Join our Newsletter — 33% off our NHI Course

AI agent governance gap: are your controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: AI agents are software tools that plan actions, retrieve data, call APIs, and execute workflows across enterprise systems, which makes their identity, permission, and monitoring model materially different from deterministic automation, according to Lasso Security. The core issue is that conventional IAM assumes stable, reviewable access, while agents can chain actions across tools and drift beyond intended scope within a single task.

Editorial analysis by NHI Mgmt Group, based on content published by Lasso Security: “How to Secure AI Agents in the Enterprise: Visibility, Governance & Risk Control”.

By the numbers:

  • Only 54% of enterprises fully understand what data their AI agents can access.
  • Just 44% have formal governance policies in place.

Key questions

Q: What breaks when AI agents are given broad enterprise access without tight governance?

A: Broad access turns AI agents into high-speed execution paths that can move data, spend money, modify records, or delete assets before operators can intervene.

Q: Why do AI agents create more risk than traditional automation?

A: AI agents create more risk because they can interpret context, choose actions, and invoke tools autonomously.

Q: How do security teams know if agent governance is actually working?

A: It is working only if the team can answer three questions quickly for any agent: what it can reach, what it did recently, and whether that behaviour matches intent.

Practitioner guidance

  • Inventory every agent and connected tool Map all AI agents, the SaaS applications they touch, the APIs they call, and the data repositories they can reach.
  • Tighten delegated access scopes Reduce OAuth scopes, API permissions, and inherited entitlements to the smallest task-specific set that still allows the agent to work.
  • Log prompts, tool calls, and outputs Capture the prompt, retrieved context, selected tools, and resulting actions in a single audit trail.

Bottom line: AI agents collapse the gap between identity and execution because they can choose tools, pull context, and act across systems within one session.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 5 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21396
 

Dynamic tool use has created an identity governance problem that conventional IAM does not fully model. The article shows that agents do not simply consume access, they select tools, retrieve data, and execute workflows in context. That means the control plane has to account for runtime behaviour, not just assigned entitlements. The practitioner conclusion is that access governance for agents is now a first-class identity domain, not an extension of application security.

A few things that frame the scale:

  • 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%), according to AI Agents: The New Attack Surface report.
  • Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.

A question worth separating out:

Q: How should organisations respond when an AI agent inherits access across multiple systems?

A: They should re-evaluate whether the inheritance model is actually necessary and then break the access into smaller, task-scoped permissions. If the agent can reach documents, tickets, chat, and databases from one identity, the blast radius is too large for effective governance. Cross-system reach should be treated as a privileged design choice, not a default.

👉 Read our full editorial: AI agent identity risk is outpacing enterprise IAM controls



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21396
 

AI agent identity risk is not a bigger IAM problem, it is a different one. IAM has long assumed that the subject of access is stable enough to authenticate, authorize, and review after the fact. That assumption weakens when the subject can plan actions, call tools, and move across systems inside one runtime session. The implication is that governance has to shift from static account state to execution-time authority.

A few things that frame the scale:

  • 19% of organisations give AI systems dramatically more access than human employees, nearly one in five granting unrestricted privilege, according to the 2026 Infrastructure Identity Survey.

A question worth separating out:

Q: What should organisations do when an autonomous agent is compromised or misdirected?

A: Contain the agent by revoking its access path, isolating the affected credentials, and reviewing downstream actions before restoring any related automation. The immediate objective is to stop trusted access from being reused as a hidden execution channel. Then reassess ownership, scope, and monitoring before the agent returns to production.

👉 Read our full editorial: AI agent identity risk is outpacing enterprise IAM controls


This post was modified 5 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.