TL;DR: AI agents now create a security layer that can watch behaviour but cannot define authority, leaving enterprises with visibility into action and weak control over what those systems may access, according to WorkOS. The real issue is that monitoring tools do not replace authentication, authorization, or lifecycle governance for autonomous identities.
Editorial analysis by NHI Mgmt Group, based on content published by WorkOS: “Zenity for AI Agent Security: Features, Pricing, and Alternatives”.
Key questions
Q: How should teams govern AI agents when observability is in place but authorization is weak?
A: Teams should treat observability as supporting evidence, not as the control boundary.
Q: Why do AI agents create more risk than traditional automation?
A: AI agents create more risk because they can interpret context, choose actions, and invoke tools autonomously.
Q: What breaks when organisations try to secure agentic AI with behaviour-based monitoring alone?
A: Behaviour-based monitoring breaks down because agentic systems do not have a stable baseline for known good activity.
Practitioner guidance
- Define agent identity boundaries Assign each AI agent a distinct identity, explicit owner, and task scope so authority is not inferred from the surrounding application stack.
- Scope access before deployment Review every agent permission set before production use and remove any inherited access that is not needed for the specific task path.
- Separate observability from enforcement Use behavioural monitoring for detection and response, but keep authorization decisions in IAM and policy layers that can actually deny access.
Bottom line: AI agent security fails when teams confuse behavioural visibility with authority control, because monitoring cannot substitute for authorization.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Observability is not an authority model: Watching AI agents move across environments does not answer the governance question that matters most, which is what they were authorised to do in the first place. Security programmes that stop at telemetry create evidence without constraint. The implication is that agentic AI security must begin with explicit permission design, not with monitoring overlays.
A few things that frame the scale:
- Systems with least-privileged AI access had a 17% incident rate vs 76% for over-privileged systems. Organisations failing to scope AI access properly are 4.5x more likely to experience a security incident, according to the 2026 Infrastructure Identity Survey.
- Gartner predicts that more than 50% of successful cyberattacks against AI agents through 2029 will exploit access control weaknesses.
A question worth separating out:
Q: What is the difference between AI agent observability and access control?
A: Observability tells you what an agent did and helps you investigate suspicious behaviour. Access control tells you what the agent may do in the first place. For production AI systems, both matter, but only access control can prevent an agent from reaching data or actions that fall outside its intended scope.
👉 Read our full editorial: AI agent security exposes the gap between observability and IAM