TL;DR: Enterprise AI security is moving from experimentation to operations, with the TAG Enterprise AI Security Handbook 2026 arguing that organisations need continuous discovery, contextual risk tiering, and identity-aware controls as AI systems embed into production, according to Orca Security. The practical issue is not whether to add more policy, but how to adapt existing IAM, data, and application controls to non-human and autonomous behaviour without losing accountability.
Editorial analysis by NHI Mgmt Group, based on content published by Orca Security: “Orca Security Recognized in the 2026 TAG Enterprise AI Security Handbook”.
Key questions
Q: How should organisations govern access to data used by AI systems?
A: Treat AI data access as an identity governance problem, not just a data storage problem.
Q: Why do AI tools create new identity governance risks for IAM teams?
A: AI tools create new identity governance risks because they combine fast adoption with broad access paths and subordinate permission objects.
Q: What are the signs that AI security controls are failing in production?
A: Common warning signs include unapproved model behavior, unexpected data access, prompt leakage, suspicious outbound calls, and runtime actions that do not match the workload’s intended function.
Practitioner guidance
- Inventory all production AI usage Build a continuously updated inventory of AI systems, agents, and AI-enabled workflows across cloud, application, and business environments.
- Assign accountable ownership to each AI identity Map every AI system to a named owner for authorization scope, data access, and lifecycle decisions so governance does not stop at the model boundary.
- Tier AI systems by business and data risk Use sensitivity, business impact, and external exposure to set different review, testing, and control requirements for each AI use case.
Bottom line: AI security becomes an identity governance problem once systems can act inside production workflows and touch real data, services, and entitlements.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
AI security has crossed into identity governance, not because the technology is new, but because the access model is now identity-shaped. Once AI systems call tools, reach data, and act inside enterprise workflows, their security posture depends on the same governance primitives used for NHIs and privileged workloads. That means the real issue is not "AI security" as a separate discipline, but whether IAM, PAM, and lifecycle controls can describe and constrain machine action with enough precision. Practitioners should treat AI systems as governed identities, not just software features.
A few things that frame the scale:
- 1 in 4 organisations are already investing in dedicated NHI security capabilities, with an additional 60% planning to do so within the next twelve months, according to The State of Non-Human Identity Security.
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, 46% confirmed and 26% suspected.
A question worth separating out:
Q: What does the shift to operational AI security mean for existing governance programmes?
A: It means AI security has to run continuously inside existing governance, not as a one-time project. Discovery, access validation, logging, and policy enforcement need to keep pace with changing workflows, because AI systems evolve after deployment. The programme needs operating cadence, ownership, and measurement, not just policy language.
👉 Read our full editorial: AI security is becoming an identity governance problem
AI security has crossed the boundary into identity governance because production AI behaves like a governed actor, not a passive tool. Once AI systems can touch data, trigger workflows, and interact with services, the organisation is no longer managing only model risk. It is managing access scope, accountability, and entitlement drift across non-human behaviour. The practitioners who treat AI security as a model-only problem will miss the governance layer that actually constrains real-world impact.
A few things that frame the scale:
- Enterprise AI use rose from 55% of organisations in 2023 to 88% in 2025, according to McKinsey’s Global Surveys on the State of AI.
A question worth separating out:
Q: Should security teams build separate AI security controls or extend existing IAM and data policies?
A: Extend existing IAM, PAM, data protection, and application security controls first. Separate AI-specific controls only make sense where the technology introduces behaviour those controls cannot express, such as continuous discovery or AI-specific testing. The practical goal is governance continuity, not policy duplication, so the programme remains coherent as AI usage expands.
👉 Read our full editorial: AI security is becoming an identity governance problem