TL;DR: Enterprise AI crossed from copilots into production infrastructure in 2025, with agents, MCP, and governance moving into core systems as firms operationalised execution, control, and accountability, according to Akto. The central issue is no longer whether AI is used, but whether organisations can see, scope, and govern what these systems can do before they act.
NHIMG editorial — based on content published by Akto: Founding Team 2025 AI Yearbook, The Year AI Became Enterprise Infrastructure
By the numbers:
- Enterprise spend on generative AI surged roughly 3.2x year over year in 2025.
- Companies spent roughly $37B on generative AI in 2025.
- 90% of the Fortune 500 use Microsoft 365, rosoft 365 Copilot.
Questions worth separating out
Q: How should security teams govern AI agents that can access enterprise systems?
A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring.
Q: Why do AI agents complicate existing IAM and PAM controls?
A: AI agents complicate IAM and PAM because they often inherit delegated credentials, operate across multiple systems, and keep acting after the initial approval moment has passed.
Q: What do security teams get wrong about ASPM in agentic environments?
A: They often treat ASPM as a reporting layer instead of a decision layer.
Practitioner guidance
- Inventory AI agents as governed identities Create and maintain a registry of agents, the tools they can reach, the data they can touch, and the owners responsible for revoking access when scope changes.
- Bind approvals to runtime execution Require approval gates for high-risk actions such as repository changes, infrastructure updates, payment flows, and data export, rather than relying on design-time trust.
- Extend lifecycle control to AI systems Apply joiner-mover-leaver style thinking to AI agents by reviewing ownership, purpose, connected tools, and revocation events whenever the workflow changes.
What's in the full article
Akto's full blog post covers the operational detail this post intentionally leaves for the source:
- The article's full yearbook-style walkthrough of major platform announcements and what they imply for agent governance.
- Specific examples of enterprise AI adoption across cloud, data, ERP, and workflow systems that show where execution is already happening.
- The source's framing of MCP, agent runtime control, and governance as the main operating issues heading into 2026.
- Akto's own discussion of the AI Agent Identity Security Maturity Model and how it maps to control depth.
👉 Read Akto's 2025 AI yearbook on enterprise AI infrastructure and governance →
AI infrastructure in 2026: is control now the real differentiator?
Explore further
AI infrastructure is now an identity problem, not just a model problem. The article shows that the decisive shift in 2025 was execution, not experimentation. Once agents, MCP, and workflow embedding became normal, the security question moved from model behaviour to who and what can act in production. That is a governance change, not a tooling trend, and practitioners should treat AI systems as governed identities.
A few things that frame the scale:
- Systems with least-privileged AI access had a 17% incident rate vs 76% for over-privileged systems, according to The 2026 Infrastructure Identity Survey.
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security.
A question worth separating out:
Q: How do organisations know if AI agent governance is actually working?
A: Look for three signals: every production agent has a named owner, access decisions are enforced during runtime, and audit trails show when requests were allowed, denied, or escalated. If teams can only describe agent behaviour in hindsight, governance is still incomplete.
👉 Read our full editorial: AI became enterprise infrastructure in 2025, and control now matters