TL;DR: AI apps and services are unmanaged in roughly 65% of enterprise environments, and even known agents can remain unmanaged in 15% of cases, creating a policy-reality gap that static IAM reviews do not catch, according to AuthMind. The real problem is not just permissive policy but the lack of continuous observability into what AI agents actually access and do.
Editorial analysis by NHI Mgmt Group, based on content published by AuthMind: “Static Policies in a Dynamic World: The False Sense of Security in AI Governance”.
By the numbers:
- Approximately 65% of AI apps and services in enterprise environments, including agentic AI, are unmanaged.
- 15% of those that are known are still unmanaged, likely because of misconfiguration or operational oversight.
Key questions
Q: What breaks when AI agent access is not re-evaluated in real time?
A: The main failure is privilege drift.
Q: Why do unmanaged AI agents create a larger risk than managed ones?
A: Unmanaged AI agents are harder to audit, revoke, and contain because no one can reliably answer who owns them, what they can reach, or whether they still need access.
Q: What do teams get wrong about AI agent access reviews?
A: Teams often assume an access review can certify an agent the same way they certify a human or a service account.
Practitioner guidance
- Inventory AI agents as identity objects Catalogue every agentic AI app, service, integration, and personal-account tool that can reach enterprise resources, including systems outside IdP, PAM, or secrets management.
- Compare declared policy to observed access Establish a continuous control that contrasts approved entitlements with actual systems called, secrets accessed, and data touched by each agent.
- Treat unmanaged agents as governance exceptions Create an explicit remediation path for agents that are known but not governed, and for shadow agents that have no reliable inventory record.
Bottom line: AI agent access governance fails when policy describes intent but production behaviour keeps changing underneath it.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Policy-reality gap is now the core failure mode in AI agent governance. Static IAM tells teams what an agent was allowed to do at provisioning time, but agentic environments change too quickly for that snapshot to remain trustworthy. When access is not continuously validated against runtime behaviour, policy becomes documentation rather than control. Practitioners should treat this as an observability problem, not a permissions paperwork problem.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
- A separate finding in the same research shows that 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface.
A question worth separating out:
Q: How can organisations tell whether AI agent governance is actually working?
A: Organisations can tell governance is working when observed agent behaviour consistently matches approved policy boundaries across secrets, systems, and roles. Useful signals include fewer unexplained permissions, fewer unmanaged agents, and rapid detection of drift. If reviews only confirm what was provisioned, not what was used, governance is not working.
👉 Read our full editorial: AI agent access governance is failing at the policy-reality gap
Policy-reality gap is the right name for the AI agent governance problem. Static access policy describes intent, but agentic systems operate in production where identity, context, and access use change continuously. When IAM is validated only at provisioning time, the control can be correct on paper and wrong in operation. The practical conclusion is that agent governance must be measured against observed behaviour, not policy artefacts alone.
A few things that frame the scale:
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security, according to the 2026 Infrastructure Identity Survey.
- 54% of organisations are actively deploying AI agents across workflows, yet only 21% report a mature governance model for agentic AI.
A question worth separating out:
Q: How should organisations govern AI agents that are not connected to IdP or PAM?
A: They should treat them as unmanaged identities first, then bring them into an inventory, ownership, and monitoring process before expecting policy compliance. If an agent is outside identity controls, it cannot be certified with the same confidence as a governed workload or user account.
👉 Read our full editorial: AI agent access governance is failing at the policy-reality gap