TL;DR: AI governance, offensive AI capability, and identity-related security gaps are converging as organisations deploy AI into critical workflows before controls and oversight mature, according to Imprivata's analysis of recent policy, vendor, and congressional developments. The decisive issue is no longer model quality but who and what can access sensitive systems, because governance assumptions built for static access do not hold once AI is operational.
Editorial analysis by NHI Mgmt Group, based on content published by Imprivata: “Identity Security Signals: AI governance gaps, expanding cyber risk, and the evolution of identity-centric security”.
Key questions
Q: How should security teams govern AI-enabled workflows that can act on their own?
A: Treat them as identity-governed execution paths, not just software features.
Q: Why do AI systems increase identity risk even when they improve security operations?
A: AI can help defenders, but it also helps attackers scale phishing, impersonation, and credential abuse.
Q: What are the signs that AI governance is failing in the enterprise?
A: Common warning signs include rapid growth in AI use without matching policy coverage, sensitive files being copied into personal accounts, and a large share of AI apps carrying high or critical risk.
Practitioner guidance
- Map AI-enabled workflows to identity boundaries Identify every workflow where an AI system can read, write, trigger, or escalate into sensitive enterprise systems.
- Review post-authentication permissions for AI-connected systems Inventory the applications, APIs, and data stores that AI tools can reach after login or token exchange.
- Treat AI governance as entitlement governance Bring IAM, security, and AI governance stakeholders into one control model for sensitive workflows.
Bottom line: AI governance and IAM are converging because the main risk is no longer model quality alone, but what trusted systems can access after authentication.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
AI governance is now an identity discipline, not a policy exercise. The article shows organisations deploying AI into critical workflows before they can define who or what should be allowed to act. That is an IAM problem because the meaningful boundary is access, not model presence. As soon as AI touches sensitive data or operational systems, governance becomes a question of entitlement, session scope, and oversight. Practitioners should treat AI governance as part of access architecture, not a post-deployment compliance layer.
A few things that frame the scale:
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
- The same research found that 45% of organisations cite lack of credential rotation as the top cause of NHI-related attacks, which is consistent with governance failures that persist after access is granted.
A question worth separating out:
Q: How can teams reduce risk when AI tools are connected to enterprise workflows?
A: Start by narrowing what the AI tool can see and do, then add monitoring for unusual access patterns and action chains. Put ownership on a named team, enforce expiry or revocation rules, and include the AI connection in privileged access reviews. That makes exposure visible before it becomes operational loss.
👉 Read our full editorial: AI governance and identity controls are colliding across critical systems
AI governance is now an identity discipline, not a policy exercise. The article shows organisations deploying AI into critical workflows before they can define who or what should be allowed to act. That is an IAM problem because the meaningful boundary is access, not model presence. As soon as AI touches sensitive data or operational systems, governance becomes a question of entitlement, session scope, and oversight. Practitioners should treat AI governance as part of access architecture, not a post-deployment compliance layer.
A few things that frame the scale:
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
- The same research found that 45% of organisations cite lack of credential rotation as the top cause of NHI-related attacks, which is consistent with governance failures that persist after access is granted.
A question worth separating out:
Q: How can teams reduce risk when AI tools are connected to enterprise workflows?
A: Start by narrowing what the AI tool can see and do, then add monitoring for unusual access patterns and action chains. Put ownership on a named team, enforce expiry or revocation rules, and include the AI connection in privileged access reviews. That makes exposure visible before it becomes operational loss.
👉 Read our full editorial: AI governance and identity controls are colliding across critical systems
Access governance is becoming the decisive AI security control: AI governance that stops at policy language fails once systems are operational. The article shows that AI tools are already influencing decisions, handling sensitive data, and interacting with enterprise workflows, which means access scope now matters more than abstract approval. The implication is that IAM and AI governance can no longer be separated into different programmes.
A few things that frame the scale:
- 52% of respondents see AI security decision-making power shifting toward platform and infrastructure teams rather than the executive suite, according to the 2026 Infrastructure Identity Survey.
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: What should teams do when AI tools can reach sensitive systems through existing IAM controls?
A: Reclassify those paths as high-risk access and apply tighter entitlement review, monitoring, and revocation rules. The question is not whether the AI was approved to exist, but whether its authenticated access is constrained to the minimum operational scope needed for the workflow.
👉 Read our full editorial: AI governance and identity controls are colliding across critical systems