TL;DR: As agentic systems begin to initiate actions, retrieve data, and make decisions across connected environments, SACR’s research says data security, identity context, and runtime control are converging into one operating model, with Cyera named as a leading platform in that category. The core shift is that governance assumptions built for static prompts and passive data flows no longer hold when AI can act on data in motion.
Editorial analysis by NHI Mgmt Group, based on content published by Cyera: “Cyera Named a Leading Platform in the Emergence of Agentic Data & AI Security”.
Key questions
Q: How should security teams govern agentic AI that can execute IAM tasks?
A: Start by treating the agent as an NHI with bounded authority, explicit ownership, and revocation procedures.
Q: Why do DSPM and DLP still matter for agentic AI security?
A: DSPM and DLP remain foundational because agentic systems still depend on data visibility and policy enforcement.
Q: What are the signs that a data security programme is not ready for agentic AI?
A: Common warning signs are low visibility into where data lives, weak lineage tracking, and limited control over how data is used by agents.
Practitioner guidance
- Map agent data paths end to end Inventory where copilots, embedded assistants and task-driven agents can read, transform and forward sensitive data across systems.
- Bind data classification to agent permissions Use data sensitivity, ownership and exposure context to determine which datasets an agent may touch during a live task.
- Add runtime policy to AI workflows Enforce contextual blocking, redaction or warning controls while prompts, retrievals and outputs are still in flight.
Bottom line: Agentic AI changes the governance problem because systems can now initiate actions and move sensitive data, not merely produce responses.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Agentic AI security collapses the old separation between identity and data governance. The article’s central point is that autonomous systems now act on information, not just display it, so data security tools and identity controls cannot remain parallel programmes. Once agents can initiate actions and chain tasks, the real control question becomes who or what is authorised to move sensitive data through a live execution path. Practitioners should treat that as one governance plane, not two.
A few things that frame the scale:
- Only 23% of IT leaders were very confident in their organisation's ability to manage security and governance for GenAI deployments, according to a 2025 Gartner survey of 360 IT leaders.
A question worth separating out:
Q: How do identity controls change when AI systems start chaining tasks?
A: Identity controls have to shift from provisioning-time entitlement checks to live task-aware enforcement. When AI systems chain actions, the relevant question is whether the current action matches the agent’s authorized purpose and data context. That requires continuous evaluation of identity context, not just a one-time approval.
👉 Read our full editorial: Agentic AI security is converging with data and identity control