: govern agent permissions, tool access and execution monitoring at runtime, not just prompt boundaries.
Why SaaS, cloud and endpoint agents create a new identity surface
AI agents embedded in SaaS, cloud and developer endpoints behave like non-human identities because they can authenticate, inherit context, and invoke APIs or other tools on behalf of a task. The article’s examples, from Microsoft 365 Copilot to AWS Bedrock agents and local coding assistants, show that the identity boundary now spans multiple operational planes. Traditional IAM often assumes the subject is either a user or a workload with stable intent. An agent breaks that simplification because its authority can expand or contract mid-task as it moves across systems.
Practical implication: inventory agents as identities, then map each one to its reachable data, tools and downstream systems.
Zero-click agent attacks expose the limits of existing detection assumptions
Zenity points to AgentFlayer-style research to show that agent abuse can occur without the obvious user action patterns defenders expect. In agentic systems, a malicious sequence may begin with a normal request and become dangerous only after the agent chains actions, calls tools, or consumes poisoned context. That means security teams cannot rely on single-event detection or prompt-level heuristics alone. The control question becomes whether the full execution path is observable and whether unsafe actions can be blocked before the chain completes.
Practical implication: instrument full agent execution paths so detection can evaluate intent across multiple steps.
Threat narrative
Attacker objective: The attacker aims to turn trusted agent autonomy into a path for unauthorized data access, tool misuse or unsafe system actions.
- Entry begins when an attacker influences an AI agent through a benign-looking request or compromised context in SaaS, cloud or endpoint workflows.
- Escalation occurs as the agent chains actions, invokes tools and accesses sensitive data beyond what a single prompt appears to permit.
- Impact follows when the agent performs unsafe actions at runtime, exposing data, altering systems or enabling follow-on compromise without adequate guardrails.
Breaches seen in the wild
- CoPhish OAuth phishing via Copilot Studio: Datadog showed Copilot Studio agents on a Microsoft domain can front OAuth consent phishing and forward stolen tokens; no victims reported.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Agentic AI TRiSM widens the governance gap because the control problem has moved from input moderation to runtime authority. Traditional security programmes were designed to inspect prompts, sessions or isolated requests. That model fails when the actor can decide which tool to call next and when to do it. The implication is that identity governance has to treat agent execution as the unit of control, not the prompt.
Access review is the wrong primary control for many autonomous agents. Review processes assume authority persists long enough to be certified, remediated and recertified. An agent that acquires, combines and discards privileges inside one execution path leaves little durable state for classic governance cycles to inspect. The result is assumption collapse: entitlement governance built for stable access windows no longer matches agent-timed behavior.
Agent-centric security is becoming the organising concept for this category. The article’s emphasis on lifecycle visibility, permission governance and step-level monitoring reflects where the market is heading, namely toward controls that bind to the agent rather than the application shell around it. For identity leaders, this validates a shift in programme design from application-centric oversight to actor-centric governance.
Ephemeral execution path governance: The useful concept here is not just least privilege, but the ability to govern what an agent may do across a short, branching, multi-tool execution path. That is a different control problem from static workload or user access. Practitioners should now treat agent runtime paths as a distinct governance surface alongside human IAM and NHI lifecycle controls.
Zero Trust for agents is no longer optional rhetoric. If an agent can cross SaaS, cloud and endpoint boundaries while retaining effective authority, the trust boundary has already expanded beyond what most governance models assumed. The field now needs stronger policy enforcement around authorisation, memory usage and tool invocation. Identity teams should prepare to align agent governance with zero-trust-style verification at every step.
From our research library:
- 69% of security leaders agree identity management must fundamentally shift to address agentic AI systems, according to the 2026 Infrastructure Identity Survey.
- Gartner predicts that more than 40% of agentic AI projects will be cancelled by the end of 2027, citing rising costs, unclear value and insufficient risk controls.
- Read next: Agentic AI Security Guide
What this signals
Ephemeral execution path governance: Agentic AI pushes identity teams toward controls that bind to runtime behavior, not just static entitlements. When an actor can decide and execute in the same session, review cycles become secondary to issuance-time policy and step-level enforcement.
Gartner’s signal is less about a vendor category and more about a control boundary change: security programmes that still separate application security, IAM and NHI governance will struggle to cover autonomous actors coherently. The practical watchpoint is whether your current model can express who owns the agent, what it may do, and how far its authority can branch.
For practitioners
- Inventory AI agents as governable identities Build an inventory of all agents across SaaS, cloud and endpoint environments, then record which data, tools and systems each one can reach. Separate discovered agents from shadow deployments and map ownership before allowing production access.
- Bind permissions to agent lifecycle stages Apply security-by-design controls before deployment and review them again when an agent changes memory, tools or data scope. Use lifecycle checkpoints to catch privilege drift that would be invisible in ordinary application reviews.
- Monitor full execution paths for unsafe actions Instrument step-level telemetry so you can detect when a benign request turns into a chain of risky tool calls, external API access or data movement. Alert on action sequences, not just suspicious prompts.
- Separate prompt controls from authority controls Treat prompt analysis as one signal, not the control boundary. Enforce policy on the agent’s tool permissions, data access and action limits so a safe-looking prompt cannot drive an unsafe outcome.
Key takeaways
- Agentic AI changes the identity problem from checking prompts to governing runtime authority, which makes traditional application security an incomplete control model.
- The article reflects a market shift toward agent-centric governance because autonomous systems can chain actions across SaaS, cloud and endpoint environments.
- Practitioners need inventory, lifecycle controls and step-level monitoring to keep agent behaviour inside bounded authority.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10, OWASP Non-Human Identity Top 10 and MITRE ATLAS address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | The article centers on agents gaining and exercising authority across tools and data. |
| Recommendation — Constrain agent identity and privilege so runtime authority cannot expand beyond policy. | ||
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | AI agents here behave as non-human identities with excessive access scope. |
| Recommendation — Audit agent entitlements and reduce any access that is broader than task scope. | ||
| NIST AI RMF | GOVERN — AI Governance and Accountability | The article is about governance structures for autonomous AI systems in production. |
| Recommendation — Assign accountable owners and governance controls for every production AI agent. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Agent access permissions and authorisations are the core control problem discussed. |
| Recommendation — Review agent permissions continuously and remove any authorisations not needed for the task. | ||
| MITRE ATLAS | TA0006;TA0008 — Credential Access; Lateral Movement | The article references attack chains where agents can be manipulated to reach more systems. |
| Recommendation — Map agent compromise scenarios to credential access and lateral movement to improve detection coverage. | ||
Key terms
- Agentic Ai Trism: Agentic AI TRiSM is the governance pattern for trusted, risk-managed, and secure AI agents. It focuses on how agents are authorised, observed, and constrained while they make runtime decisions across tools and systems, rather than only approving the model or application at deployment time.
- Agent-centric security: A security model that treats the AI agent itself as the thing being governed, not just the prompt, model, or hosting application. It focuses on what the agent can access, what actions it can chain, and how those actions are observed and constrained.
- Runtime authority: Runtime authority is the permission an AI system has while it is actively deciding and acting, not just when it is approved. In governance terms, it is the point where access, tool use, and action scope become operational, which is why build-time review alone cannot prove safety.
- Execution Path: An execution path is the chain of systems, roles, functions, and permissions that an identity uses to reach a target service. For AI agents, this matters more than the label on the agent itself because effective authority often comes from the path, not the object.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org