Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AI agent insider risk: what it means for IAM and governance


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 12324
Topic starter  

TL;DR: AI agents now behave like trusted insiders with real credentials, machine-speed execution, and volatile tool use, while the old human-insider assumptions no longer hold, according to Pillar Security and its SAIL 2.0 framework. The governing premise that identity, pace, consequence, and behavior stay human-shaped collapses once the actor is an autonomous system with no stable review window.

NHIMG editorial — based on content published by Pillar Security: Introducing SAIL 2.0 Framework, a practical guide to secure AI agents

By the numbers:

Questions worth separating out

Q: How should security teams govern AI agents that can access enterprise systems?

A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring.

Q: Why do insider risk programmes struggle with AI-driven activity?

A: They were designed for stable users and discrete events, not for delegated, fast-moving activity that can blend into normal work.

Q: What do security teams get wrong about prompt guardrails?

A: Teams often treat prompt guardrails as if they were authorisation controls, but they are only one layer of defence.

Practitioner guidance

What's in the full article

Pillar Security's full blog post covers the operational detail this post intentionally leaves for the source:

  • How SAIL 2.0 maps agent security across seven lifecycle phases from discovery to decommissioning
  • The GuardFall research details behind the claim that 10 of 11 coding agents could be bypassed
  • Examples of action-level runtime enforcement that pause, redirect, or terminate agents mid-execution
  • The article's full discussion of indirect prompt injection across email, repositories, and web content

👉 Read Pillar Security's full analysis of AI agents as insider threats →

AI agent insider risk: what it means for IAM and governance?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 2 months ago
Posts: 11878
 

The insider threat model now has to include AI agents, because legitimacy no longer means predictability. These systems sit inside the trust boundary with valid credentials, but they do not inherit human pacing, hesitation, or self-preservation. That means the old insider logic still applies at a label level, yet it fails at the control-design level. Practitioner conclusion: treat agent identity as a governed insider population, not as an automation sidecar.

A few things that frame the scale:

  • 92% agree governing AI agents is critical to enterprise security, yet only 44% have implemented any policies to do so, according to AI Agents: The New Attack Surface report.
  • 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, inappropriately sharing sensitive data, and revealing access credentials.

A question worth separating out:

Q: Who is accountable when an authorised AI agent causes a breach?

A: Accountability usually sits with the organisation that assigned the access, defined the workflow, and failed to instrument runtime oversight. The hard part is proving whether the failure was an entitlement decision, a workflow design issue, or a missing behavioural control, which is why governance ownership must span IAM, security engineering, and application teams.

👉 Read our full editorial: AI agents as insiders expose the limits of human IAM controls



   
ReplyQuote
Share: