TL;DR: AI agents are already operating across enterprise systems with limited oversight, and Saviynt argues that 92% of organisations have limited or no visibility into their AI identities while 53% report agents exceeding intended permissions. The security model shifts from periodic review to continuous runtime authorisation because autonomous behaviour can outpace human-paced governance.
NHIMG editorial — based on content published by Saviynt: The AI Bell Has Been Rung. A CISO’s Next Steps
By the numbers:
- In fact, 92% of organizations report limited or no visibility into their AI identities.
- AI and other non-human identities now outnumber human identities by as much as 144 to 1.
- 53% of organizations report that AI agents exceed their intended permissions.
Questions worth separating out
Q: How should security teams govern AI agents that can access enterprise systems?
A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring.
Q: Why do AI agents create more risk than traditional automation?
A: AI agents create more risk because they can interpret context, choose actions, and invoke tools autonomously.
Q: What are the signs that AI governance is failing in the enterprise?
A: Common warning signs include rapid growth in AI use without matching policy coverage, sensitive files being copied into personal accounts, and a large share of AI apps carrying high or critical risk.
Practitioner guidance
- Inventory every AI identity and owner Create a live register of agents, copilots, and embedded AI tools that records system access, data reach, business owner, and technical owner.
- Move AI access decisions to runtime Use intent-aware runtime authorization and fine-grained resource controls so an agent is checked while it acts, not only when it is provisioned.
- Treat AI agents as first-class identities Bring agents into the same governance processes used for non-human identities, including lifecycle ownership, termination, and periodic review triggers.
What's in the full article
Saviynt's full blog post covers the operational detail this post intentionally leaves for the source:
- How its AI identity security workflow separates discovery, ownership, and runtime control into distinct steps
- How intent-aware runtime authorization is applied to agent actions in practice
- How the vendor describes continuous governance across creation, change, and termination of AI identities
- How its control plane is positioned for AI and NHI visibility across connected environments
👉 Read Saviynt's analysis of AI agent identity governance and runtime controls →
AI agent identity governance: are periodic reviews enough anymore?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
AI identity governance is now a first-class identity discipline, not an add-on to application security. The article is right to frame discovery, ownership, and runtime control as identity problems because AI agents already act like non-human identities with expanding reach. That means IAM, IGA, PAM, and NHI teams all need to share the same governance model instead of treating AI as a separate silo. The practitioner implication is simple: AI identities must enter the same governance inventory as service accounts, tokens, and privileged access.
A few things that frame the scale:
- 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures, according to Ultimate Guide to NHIs.
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.
A question worth separating out:
Q: How do AI agent access reviews differ from human access reviews?
A: AI agent access reviews should focus on runtime behaviour, ownership, and the scope of delegated tool use, not employee lifecycle events. Human reviews assume stable job roles and enduring entitlements. Agent reviews must instead ask whether the agent still exists, whether its tasks changed, and whether the access path is still justified for that specific execution pattern.
👉 Read our full editorial: AI agent identity governance needs runtime controls, not periodic reviews