Join our Newsletter — 33% off our NHI Course

Agentic AI governance gaps: are your controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Agentic AI governance shifts the risk from what a system says to what it can do, because agents can query databases, trigger workflows, call APIs, and update records in one sequence, according to Lasso Security. Static AI policies were built for outputs, not machine-speed actions, and that assumption now fails.

Editorial analysis by NHI Mgmt Group, based on content published by Lasso Security: “AI Governance Challenges in the Age of Agentic AI”.

Key questions

Q: What breaks when AI governance only monitors prompts and outputs?

A: Prompt and output monitoring misses the moment where the real risk occurs, which is execution.

Q: Why do autonomous agents force teams to rethink AI governance and accountability?

A: Because the action sequence now happens at machine speed, human review no longer sits inside the decision window.

Q: How do security teams know if AI governance is working?

A: Look for evidence that access decisions are reviewable, permissions are revocable, and exceptions are not becoming permanent.

Practitioner guidance

  • Build a live agent inventory Track every agent across repositories, cloud platforms, low-code tools, models, APIs, and system prompts so changes are visible when code does not change.
  • Move policy enforcement to runtime Bind guardrails to the tools, data sources, and decision points the agent actually uses, instead of relying on prompt and output review.
  • Test for fragile intent continuously Run single-turn and multi-turn adversarial testing to see where an agent can be pushed from safe behaviour into unsafe action paths.

Bottom line: Agentic AI changes the governance problem from what a system says to what it can do across connected systems.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21364
 

Agentic AI creates an identity governance problem, not just an AI policy problem. Once an agent can act across systems, the question is no longer whether its output is acceptable. The question is whether its runtime authority is bounded well enough for IAM, PAM, and governance controls to make sense. That moves the issue into identity security, where inventory, entitlement scope, and escalation boundaries are the real control plane. Practitioners should treat agent access as governed identity, not as a content moderation problem.

A few things that frame the scale:

  • 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%), according to AI Agents: The New Attack Surface report.
  • 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.

A question worth separating out:

Q: Who is accountable when an autonomous agent causes business harm?

A: Accountability sits with the organisation that granted the agent its access, defined its guardrails, and failed to monitor its runtime behaviour. In practice, responsibility spans the AI owner, the identity team, and the control owners for every connected system the agent can touch. Governance must make that chain explicit before incidents occur.

👉 Read our full editorial: AI governance for agentic systems breaks at runtime, not policy



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21364
 

Agentic AI creates an identity governance problem, not just an AI policy problem. Once an agent can act across systems, the question is no longer whether its output is acceptable. The question is whether its runtime authority is bounded well enough for IAM, PAM, and governance controls to make sense. That moves the issue into identity security, where inventory, entitlement scope, and escalation boundaries are the real control plane. Practitioners should treat agent access as governed identity, not as a content moderation problem.

A few things that frame the scale:

  • 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%), according to AI Agents: The New Attack Surface report.
  • 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.

A question worth separating out:

Q: Who is accountable when an autonomous agent causes business harm?

A: Accountability sits with the organisation that granted the agent its access, defined its guardrails, and failed to monitor its runtime behaviour. In practice, responsibility spans the AI owner, the identity team, and the control owners for every connected system the agent can touch. Governance must make that chain explicit before incidents occur.

👉 Read our full editorial: AI governance for agentic systems breaks at runtime, not policy



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21364
 

Runtime governance is the real control boundary for agentic AI: policies written for conversational systems do not control systems that can execute actions across multiple tools in one session. The problem is not policy intent but timing, because agent decisions now happen inside the same runtime window as the action itself. Practitioners should treat execution-time control as the primary governance boundary.

A few things that frame the scale:

  • Only 13% of organisations feel extremely prepared for the reality of agentic AI despite the majority racing toward autonomous adoption, according to the 2026 Infrastructure Identity Survey.
  • 52% of respondents see AI security decision-making power shifting toward platform and infrastructure teams rather than the executive suite, according to the 2026 Infrastructure Identity Survey.

A question worth separating out:

Q: What happens when an AI agent is allowed to delegate across other agents and tools?

A: The blast radius grows quickly because one compromised instruction chain can propagate through downstream agents and systems before monitoring notices. Traditional human-centric oversight has no reliable frame of reference for this kind of non-human delegation, so the chain needs explicit runtime supervision.

👉 Read our full editorial: AI governance for agentic systems breaks at runtime, not policy


This post was modified 3 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.