TL;DR: AI agents are entering production faster than governance frameworks can mature, and Soffid cites Keyfactor data showing half of organizations still lack AI agent governance while only 28% can stop an out-of-control agent before damage occurs. That gap makes identity, access, and detection convergence the real control problem, not another layer of tooling.
NHIMG editorial — based on content published by Soffid: AI Agent Security: How to Govern the Next Wave of Non-Human Identities
By the numbers:
- Only 28% say they could stop the actions of an out-of-control AI agent before it causes damage.
- 80% of organisations report their AI agents have already performed actions beyond their intended scope.
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities.
Questions worth separating out
Q: How should security teams govern AI agents that inherit authority from other identities?
A: Security teams should govern AI agents by tracking identity lineage, not just credentials.
Q: Why do AI agents create new risk in non-human identity management?
A: AI agents create risk because they operate as software identities with delegated authority, but many organisations do not track them with the same discipline applied to users or service accounts.
Q: What breaks when AI agents inherit access from users and service accounts?
A: The main failure is that inherited access can be broader than the agent’s actual task, so privilege becomes easier to reuse than to govern.
Practitioner guidance
- Create a dedicated AI agent identity inventory Catalogue every agent, its owning team, the credentials it uses, the tools it can call, and the data domains it can reach.
- Bind each agent to least-privilege tool scopes Limit every agent to the smallest set of APIs, repositories, and actions required for the task.
- Integrate agent telemetry with identity threat detection Correlate agent logins, token use, tool calls, and sensitive data access so unexpected behavior can be traced back to a specific identity decision.
What's in the full article
Soffid's full article covers the operational detail this post intentionally leaves for the source:
- How Soffid frames a converged IAM architecture for AI agent security across identity, access, governance, and detection.
- The specific layered controls it recommends for limiting agent operations, tool access, and decision-chain visibility.
- Its explanation of why identity security and ITDR are treated as complementary controls for agent governance.
- The article’s view of how AI agent behaviour maps to non-human identity management in practice.
👉 Read Soffid's analysis of AI agent security and non-human identity governance →
AI agent security: are your identity controls keeping up?
Explore further
AI agent security is now an identity governance problem, not an application hardening problem. The article’s core claim is correct in one respect: agents are only manageable when identity, access, governance, and detection are converged. Separate control stacks create blind spots because the agent’s authority is distributed across provisioning, policy, telemetry, and response. Practitioners should treat this as a governance architecture issue before it becomes a tooling issue.
A few things that frame the scale:
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%), according to AI Agents: The New Attack Surface report.
- 48% of organisations say they have a complete blind spot for compliance and breach investigation because they cannot track and audit the data their AI agents access.
A question worth separating out:
Q: Who is accountable when an AI agent uses delegated access incorrectly?
A: Accountability should follow the delegated authority chain, not stop at the agent label. The relevant owners are the teams responsible for the human identity, the service identity, the workflow, and the policy that allowed the action path. If those responsibilities are not explicit, incident review will be incomplete and remediation will focus on the wrong layer.
👉 Read our full editorial: AI agent security demands converged IAM, governance, and detection