TL;DR: AI agent access risk grows when autonomous software can interpret instructions, choose actions, and operate across systems faster than human review can keep up, according to Living Security Human Risk Management Platform. The governance gap is that access reviews assume stable, reviewable privilege, but agents can change scope, chain actions, and create impact within a single runtime session.
NHIMG editorial — based on content published by Living Security Human Risk Management Platform: AI Agent Access Risk: What Security Teams Need to Measure
By the numbers:
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%).
Questions worth separating out
Q: How should security teams govern AI agents that can access enterprise systems?
A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring.
Q: Why do AI agents create more authorization risk than static service accounts?
A: AI agents can vary their access needs by task, context, and timing inside the same workflow, which makes static entitlement assumptions weaker.
Q: What breaks when AI agents are given broad inherited permissions?
A: Broad inherited permissions break the assumption that access is tied to a narrow business need.
Practitioner guidance
- Inventory every agent identity and owner Catalog production, development, SaaS, and workflow agents with their purpose, connected systems, data access, model provider, and authentication method.
- Separate agent identities from shared application tokens Give each agent a distinct attributable identity and remove broad shared credentials where possible.
- Baseline behaviour by task and destination Define normal request volume, tools, timing, and destination systems for each agent, then alert on new connections, unusual escalation patterns, and data movement outside the approved path.
What's in the full article
Living Security Human Risk Management Platform's full blog post covers the operational detail this post intentionally leaves for the source:
- A deeper measurement model for correlating identity, behaviour, and threat signals across AI agents and human owners.
- Operational examples of how to inventory agents across SaaS tools, cloud environments, and employee workflows.
- More detail on the behavioural baselines and escalation signals that distinguish normal automation from risky agent drift.
AI agent access risk: what should security teams measure now?
Explore further
AI agent access risk is an identity governance problem before it is an AI problem. The article is right to treat identity, privilege, behaviour, and threat as a single measurement set. That is the only way to understand whether an agent is acting inside its intended boundary or merely appearing compliant. The practitioner conclusion is that IAM and NHI teams, not just AI owners, must own the control plane.
A few things that frame the scale:
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%), according to AI Agents: The New Attack Surface report.
- Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation, according to AI Agents: The New Attack Surface report.
A question worth separating out:
Q: Who is accountable when an AI agent makes an unauthorised change?
A: Accountability should be assigned to the governance model that authorised the delegation, the owner of the workflow, and the team that set the policy boundary. In practice, organisations need clear responsibility for agent configuration, monitoring, and incident response because the machine’s speed does not remove human accountability for the delegated identity.
👉 Read our full editorial: AI agent access risk demands identity, behavior and threat control