By NHI Mgmt Group Editorial TeamDomain: Agentic AI & NHIsSource: CyberhavenPublished April 16, 2026

TL;DR: AI agents are running autonomously across endpoints, files, tools, and data stores, and legacy DLP and EDR cannot govern machine-speed behaviour without human oversight or a reliable audit trail, according to Cyberhaven’s whitepaper. The governance problem is no longer theoretical: access review and containment models built for human-paced identity break when agents decide and act inside the same session.


At a glance

What this is: This whitepaper argues that agentic AI now operates as an enterprise identity class that existing DLP and EDR controls cannot govern on their own.

Why it matters: IAM, PAM, and NHI teams need to treat autonomous agents as a distinct governance surface because visibility gaps, weak lineage, and missing control points compound quickly across identity programmes.

By the numbers:

  • 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%).

👉 Read Cyberhaven's whitepaper on governing autonomous AI agents


Context

Agentic AI governance is the problem of controlling software that can choose actions, use tools, and move data without a human approving each step. In this whitepaper, Cyberhaven argues that those agents are already operating on endpoints and across enterprise systems, which means identity control now extends beyond people and service accounts into autonomous runtime behaviour.

The primary governance failure is not simple visibility loss. It is that legacy DLP and EDR were built for human-paced workflows, while agents can move across files, tools, and data stores at machine speed with no reliable audit trail. That shifts the identity question from who clicked to what actor is allowed to decide and execute in the first place.

For IAM and NHI programmes, this is a lifecycle problem as much as a detection problem. If the enterprise cannot model agent identity, scope, lineage, and revocation as a single control plane, then every downstream alert becomes harder to trust and slower to investigate.


Key questions

Q: How should organisations govern AI agents that act as business units of work?

A: Organisations should govern AI agents as first-class non-human identities. That means assigning named ownership, defining the scope of permitted actions, separating duties such as propose versus publish, and requiring auditable logs and revocation paths before the agent is allowed into production. The governance model belongs in procurement, not just in the technical rollout.

Q: What breaks when existing DLP and EDR tools are used to monitor AI agents?

A: Those tools break at the point where agent behaviour becomes sequential and contextual rather than single-event based. DLP may see one transfer, and EDR may see one process, but neither understands the full conversation thread, tool chain, or data provenance needed to judge the actual risk.

Q: Why do AI agents complicate existing IAM and NHI governance models?

A: AI agents complicate governance because access is no longer confined to a single environment or a single identity type. An agent may need cloud runtime permissions, customer data access, and tool-level OAuth tokens at the same time, which means standing privilege and lifecycle assumptions break down fast. That is why one control model rarely covers the full path.

Q: How can organisations reduce risk from AI clients without blocking adoption?

A: Organisations should reduce risk by removing shared secrets, narrowing tool scopes, and making delegation reviewable. That lets AI clients operate with less standing privilege while still preserving business value. The goal is not to stop agent use, but to make every access path attributable and revocable.


Technical breakdown

Why legacy DLP and EDR struggle with agentic AI

DLP and EDR were designed around observable human or endpoint events, such as a file download, a process launch, or a suspicious exfiltration path. Agentic AI changes the timing and sequencing of those events because the system can decide, chain tools, and move data without waiting for human approval. That reduces the value of point-in-time telemetry and makes isolated alerts less useful than a continuous model of identity, intent, and data lineage. The control failure is not that telemetry disappears, but that the actor outruns the governance model.

Practical implication: Treat DLP and EDR as partial signals and add control logic that can understand agent identity, not just endpoint activity.

Visibility, observability, and controls as one governance system

Cyberhaven’s framing is useful because it treats visibility, observability, and controls as a coupled system rather than separate projects. Visibility answers what the agent touched, observability explains how the action unfolded, and controls enforce what the agent may do next. If any pillar is weak, the other two become less actionable because the investigation lacks context and the policy lacks enforcement points. For autonomous systems, that coupling matters more than in human IAM because the same session can create, consume, and propagate risk before a review cycle begins.

Practical implication: Build agent governance so telemetry, policy, and enforcement share the same identity and data model.

Data lineage is the missing anchor for AI agent investigations

Data lineage connects an agent’s action to the source, destination, tool path, and downstream consequence. Without that chain, security teams see isolated alerts but cannot reconstruct whether a prompt, tool call, file access, or data transfer caused the exposure. In agentic environments, lineage becomes the difference between an alert that is interesting and an alert that is operationally useful. It also creates a bridge between AI governance and classic identity work because the same lineage can support entitlement review, incident scoping, and least-privilege analysis.

Practical implication: Prioritise lineage capture before broad agent deployment so investigations can trace actions end to end.


Threat narrative

Attacker objective: The attacker objective is to abuse the agent’s legitimate access path so data movement, credential exposure, or unauthorized system interaction occurs inside normal enterprise workflows.

  1. Entry begins when an AI agent is granted legitimate access to endpoints, tools, and data stores that were originally authorised for productivity use. Escalation follows when the agent is allowed to chain actions across those systems without a human approval gate between steps. Impact occurs when the agent moves or exposes data faster than legacy controls can classify, review, or contain the activity.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Agentic AI turns identity governance into runtime control, not just access management. The article’s core point is that autonomous agents do not wait for a review cycle or remain within a static permission set. That means the enterprise is no longer governing a user session or a workload credential in isolation. It is governing a decision-making actor whose access pattern changes as the task unfolds, so the practitioner problem becomes runtime scope control across identity, data, and tools.

Legacy review models assume privilege persists long enough to be inspected. Access certification, recertification, and periodic review were designed for identities that remain observable over time. That assumption fails when an autonomous agent can acquire, combine, and consume access within a short execution window. The implication is not simply that teams need more review, but that they must rethink what counts as a reviewable identity state.

Data lineage is the named concept that connects AI governance to identity operations. Without a lineage model, security teams cannot tie an agent action to source data, tool use, and downstream exposure. That makes incident reconstruction, policy tuning, and entitlement analysis separate exercises instead of one coherent control loop. Practitioners should treat lineage as the bridge between AI observability and identity evidence.

AI agents are becoming a new non-human identity population that existing tooling does not fully classify. The category spans workload identity, delegated access, and autonomous execution, so governance cannot be bolted onto one layer alone. NHI, IAM, and AI risk functions all need a shared model for ownership, scope, and revocation if the enterprise is going to manage agent behaviour without creating blind spots.

The market is moving toward governance frameworks that combine identity, data, and runtime signals. The whitepaper reflects a broader shift away from siloed controls and toward systems that can correlate who or what acted, what it could see, and where the data went. That direction favours programmes that already connect IGA, PAM, and NHI governance rather than those that still treat AI security as a separate stack.

From our research:

  • 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%), according to AI Agents: The New Attack Surface report.
  • 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.
  • If you are building the control model behind autonomous actors, review OWASP Agentic AI Top 10 alongside NIST AI Risk Management Framework for the governance layer.

What this signals

Runtime identity will become the unit of control for agentic programmes. Teams that still treat AI agents as extensions of endpoint tooling will keep missing the governance problem. The practical shift is toward policies that follow the actor across tasks, tools, and data paths, with ownership and revocation tied to the agent itself rather than the device it runs on.

Data lineage is becoming operational, not optional. When 80% of organisations already report out-of-scope agent behaviour, the next question is not whether alerts exist, but whether they can be investigated with enough context to drive containment. That is why lineage, IAM evidence, and security telemetry need to converge into one investigation workflow.

Agentic AI expands the scope of NHI governance into systems that make decisions at runtime. Security teams should expect pressure to reconcile AI risk, PAM, and NHI controls in the same programme review cycle, especially where autonomous access reaches sensitive data. The organisations that do this well will spend less time proving what happened and more time preventing repeat exposure.


For practitioners

  • Model AI agents as governed identities Assign each agent an owner, a purpose, and a scoped policy boundary so the agent is managed like a runtime identity rather than an untracked automation path.
  • Tie alerts to data lineage Require every high-risk agent event to carry source, destination, and transformation context so investigators can reconstruct the action path without manual correlation.
  • Align DLP and EDR with agent runtime behaviour Test whether your current monitoring can explain machine-speed actions across files, tools, and data stores, then identify where policy enforcement stops at the endpoint.
  • Define revocation triggers for autonomous sessions Set explicit conditions that terminate or constrain an agent when it crosses scope, touches restricted data, or attempts tool combinations outside its approved task.
  • Integrate IAM, PAM, and AI governance reviews Use a shared review process for agent permissions, privileged actions, and data access so the same identity change does not bypass separate control owners.

Key takeaways

  • Agentic AI changes the identity problem from who has access to what an autonomous actor can decide to do at runtime.
  • Legacy DLP and EDR cannot fully govern machine-speed behaviour without data lineage and identity correlation.
  • IAM, PAM, and NHI teams should align on a shared control model for owners, scope, and revocation before agent deployment scales further.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10AGENT-03The article centers on autonomous agent scope, tool use, and runtime control.
NIST AI RMFGOVERNThe whitepaper is fundamentally about governance for AI agents in production.
OWASP Non-Human Identity Top 10NHI-03Agent identities need lifecycle and privilege management like other non-human identities.
NIST CSF 2.0PR.AC-4Access permissions and least privilege are central to agent governance.
NIST Zero Trust (SP 800-207)5.2Zero trust principles fit agents that move across tools and data stores.

Verify every agent action continuously rather than trusting session start authentication.


Key terms

  • Agentic AI: Autonomous AI systems capable of planning, deciding, and taking actions — including calling APIs, writing code, and orchestrating other agents — with minimal human oversight. Agentic AI introduces new NHI risks as agents must authenticate to external services.
  • Data Lineage: The record of how data moves across systems, applications, and workflows. In security operations, lineage shows where sensitive data propagates, which identities touch it, and how a compromise could spread across connected environments.
  • Runtime Identity: Runtime identity is the practice of making identity and authorization decisions at the moment an action occurs. For agents and workloads, it means access is validated against live context, not only against the identity state set during onboarding or provisioning. That makes accountability and scope enforcement possible inside fast-moving workflows.

What's in the full article

Cyberhaven's full whitepaper covers the operational detail this post intentionally leaves for the source:

  • The three-pillar framework for governing agentic AI across visibility, observability, and control
  • The specific ways legacy DLP and EDR fail when agents act across endpoints and data stores at machine speed
  • The data lineage model used to turn isolated alerts into an investigation path
  • The operational guardrails security teams can use to govern autonomous agents without blocking productivity

👉 Cyberhaven's full whitepaper covers the three-pillar framework, data lineage approach, and governance model in more operational detail.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity security programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org