By NHI Mgmt Group Editorial TeamBased on Zenity: “Zenity Named the “Company to Beat” in AI Agent Governance in New Gartner® Report” (April 23, 2026)

TL;DR: Enterprise AI agent governance is moving beyond static policy controls toward continuous monitoring, intent-aware detection and runtime enforcement across SaaS, cloud and endpoint environments, according to Gartner’s assessment of Zenity. That shift matters because autonomous agents can act across heterogeneous systems faster than traditional review cycles can observe or contain them.


At a glance

What this is: Zenity’s analysis, framed through a Gartner callout, argues that AI agent security now depends on runtime governance rather than static policy controls as agents operate across heterogeneous enterprise environments.

Why it matters: For IAM, IGA and PAM teams, the shift matters because AI agents can initiate actions across systems in ways that outpace review cycles, forcing governance to move closer to execution time.


Context

AI agent governance is the discipline of controlling what autonomous software agents can access, do and invoke while they are running. In this article, the central claim is that static, policy-based controls are no longer sufficient when agents can cross SaaS, cloud and endpoint environments in a single workflow.

The governance gap is not just visibility. It is the mismatch between review-based identity controls and agents that can change state, call tools and touch data faster than conventional certification or exception processes can keep up. That makes runtime enforcement the operational centre of gravity for AI agent programmes.


Key questions

Q: What breaks when AI agents are not governed at runtime?

A: Without runtime governance, an agent can shift behaviour after provisioning and still execute actions that were never reviewed in context. That is where tool chaining, MCP connections, and rapid decision-making become dangerous. Static approval cannot stop a live change in intent, so teams lose control at the point of action.

Q: Why do AI agents need runtime controls instead of only pre-approved access?

A: Pre-approved access cannot tell you what the agent will do once prompts, tools, memory, and sub-agents start interacting. Runtime controls matter because the risky event is the action itself, not the entitlement on paper. If the workflow can change mid-session, the control must be able to intervene mid-session too.

Q: How do teams know whether AI governance is actually working?

A: Look for evidence that every AI interaction can be traced end to end, from identity and intent to output and enforcement. If auditors can ask for a transaction and receive a complete record in hours, not weeks, the programme is producing usable control evidence rather than just documentation.

Q: Who is accountable when shadow AI is used from managed endpoints?

A: Accountability sits with the organisation that owns the endpoint governance model, not just with the individual user. Security, IAM, and compliance teams need a shared view of approved AI usage, device restrictions, and evidence retention so shadow AI does not become an unmanaged exception path.


Technical breakdown

Why static policy control fails for autonomous agents

Static policy controls assume the relevant access decision can be expressed in advance and then enforced consistently at request time. AI agents break that assumption because they can choose actions, sequence tool calls and touch multiple systems during a single runtime session. In that model, the risk is not only misconfiguration but decision-making that unfolds after provisioning, outside the cadence of traditional access review. Continuous monitoring therefore becomes part of the control plane, not a secondary detective layer.

Practical implication: shift AI agent governance from approval-only rules to runtime controls that can inspect behaviour as it happens.

How intent-aware detection changes agent security

Intent-aware detection looks at whether an agent’s runtime behaviour matches the purpose it was authorised for, not just whether the action was syntactically allowed. That matters because malicious manipulation can ride on otherwise legitimate tools, memory access and data flows. For AI agents, the security question becomes whether the observed sequence still aligns with the approved task context. This is materially different from traditional policy enforcement, which often sees only allowed or denied actions without the surrounding operational intent.

Practical implication: require telemetry that can correlate tool use, memory access and data usage with the agent’s declared task.

Why shadow AI discovery is now a governance control

Shadow AI is not simply an inventory problem. It is the presence of unmanaged agents that may already hold credentials, invoke tools or interact with sensitive data without being inside the governance process. Once agentic systems are embedded in citizen developer platforms and departmental workflows, undiscovered instances can create policy drift faster than central teams can manually reconcile. Discovery, posture management and lifecycle control therefore belong together as one governance function.

Practical implication: treat discovery of unmanaged agents as a prerequisite for any credible AI agent access model.


Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Runtime governance is becoming the control boundary for AI agents. The old assumption was that policy could be set before access was exercised and then verified later through reviews or audit. That assumption fails when agents can decide, act and move across environments inside a single operational session. The implication is that governance programmes must measure control effectiveness at execution time, not only at provisioning time.

Intent-aware enforcement is the right framing for agent security. AI agent risk is not reducible to allowlists or static permission sets because a permitted tool call can still be malicious in context. The article points to monitoring of tool calls, memory access and data usage as the meaningful security signal. That means practitioners should treat agent intent as a governance variable, not a logging detail.

Shadow AI creates identity debt before security teams see the system. Unmanaged agents can be built, copied or embedded in citizen developer platforms long before they are formally registered. Once that happens, the organisation inherits access, data and lifecycle obligations without owning the inventory. Shadow AI governance: this is the control gap created when runtime agents exist outside discovery, and it is the blind spot most identity programmes are still underestimating.

AI agent governance is converging with broader identity lifecycle discipline. The article makes clear that agents now need discovery, posture management, runtime enforcement and lifecycle coverage across environments. That is a governance pattern, not a one-off security feature. The practical conclusion is that IAM, IGA and PAM teams need a shared operating model for human, NHI and autonomous identities instead of separate exception paths.

The market is shifting from static control products to behavioural governance platforms. Gartner’s framing suggests buyers will increasingly evaluate whether a control plane can follow the agent through SaaS, cloud, endpoint and inter-agent interactions. That raises the bar for governance maturity across the market. Practitioners should expect AI agent programmes to be judged on runtime observability and containment, not just policy coverage.

From our research library:

What this signals

Runtime governance is now the control plane for AI agents: when agents can invoke tools, touch data and act across SaaS, cloud and endpoint environments, governance has to move from periodic review to continuous enforcement. That shift is already visible in agent programmes that treat discovery, posture management and execution-time checks as one lifecycle.

Identity teams should expect AI agent risk to blur the line between IAM, IGA and PAM. The practical challenge is not just granting access but proving that an agent stayed within its intended task while using that access, which makes intent-aware telemetry a first-class requirement.

Shadow AI governance: unmanaged agents create hidden access paths long before they are formally added to the inventory. Once a citizen developer platform or workflow engine can spin up an agent, the control problem becomes one of finding and classifying those identities before they accumulate lasting privilege.


For practitioners

  • Define runtime control points for AI agents Map where agent decisions can be observed and constrained during execution, not just where access is granted. Prioritise tool invocation, memory access and cross-environment actions as control points.
  • Inventory shadow AI before expanding agent access Create a discovery process for agents embedded in citizen developer platforms, custom workflows and endpoint deployments. Unknown agents should be treated as governed assets only after they are identified and classified.
  • Align access reviews to agent lifecycle stages Separate build-time approval, runtime enforcement and post-execution review so lifecycle governance matches how agents actually operate. Do not rely on periodic recertification alone for systems that can act within minutes.
  • Correlate behaviour with declared intent Require telemetry that ties tool use, data access and action sequences back to the task the agent was authorised to perform. Behaviour that drifts outside that declared intent should trigger containment and investigation.

Key takeaways

  • AI agent governance is moving away from static policy enforcement and toward runtime control because autonomous systems can act faster than review cycles can see.
  • The article ties that shift to a broader market reality: security teams need discovery, intent-aware monitoring and enforcement across SaaS, cloud and endpoint environments.
  • For practitioners, the immediate lesson is to govern AI agents as active identities with lifecycle, telemetry and containment requirements, not as ordinary application settings.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10, MITRE ATLAS and CSA MAESTRO address the attack and risk surface, while NIST AI RMF sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseThe article centres on agent runtime behaviour, privilege use and governance gaps.
ASI10 — Rogue AgentsShadow AI discovery and unmanaged agents are a direct theme of the article.
Recommendation — Apply ASI03 to govern agent privileges and inspect runtime behaviour against authorised intent. Map undiscovered agents to ASI10 and require discovery before operational access is granted.
NIST AI RMFGOVERN — AI Governance and AccountabilityThe article is fundamentally about enterprise governance of autonomous AI systems.
Recommendation — Establish governance ownership, accountability and lifecycle oversight for AI agents under GOVERN.
MITRE ATLASTA0006;TA0008 — Credential Access; Lateral MovementThe article discusses agent behaviour that can pivot across environments and access sensitive data.
Recommendation — Map observed agent abuse paths to credential access and lateral movement techniques for detection.
CSA MAESTROAgentic AI Threat ModelingRuntime enforcement and tool misuse align with agentic AI threat modeling concerns.
Recommendation — Use MAESTRO to model agent tool-use, intent drift and cross-environment abuse paths.

Key terms

  • Runtime Governance: Runtime governance is the set of controls that verify what a system or agent is actually doing after deployment. It combines monitoring, authorization checks, and access validation so teams can detect drift, misuse, or excessive privilege in motion rather than assuming build-time policy still holds.
  • Intent-Aware Detection: A detection method that evaluates whether an agent’s sequence of actions still matches its intended task, not just whether individual events look suspicious. For autonomous behaviour, this is more useful than event-only alerting because risk often appears in the chain, not the single action.
  • Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
  • Agent Lifecycle Management: The process of provisioning, governing, updating, and retiring an AI agent or other non-human identity. It includes credential issuance, permission changes, logging, rotation, and offboarding. Without lifecycle control, agents can retain access after their business purpose ends, creating persistent risk.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 6, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org