Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AI agent governance: are your identity controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15509
Topic starter  

TL;DR: Boards and auditors are forcing enterprises to answer four governance questions about AI agent access, accountability, privilege, and auditability, according to Oleria Security. The issue is not the protocol path an agent uses, but the identity model behind it, because legacy IAM assumes human-paced, reviewable access.

NHIMG editorial — based on content published by Oleria Security: four questions every CISO will be asked about AI agents

Questions worth separating out

Q: How should security teams govern AI agents that can access enterprise systems?

A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring.

Q: Why do AI agents create new risk in non-human identity management?

A: AI agents create risk because they operate as software identities with delegated authority, but many organisations do not track them with the same discipline applied to users or service accounts.

Q: What breaks when AI agent access is reviewed only after the fact?

A: After-the-fact review leaves a gap between action and containment.

Practitioner guidance

  • Inventory every production AI agent as an identity subject Record who approved it, what systems it can reach, what human it represents, and when that approval expires.
  • Enforce task-scoped privilege for agent actions Replace standing broad scopes with short-lived, purpose-bound access for the exact operation the agent is performing.
  • Make on-behalf-of attribution mandatory in logs Require every material agent action to carry a human accountability reference that can survive audit, legal review, and incident response.

What's in the full article

Oleria Security's full article covers the operational detail this post intentionally leaves for the source:

  • The full breakdown of the four governance questions CISOs will be asked about AI agents in 2026.
  • The incident examples behind agent-authorisation failures, including the Vercel case and related AI-adjacent exposures.
  • The practical framing for accountability, on-behalf-of semantics, and auditability across common agent entry points.
  • The source article's discussion of how boards, auditors, regulators, and customers are already changing expectations.

👉 Read Oleria Security's analysis of the four AI agent governance questions CISOs will face →

AI agent governance: are your identity controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15094
 

Identity governance for AI agents fails when organisations keep treating them as software. Software can be inventoried by vendor and contract, but an agent needs an authority model, an accountability chain, and an evidence trail. Once an agent can act on behalf of a human across multiple systems, the governance unit is no longer the tool. The governance unit is the actor. Practitioners should reframe agent onboarding as identity lifecycle management, not application procurement.

A few things that frame the scale:

  • 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
  • Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities.

A question worth separating out:

Q: Who is accountable when an AI agent makes a risky decision?

A: Accountability should rest with the organisation that authorised the agent, the human owner of the workflow, and the control process that allowed the behaviour. If an agent can act independently, the programme must preserve attribution, action logs, and policy decisions so audit and remediation are possible after the event.

👉 Read our full editorial: Four questions every CISO will face on AI agent governance



   
ReplyQuote
Share: