Join our Newsletter — 33% off our NHI Course

AI authorization gap: are your controls keeping up with agents?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Gartner projects AI governance spending will reach $492 million in 2028 and exceed $1 billion by 2030, while regulation is expected to extend to 70% of global economies by decade end, underscoring the gap between visibility and runtime control according to EnforceAuth. The real issue is that point-in-time audits and policy tracking do not continuously authorize what AI is allowed to do.

Editorial analysis by NHI Mgmt Group, based on content published by EnforceAuth: “Gartner Just Confirmed What We've Been Saying: AI Governance Without Authorization Is a $1 Billion Blind Spot”.

By the numbers:

  • Gartner projects AI governance spending will hit $492 million in 2028 and surpass $1 billion by 2030.
  • AI regulation will quadruple, extending to 70% of the world's economies by the end of the decade.

Key questions

Q: Why do AI governance programmes still leave an authorization gap?

A: Because many programmes stop at visibility, risk scoring, and compliance tracking.

Q: When should organisations prioritise runtime authorisation over role-based access control?

A: Prioritise runtime authorisation when the actor can change behaviour mid-session, chain tools, or make repeated service calls without human approval.

Q: What breaks when AI agent identity is split across multiple tools?

A: Governance breaks first.

Practitioner guidance

  • Separate governance from enforcement Treat inventory, risk tracking, and compliance reporting as governance functions, then build a distinct runtime authorisation layer for AI actions.
  • Map cross-domain AI transaction paths Document how a single AI workflow moves across applications, infrastructure, data stores, and downstream agents so policy gaps are visible.
  • Adopt policy-as-code for AI controls Store authorisation rules in version control so they can be tested, reviewed, and moved if a vendor changes direction.

Bottom line: AI governance budgets are rising, but the operational control gap remains because visibility is not the same as runtime authorization.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 1 day ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

AI governance spending is rising faster than runtime control maturity. The market is clearly investing in inventory, risk, and compliance functions, but those do not prevent an AI system from acting outside policy in the moment of execution. That leaves a structural gap between governance evidence and operational enforcement. Practitioners should treat the growth in AI governance budgets as validation of the problem, not proof that the control gap is closing.

A few things that frame the scale:

  • 52% of respondents see AI security decision-making power shifting toward platform and infrastructure teams rather than the executive suite, according to the 2026 Infrastructure Identity Survey.
  • Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security, according to the 2026 Infrastructure Identity Survey.

A question worth separating out:

Q: How should teams respond if their AI governance vendor is acquired or changes strategy?

A: They should test whether policy rules are portable, versioned, and separable from the vendor’s configuration layer. If the rules cannot survive a platform change, the security programme is exposed to product decisions rather than governed by its own policy intent.

👉 Read our full editorial: AI governance spending rises, but the authorization gap remains


This post was modified 1 day ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.