TL;DR: Enterprise security teams are discovering far more AI agents and tools than they approved, while nearly half of public MCP server builds show at least one security finding, according to Island. The real governance gap is not model quality but end-to-end visibility across identity, tools, logs, and runtime actions, because the second workforce already operates outside human onboarding assumptions.
NHIMG editorial — based on content published by Island: Agents Work Everywhere Now. Governance Has to See Everywhere Too
By the numbers:
- About 1 in 8 exposed a tool that could execute code, delete data, or take an irreversible action on the first call.
- 84 percent of identifiable maintainers listed a single publisher, and most had no organization verification at all.
Questions worth separating out
Q: What breaks when AI agents are connected through personal accounts or shared credentials?
A: Shared or personal credentials break accountability, lifecycle control, and revocation.
Q: Why do enterprise AI agents complicate NHI governance?
A: They complicate NHI governance because the security model was built around predictable non-human identities such as API keys and workload credentials.
Q: How can security teams tell whether agent access is actually under control?
A: Look for evidence that the team can trace every tool call, secret use, and cross-system action back to a named owner and a valid approval path.
Practitioner guidance
- Map every agent capability to a governed inventory Track agents, MCP servers, IDE extensions, hooks, and skills as part of the identity estate.
- Issue separate identities for agents and humans Stop relying on borrowed human credentials for agent activity.
- Block standing credentials for agent workflows Move agent access behind a gateway that brokers just-in-time access and keeps raw API keys out of the agent session.
What's in the full article
Island's full blog post covers the operational detail this analysis intentionally leaves for the source:
- How Island maps agent activity across browser, endpoint, network, and gateway control points
- Examples of inline enforcement for prompts, tool calls, and returned payloads in agent workflows
- The operational model for just-in-time access when an agent needs to reach multiple tools
- Why the vendor frames agent onboarding as a workforce governance problem rather than a point solution
👉 Read Island's analysis of governing the enterprise AI workforce →
Agentic workforce governance: what changes when agents bring their own tools?
Explore further
Agentic governance fails when organisations assume work can be governed one login at a time: the article shows a second workforce operating with its own tools, timing, and execution paths. That assumption was built for human-paced workflows and static entitlement models. When agents can bring, chain, and invoke tools in-session, the implication is that governance has to move from account review to action-chain oversight.
A few things that frame the scale:
- 1 in 4 organisations are already investing in dedicated NHI security capabilities, with an additional 60% planning to do so within the next twelve months, according to The State of Non-Human Identity Security.
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, which shows how quickly delegated access becomes governance debt.
A question worth separating out:
Q: Who is accountable when an AI agent makes an unauthorised change?
A: Accountability should be assigned to the governance model that authorised the delegation, the owner of the workflow, and the team that set the policy boundary. In practice, organisations need clear responsibility for agent configuration, monitoring, and incident response because the machine’s speed does not remove human accountability for the delegated identity.
👉 Read our full editorial: Agentic workforce governance needs visibility across every control point