TL;DR: AI agents now operate inside enterprise systems faster than governance can adapt, with 53% of AI interactions already autonomous actions and 93% of prompts approved by human reviewers, according to Island and McKinsey. The real issue is not model quality but identity, policy, and audit gaps around non-human actions.
NHIMG editorial — based on content published by Island: The control plane for the agentic enterprise
By the numbers:
- A McKinsey survey found that 93% of respondents have reported exceeding their AI budgets.
Questions worth separating out
Q: How should security teams govern AI agents that can choose tools at runtime?
A: Security teams should govern runtime agent choice as an access event, not as a simple application action.
Q: Why do AI agents create more risk than traditional automation?
A: AI agents create more risk because they can interpret context, choose actions, and invoke tools autonomously.
Q: What breaks when an agent has broad write access across business systems?
A: Broad write access turns a helpful agent into a platform-wide escalation path.
Practitioner guidance
- Map every agent to a named non-human identity Inventory which browser sessions, endpoints, MCP servers, and internal APIs each agent can reach, then bind those paths to a specific identity record and owner.
- Replace prompt review with runtime policy enforcement Block or allow tool calls, file access, and sub-agent handoffs in-session rather than relying on human approval of the original prompt.
- Issue just-in-time credentials for every agent task Remove standing keys from agent workflows and scope each credential to a single task or bounded session.
What's in the full article
Island's full blog covers the operational detail this post intentionally leaves for the source:
- How the control plane maps across browser, endpoint, network, and identity surfaces in live enterprise workflows
- How the vendor groups agentic endpoint posture, agentic identity, AI protect, and cost controls into one policy engine
- How the audit trail is positioned for SOC 2, ISO 27001, and EU AI Act conformance
- How the product treats MCP servers, skills, packages, and extensions as governed agent inputs
👉 Read Island's analysis of the control plane for the agentic enterprise →
Agentic enterprise control planes: what do IAM teams need now?
Explore further
Agentic enterprise governance is now an identity control problem, not an AI policy add-on. The article shows agents running inside the same work surfaces as employees, which means identity, privilege, and audit must follow runtime behaviour instead of user intent. Once an actor can call tools and continue executing without a human approval gate, traditional access review logic no longer describes the risk. The practitioner conclusion is that agent governance belongs inside IAM and PAM architecture, not beside it.
A few things that frame the scale:
- 33% of organisations report their AI agents have accessed inappropriate or sensitive data beyond their intended scope, according to AI Agents: The New Attack Surface report.
- 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.
A question worth separating out:
Q: Who is accountable when an AI agent acts outside its intended scope?
A: The organisation is accountable, but operational responsibility should sit with a named owner and a governance process that can explain the agent’s purpose, access, and recorded actions. Without that, autonomous behaviour becomes unassignable risk rather than managed automation.
👉 Read our full editorial: Agentic enterprise control planes are becoming an identity problem