By NHI Mgmt Group Editorial TeamDomain: AI SecuritySource: WitnessAIPublished July 21, 2026

TL;DR: MITRE’s AI maturity model gives organisations a structured way to score readiness across governance, data, technology, and operating model, but WitnessAI’s analysis makes clear that maturity alone cannot govern prompts, responses, or agent actions in real time. That gap matters because AI adoption is already outpacing control design, making runtime enforcement the decisive layer as agentic and customer-facing systems scale.


At a glance

What this is: This is an analysis of MITRE’s AI maturity model as an enterprise readiness diagnostic, with the key finding that maturity scoring helps assess governance but does not replace runtime controls for AI systems and agents.

Why it matters: It matters to IAM and security practitioners because AI adoption is increasingly creating access, approval, and data-boundary decisions that must be governed continuously, not only assessed at review time.

By the numbers:

👉 Read WitnessAI’s analysis of the MITRE AI maturity model and runtime AI control gaps


Context

MITRE’s AI maturity model is a readiness diagnostic, not a runtime enforcement framework. That distinction matters because many organisations are scaling AI pilots, copilots, chatbots, and agents before they have a stable view of governance, data controls, approval paths, or monitoring coverage across the enterprise. In practice, AI governance breaks when assessment is treated as control.

For IAM, PAM, and NHI programmes, the important question is not whether an AI initiative can be scored, but whether the system’s identity, privilege, and action boundaries are continuously enforced once it is live. The most relevant overlap is with AI agent identity and machine identity governance, because a model can look mature on paper while its credentials, tool access, and delegation paths remain unmanaged.

That makes the MITRE model useful as a board-level and programme-level baseline, but incomplete for operational security. Organisations that rely on a maturity score without pairing it with runtime policy, data controls, and access governance will usually overestimate their ability to contain AI-driven risk.


Key questions

Q: What breaks when AI maturity assessments are used as a substitute for runtime control?

A: The assessment becomes a snapshot of readiness rather than a live control, so unauthorised prompts, tool calls, and agent actions can still occur outside policy. Organisations then overestimate their ability to govern AI because the score reflects structure and process, not enforcement at the moment of execution.

Q: Why do AI tools create new identity governance risks for IAM teams?

A: AI tools create new identity governance risks because they combine fast adoption with broad access paths and subordinate permission objects. A user may look clean in the directory while the platform still holds project roles, service accounts, or keys that can act independently. That makes governance a control-plane problem, not a simple login problem.

Q: How do security teams know if AI governance is working?

A: Look for evidence that access decisions are reviewable, permissions are revocable, and exceptions are not becoming permanent. If the team cannot explain who owns an AI workflow, what it can reach, and when its access was last reviewed, governance is incomplete. Control maturity shows up in traceability, not adoption volume.

Q: Who is accountable when an AI agent makes an unauthorised change?

A: Accountability should be assigned to the governance model that authorised the delegation, the owner of the workflow, and the team that set the policy boundary. In practice, organisations need clear responsibility for agent configuration, monitoring, and incident response because the machine’s speed does not remove human accountability for the delegated identity.


Technical breakdown

How the MITRE AI maturity model structures enterprise readiness

The MITRE AI maturity model is a qualitative assessment that scores an organisation across six pillars, 20 dimensions, and five cumulative levels. Its value is structural: it turns scattered judgments about governance, data, technology, organisation, and performance into a repeatable baseline that can be revisited over time. Because the levels are cumulative, a weak governance foundation will constrain higher-stage AI adoption even if individual pilots appear successful. The model is therefore best read as an enterprise readiness map, not as proof that a specific AI system is safe to operate.

Practical implication: use the model to prioritise capability investment, but do not treat a high score as evidence of runtime control.

Why maturity scoring stops short of runtime authorisation

Maturity tools describe whether an organisation is ready to operate AI, but they do not answer the execution-layer question of whether a specific prompt, tool call, or agent action is authorised at that moment. That distinction becomes critical when AI systems can access business data, call external tools, or chain actions without human review. NIST AI RMF addresses risk management at the system level, while frameworks such as OWASP Agentic AI Top 10 and NHI governance focus on identity, privilege, and misuse paths that emerge during operation. The control problem is therefore temporal as much as structural.

Practical implication: pair maturity assessment with policy enforcement at the point of AI action.

Where AI governance overlaps with NHI and machine identity

AI programs increasingly depend on service accounts, tokens, API keys, and delegated permissions, which means the identity problem is no longer limited to human users. Agentic workflows often authenticate as non-human identities and then use those credentials to retrieve data or trigger downstream systems. That creates the same lifecycle questions that identity teams already manage for workloads and service accounts: who issued the credential, what it can reach, how long it lives, and whether its actions are attributable. When those questions are unanswered, AI governance becomes indistinguishable from secret sprawl.

Practical implication: bring NHI lifecycle, secrets governance, and privilege review into AI programme design from the start.


Threat narrative

Attacker objective: The objective is to turn an ungoverned AI workflow into a trusted execution path that can expose data, manipulate systems, or bypass normal approval controls.

  1. Entry occurs when employees, copilots, or agents begin using AI tools before formal approval, creating unreviewed access paths into data and business workflows.
  2. Escalation follows when those tools gain credentials, API access, or delegated permissions broader than the task requires, allowing prompts or agent actions to reach connected systems.
  3. Impact appears when runtime misuse, prompt injection, or unauthorised commands drive disclosure, configuration changes, or data movement beyond policy boundaries.

NHI Mgmt Group analysis

Maturity scoring is a governance signal, not a security control. The MITRE model is valuable because it gives leaders a common language for readiness, but readiness is not enforcement. Organisations can look disciplined on paper while still leaving prompts, tools, and agent actions outside policy coverage. That is why boards should treat maturity outputs as a prioritisation input, not as evidence that AI is safe to scale.

AI governance debt is now a material security problem. When adoption accelerates faster than policy, inventory, and runtime controls, organisations accumulate unresolved decisions about who can use which models, what data they can reach, and which actions must be blocked. This debt shows up first in shadow AI and then in sanctioned agentic workflows. Practitioners should read the model as a warning that governance lag is becoming operational exposure.

Identity is the missing bridge between AI strategy and AI control. The model usefully surfaces readiness across governance and data, but the decisive control layer for agentic systems is identity, privilege, and session-bound authorisation. That is where NHI governance becomes central, because AI systems are increasingly acting through service accounts, tokens, and delegated access. The practical conclusion is that AI maturity and identity governance must be assessed together.

Runtime policy must sit alongside framework alignment. NIST AI RMF, ISO/IEC 42001, and the EU AI Act each address important governance or compliance requirements, but none of them alone prevents an agent from making an unauthorised action in real time. That gap explains why organisations need executable controls in the workflow, not only policy documents and maturity scores. Practitioners should align framework work with runtime enforcement design.

What this signals

AI maturity programmes will increasingly be judged by whether they produce enforceable runtime controls, not just scores. That means security and identity teams should expect more pressure to show how AI systems are authenticated, what they can reach, and how their actions are monitored across the workflow. The practical shift is toward continuous authorisation rather than static approval.

Non-human identity governance is becoming part of AI governance by default. As agents and copilots adopt credentials, the same lifecycle problems that affect service accounts and tokens now apply to AI use cases. Teams should bring in the NHI Lifecycle Management Guide and the OWASP Agentic AI Top 10 to align credential control with agent risk.

A programme that can score AI maturity but cannot revoke, scope, or trace AI credentials is not ready for scale. Security leaders should watch for the growth of shadow AI, unmanaged agent permissions, and inconsistent ownership between AI, data, and IAM teams.


For practitioners

  • Define AI action boundaries Map which prompts, tools, data sets, and downstream systems each AI use case can touch, then separate approved from prohibited actions before scaling the workload. This is where governance becomes enforceable rather than descriptive.
  • Inventory non-human credentials used by AI systems Track every token, service account, API key, and delegated permission used by copilots, agents, and chatbots, including owner, expiry, and revocation path. That inventory should sit alongside your existing NHI register.
  • Add runtime policy to AI workflows Apply intent-based allow, warn, block, and route decisions at the moment an AI system acts, especially where prompts can trigger data access or external tool calls. Review these decisions as part of security operations, not only model governance.
  • Run cross-functional maturity reviews Use the MITRE assessment with security, data, legal, compliance, and AI owners in the same room so scoring disagreements surface hidden gaps. The point is to identify where policy, data, or operations are lagging, not to average the answers.

Key takeaways

  • MITRE’s AI maturity model is useful as a readiness baseline, but it cannot by itself stop risky AI actions at runtime.
  • The biggest governance gap is the one between organisational scoring and executable control over prompts, tools, and agent permissions.
  • Identity, privilege, and credential lifecycle management now sit inside AI governance, not beside it.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 address the attack surface, NIST AI RMF, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, and ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST AI RMFGOVERNThe article contrasts readiness scoring with AI governance accountability.
OWASP Agentic AI Top 10Agentic AI runtime misuse and identity abuse are central to the gap described here.
NIST CSF 2.0PR.AC-4The article’s access-boundary problem maps to least privilege and access management.
NIST SP 800-53 Rev 5AC-6Least privilege is the core control needed when AI systems can act through credentials.
ISO/IEC 27001:2022A.5.15The article’s governance gap depends on access control rules being defined and enforced.

Use the agentic AI risks list to design runtime controls around tool use, delegation, and approvals.


Key terms

  • AI maturity model: A structured framework for assessing how far an organisation has progressed in adopting and operationalising AI. In practice, it helps teams compare pilots, production use, and enterprise-wide integration by looking at governance, data quality, capability, and lifecycle discipline rather than adoption hype.
  • Runtime control: Controls that enforce policy while an AI system is operating, rather than after the fact. For healthcare chatbots, runtime control includes data masking, output filtering, access scoping, and immutable logging so the organisation can defend the interaction itself.
  • Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
  • Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.

What's in the full article

WitnessAI's full article covers the operational detail this post intentionally leaves for the source:

  • The full MITRE AI maturity assessment structure, including the six pillars and 20 dimensions used for scoring.
  • The step-by-step assessment workflow for assembling a cross-functional review and translating scores into a roadmap.
  • The specific relationship between maturity scoring, NIST AI RMF, ISO/IEC 42001, and the EU AI Act.
  • The runtime visibility and enforcement controls WitnessAI describes for AI prompts, responses, and agent actions.

👉 WitnessAI’s full article expands on the assessment steps, framework alignment, and runtime control gap.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps security and identity practitioners connect AI adoption to the controls needed for accountable access and lifecycle management.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 17, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org