TL;DR: Most enterprises overestimate their AI governance maturity, with many still unable to inventory production agents, query actions from one audit log, or attribute activity back to the human originator, according to C1.ai. The real dividing line is whether policy is enforced at request time, not described in a wiki.
NHIMG editorial — based on content published by C1.ai: Most Enterprises Think They're on Rung 3. They're on Rung 1
By the numbers:
- NHIs outnumber human identities by 25x to 50x in modern enterprises.
- Only 5.7% of organisations have full visibility into their service accounts.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.
Questions worth separating out
Q: How should security teams govern agentic AI as it moves into production?
A: Security teams should govern agentic AI as a class of non-human identity, not as a generic application feature.
Q: Why do inventory and policy documents fail to prove AI governance maturity?
A: Because maturity depends on enforcement, not description.
Q: What do teams get wrong about audit logging for AI tool use?
A: Teams often log the server error but not the identity event.
Practitioner guidance
- Inventory production agents with a single source of truth Build one authoritative register for every agent, workflow, and tool call path so you can answer what is running, who deployed it, and what it touches without stitching together five systems.
- Enforce policy at request time Move from wiki policy to runtime authorisation that evaluates each tool call before execution, and log the decision with requester, action, and context.
- Preserve originator attribution through the full chain Require audit records to retain the human originator, not just the service account or platform identity, so investigations and recertification can trace accountability end to end.
What's in the full article
C1.ai's full blog covers the operational detail this post intentionally leaves for the source:
- The five-rung maturity ladder with the specific signals used to distinguish each level in practice.
- The four diagnostic questions in full, including the operational examples behind each test.
- The ADAPT series context and the executive meeting structure used to set the next-stage roadmap.
- The article’s framing of how teams move from inventory and policy language to governed execution.
👉 Read C1.ai's post on AI governance maturity and the five-rung ladder →
AI governance maturity: are most enterprises really on rung 3?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Most enterprises confuse AI documentation with AI governance. A policy deck, a wiki page, and an inventory are not the same thing as control at runtime. The article’s ladder is useful because it exposes how often organisations stop at visibility and call it maturity. Practitioners should treat this as a warning that evidence of AI existence is not evidence of AI control.
A few things that frame the scale:
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to Ultimate Guide to NHIs.
- Only 5.7% of organisations have full visibility into their service accounts, which is why discovery without enforcement remains a governance trap.
A question worth separating out:
Q: Who is accountable when a third-party AI agent misbehaves in production?
A: The organisation using the agent remains accountable for the outcomes, even if a vendor supplies the platform. Security, legal, compliance, and business owners should share responsibility for controls, monitoring, and incident response. If the agent can affect customers or regulated data, accountability cannot be outsourced with the technology.
👉 Read our full editorial: AI governance maturity is still stuck at shadow and tracked AI