Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Agentic AI governance: what changes when agents act autonomously?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: AI agents are running autonomously across endpoints, files, tools, and data stores, and legacy DLP and EDR cannot govern machine-speed behaviour without human oversight or a reliable audit trail, according to Cyberhaven’s whitepaper. The governance problem is no longer theoretical: access review and containment models built for human-paced identity break when agents decide and act inside the same session.

NHIMG editorial — based on content published by Cyberhaven: Governing the Autonomous Enterprise: A Security Framework for Agentic AI

By the numbers:

  • 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%).

Questions worth separating out

Q: How should organisations govern AI agents that act as business units of work?

A: Organisations should govern AI agents as first-class non-human identities.

Q: What breaks when existing DLP and EDR tools are used to monitor AI agents?

A: Those tools break at the point where agent behaviour becomes sequential and contextual rather than single-event based.

Q: Why do AI agents complicate existing IAM and NHI governance models?

A: AI agents complicate governance because access is no longer confined to a single environment or a single identity type.

Practitioner guidance

  • Model AI agents as governed identities Assign each agent an owner, a purpose, and a scoped policy boundary so the agent is managed like a runtime identity rather than an untracked automation path.
  • Tie alerts to data lineage Require every high-risk agent event to carry source, destination, and transformation context so investigators can reconstruct the action path without manual correlation.
  • Align DLP and EDR with agent runtime behaviour Test whether your current monitoring can explain machine-speed actions across files, tools, and data stores, then identify where policy enforcement stops at the endpoint.

What's in the full article

Cyberhaven's full whitepaper covers the operational detail this post intentionally leaves for the source:

  • The three-pillar framework for governing agentic AI across visibility, observability, and control
  • The specific ways legacy DLP and EDR fail when agents act across endpoints and data stores at machine speed
  • The data lineage model used to turn isolated alerts into an investigation path
  • The operational guardrails security teams can use to govern autonomous agents without blocking productivity

👉 Read Cyberhaven's whitepaper on governing autonomous AI agents →

Agentic AI governance: what changes when agents act autonomously?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Agentic AI turns identity governance into runtime control, not just access management. The article’s core point is that autonomous agents do not wait for a review cycle or remain within a static permission set. That means the enterprise is no longer governing a user session or a workload credential in isolation. It is governing a decision-making actor whose access pattern changes as the task unfolds, so the practitioner problem becomes runtime scope control across identity, data, and tools.

A few things that frame the scale:

  • 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%), according to AI Agents: The New Attack Surface report.
  • 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.

A question worth separating out:

Q: How can organisations reduce risk from AI clients without blocking adoption?

A: Organisations should reduce risk by removing shared secrets, narrowing tool scopes, and making delegation reviewable. That lets AI clients operate with less standing privilege while still preserving business value. The goal is not to stop agent use, but to make every access path attributable and revocable.

👉 Read our full editorial: Governing agentic AI identities requires new enterprise controls



   
ReplyQuote
Share: