TL;DR: Enterprise AI security is shifting from adoption and access to authority, with Gartner projecting that roughly 40% of enterprise applications will embed task-specific AI agents by the end of 2026, according to Lasso Security’s 2026 predictions. The control gap is no longer just permissions, but purpose, boundaries, and runtime oversight across agentic workflows.
Editorial analysis by NHI Mgmt Group, based on content published by Lasso Security: “Enterprise AI Security Predictions 2026: Intent & Control”.
Key questions
Q: What breaks when AI agents can behave deceptively inside approved workflows?
A: What breaks is the assumption that access approval and behavioural alignment remain stable for the duration of the task.
Q: Why do AI agents create risk even when they stay within approved permissions?
A: AI agents can be authorised correctly and still produce harmful outcomes because permission is not the same as intent or behavioural appropriateness.
Q: What are the signs that agentic AI is drifting away from the rules it was designed to follow?
A: The clearest signs are stale outputs, inconsistent decisions, and behavior that no longer matches the workflow the agent was built to execute.
Practitioner guidance
- Define AI purpose boundaries Document what each AI system is allowed to accomplish, where its mandate ends, and which workflows fall outside approved scope.
- Map delegated authority paths Inventory where agents can trigger APIs, workflows, and decisions on behalf of users, then trace which identities and approvals make those actions possible.
- Review session trust for agentic browsers Reassess single sign-on, session binding, and step-up controls when a browser session can contain both human and agent execution.
Bottom line: Enterprise AI security is shifting from static access control to runtime authority, purpose limitation, and behavioural oversight.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Agentic behaviour exposes an intent gap, not just an access gap. Traditional IAM and NHI controls are built to decide who can access what. This article shows that AI agents create a second question: what is the system trying to accomplish, and how far may it go while doing it? That is a governance problem because a system can remain within access rules while still violating business intent. Practitioners should treat intent boundaries as a first-class control plane.
A few things that frame the scale:
- Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities, according to The State of Non-Human Identity Security.
- That confidence gap shows why AI governance cannot rely on human-era control assumptions when delegated machine behaviour is expanding across enterprise workflows.
A question worth separating out:
Q: Who is accountable when AI-mediated actions create compliance or operational risk?
A: Accountability remains with the deploying organisation, even when an AI model or agent is externally provided. Teams need logs, approvals, and governance records that show what acted, under what authority, and within which mandate. Without that evidence, compliance obligations become difficult to defend.
👉 Read our full editorial: Enterprise AI security in 2026 is becoming an intent problem
Intent is becoming the control plane for enterprise AI. Once AI systems begin acting on behalf of users or objectives, the security problem is no longer limited to access rights. The deeper issue is whether the system’s actual behaviour still matches the mandate that justified its access in the first place. For IAM and governance teams, purpose limitation is moving from a policy principle into an operational control requirement.
A few things that frame the scale:
- Enterprise AI use rose from 55% of organisations in 2023 to 88% in 2025, according to McKinsey’s Global Surveys on the State of AI.
A question worth separating out:
Q: How should organisations govern autonomous AI agent actions separately from human sessions?
A: Treat the agent as a governed execution identity with its own permissions, logs, and guardrails. Human authentication does not prove the agent should be able to call tools or modify systems. Governance has to distinguish who started the workflow from what the agent is authorised to do at runtime.
👉 Read our full editorial: Enterprise AI security in 2026 is becoming an intent problem