TL;DR: Agentic AI companies build systems that can plan, use tools, call APIs, and execute workflows, which means the real governance problem is no longer model quality but access, permissions, and auditability, according to BigID. When agents inherit privileges through applications, service accounts, and user roles, existing IAM controls start to look incomplete rather than merely strained.
NHIMG editorial — based on content published by BigID: Agentic AI Companies: Key Takeaways and governance guidance
By the numbers:
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, inappropriately sharing sensitive data, and revealing access credentials.
Questions worth separating out
Q: How should security teams govern AI agents that can access enterprise systems?
A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring.
Q: Why do endpoint agentic AI tools create more governance risk than chat-only GenAI?
A: Endpoint agentic AI can act inside a user’s session, move data, and trigger downstream actions, which expands the effective privilege boundary.
Q: What breaks when agent access is not tied to ownership and lifecycle?
A: When ownership is unclear, access reviews cannot confirm who approved the credential, who is accountable for its use, or when it should be removed.
Practitioner guidance
- Map every agent to its inherited identities Trace which service accounts, API keys, application tokens, and user roles each agent can use in production.
- Classify agent-accessed data before expanding scope Link every planned agent workflow to the data classes it can touch, including regulated records, customer data, and intellectual property.
- Add audit evidence to the agent lifecycle Require inventories, action logs, permission records, and ownership records before an agent can move from pilot to production.
What's in the full article
BigID's full article covers the operational detail this post intentionally leaves for the source:
- Vendor-by-vendor category breakdowns of agentic AI companies and the enterprise use cases they target.
- Detailed evaluation questions for security, governance, and data access that implementation teams can reuse.
- A fuller explanation of how BigID positions discovery, inventory, and risk prioritisation across AI agents.
- Operational context around governance controls, audit readiness, and ownership mapping for production use.
👉 Read BigID's analysis of agentic AI companies and governance risk →
Agentic AI companies: what identity teams should evaluate?
Explore further