TL;DR: AI agents now do real work inside enterprises, but governance, liability, and runtime controls are still unsettled, according to FireCompass. Senior security leaders in a FireCompass roundtable said the core problem is assumption collapse: controls built for human-paced review, stable intent, and predictable outputs do not hold when agents act at machine speed and can repeat mistakes thousands of times.
NHIMG editorial — based on content published by FireCompass: AI Agents Are Doing Real Work. Governing Them Is the Unsolved Problem
By the numbers:
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, sharing sensitive data, or revealing credentials.
- Only 44% of companies have implemented policies to govern AI agents, even though 92% say that governing them is critical to enterprise security.
Questions worth separating out
Q: What breaks when AI agents are treated like standard human users?
A: You lose visibility into effective permissions, expected behaviour, and real blast radius.
Q: Why do AI agents create a liability problem for organisations?
A: Courts are already leaning toward the deploying organisation being responsible for what its agents say or do.
Q: What are the signs that AI governance is failing in the enterprise?
A: Common warning signs include rapid growth in AI use without matching policy coverage, sensitive files being copied into personal accounts, and a large share of AI apps carrying high or critical risk.
Practitioner guidance
- Inventory every agent and owner Create a live register of approved agents, business owners, data access, and permitted use cases.
- Assign per-agent identity and least privilege Issue unique identities for each agent and scope access to the smallest set of tools, data, and actions needed for the task.
- Remove destructive tools from the agent path Do not rely on prompt instructions alone to keep an agent safe.
What's in the full article
FireCompass's full blog post covers the operational detail this analysis intentionally leaves for the source:
- The roundtable framing and participant context behind the governance positions, including the role of Bruce Schneier.
- The practical control set leaders discussed for runtime enforcement, approval gating, and tool segregation.
- FireCompass's own agentic pentesting example, including how its harness uses deterministic controls and critic agents.
- The article's discussion of why reliability can erode human oversight as agents improve.
👉 Read FireCompass's discussion of AI agent governance and runtime control →
AI agent governance: what security teams still need to solve?
Explore further
AI agent governance is now an identity discipline, not an AI feature discussion. The roundtable makes clear that agents must be handled as privileged identities with ownership, scope, and audit boundaries. That places the problem squarely inside IAM, PAM, and NHI governance rather than leaving it in a general AI policy lane. Security teams that separate agent governance from identity governance are already misclassifying the risk.
A few things that frame the scale:
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, sharing sensitive data, or revealing credentials, according to AI Agents: The New Attack Surface report.
- 52% of companies can track and audit the data their AI agents access, which means 48% still face a complete compliance and breach-investigation blind spot.
A question worth separating out:
Q: How should security teams govern AI agents that inherit authority from other identities?
A: Security teams should govern AI agents by tracking identity lineage, not just credentials. That means recording the originating identity, the delegated authority path, and the runtime context for each action. If an agent can inherit permissions from humans, services, or other agents, policy has to evaluate the full chain before access is granted or continued.
👉 Read our full editorial: AI agent governance is an unsolved identity problem