TL;DR: AI systems that choose tools, access data, and act on behalf of users have outgrown traditional risk management, and Akto’s guide argues for a repeatable framework covering inventory, taxonomy, scoring, mitigation, and continuous reassessment. The real shift is that AI risk is now an identity governance problem as much as a model-risk problem.
NHIMG editorial — based on content published by Akto: AI Risk Assessment Framework for AI Agents, LLMs, and Governance
By the numbers:
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, inappropriately sharing sensitive data, and revealing access credentials.
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, 46% confirmed and 26% suspected.
Questions worth separating out
Q: How should security teams test AI agents that can call tools and APIs?
A: They should test the agent's actual execution paths, not just its text responses.
Q: Why do chat-based AI systems create new identity risk for organisations?
A: Chat-based AI systems compress intent, delegation, and execution into one interaction, which makes privilege boundaries easier to cross without noticing.
Q: What breaks when AI risk reviews are done only at deployment time?
A: You miss the behaviour that appears after launch.
Practitioner guidance
- Inventory AI systems as governed identities Track models, agents, vector stores, prompts, templates, and tool integrations across cloud, on-prem, and employee devices.
- Classify AI assets by autonomy, sensitivity, and exposure Use separate risk tiers for internal assistants, public-facing agents, and systems touching regulated data.
- Scope agent credentials to the minimum viable task Replace shared credentials and standing access where possible, and define explicit permission boundaries for each agent.
What's in the full article
Akto's full blog post covers the operational detail this post intentionally leaves for the source:
- Step-by-step guidance for discovering AI systems, agents, models, and tool integrations across mixed environments.
- Detailed risk scoring workflow for prioritising AI findings by likelihood, impact, and compliance exposure.
- Implementation examples for permission scoping, output validation, sandboxing, and runtime reassessment.
- A structured walkthrough of AI risk categories including prompt injection, autonomous action, MCP risk, and supply chain exposure.
👉 Read Akto's guide to building an AI risk assessment framework for agents and LLMs →
AI risk assessment frameworks: what IAM teams need to govern?
Explore further
AI risk assessment has become identity governance for agentic systems. Once a model can choose tools, act on data, and trigger downstream systems, the security question stops being limited to output quality. The governance question becomes who or what is allowed to act, for how long, and with what blast radius. Security teams that still treat AI review as a one-time model exercise are missing the identity layer that now defines operational risk.
A few things that frame the scale:
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, inappropriately sharing sensitive data, and revealing access credentials, according to AI Agents: The New Attack Surface report.
- Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.
A question worth separating out:
Q: Who is accountable when an AI agent causes a security incident?
A: Accountability should sit with the business owner, the system owner, and the security function together, because agent behaviour crosses operational boundaries. Organisations need a defined owner for approval, monitoring, and retirement, plus audit evidence that shows what the agent accessed and why.
👉 Read our full editorial: AI risk assessment frameworks are now identity governance work