Join our Newsletter — 33% off our NHI Course

Claude for work and personal AI assistants: are controls ready?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Enterprises are starting to give every employee AI assistants broad access to email, calendars, documents, and internal systems, but those agents often lack a distinct identity, policy enforcement, and auditable separation from the user, according to Aembit. The governance model built for human workers does not yet fit agentic access that spans the full digital work life.

Editorial analysis by NHI Mgmt Group, based on content published by Aembit: “Every Employee is Getting an AI Assistant, But Is Security Infrastructure Ready?”.

Key questions

Q: What breaks when a personal AI assistant shares the user's identity?

A: The control boundary breaks because every action becomes attributable to the human by default, even when the assistant made the execution decision.

Q: Why does integrating an AI assistant into Microsoft 365 create security and compliance risk if governance is weak?

A: Because the assistant inherits the context and permissions of the environment it works in.

Q: How can security teams tell whether an AI assistant has crossed from analysis into operational control?

A: Look for any path where the assistant can create, schedule or execute a remediation step rather than only describe one.

Practitioner guidance

  • Define a separate agent identity for employee assistants Bind the assistant to a distinct identity that can be authorised independently of the human user, so agent actions are not indistinguishable from employee actions.
  • Scope assistant access by task and data class Limit access to the specific systems, datasets, and business functions the assistant needs for a given workflow, rather than granting full digital work life reach.
  • Require runtime policy enforcement on every sensitive action Evaluate context at execution time before the assistant reads, writes, or transmits sensitive information, especially across email, documents, and internal systems.

Bottom line: Employee AI assistants widen the access surface across business systems, so treating them like ordinary applications leaves a governance gap.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 21 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 20880
 

Personal AI assistants expose the agent identity gap because current IAM models still assume a single human principal behind the work. That assumption fails when the assistant can independently reach into email, calendars, documents, and internal systems during the user’s workflow. The governance consequence is that identity, policy, and audit all need to represent the agent as a first-class actor, not a hidden extension of the employee.

A few things that frame the scale:

  • 19% of organisations give AI systems dramatically more access than human employees, nearly one in five granting unrestricted privilege, according to the 2026 Infrastructure Identity Survey.
  • Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security, according to the 2026 Infrastructure Identity Survey.

A question worth separating out:

Q: What should IAM teams prioritise before AI agents are widely deployed?

A: They should prioritise continuous identity correlation across all actor types, because agentic AI amplifies any existing visibility gap. If the organisation cannot see service accounts, tokens, and agent activity in one operational view, it will not be able to govern runtime access safely once AI usage scales.

👉 Read our full editorial: Claude as a personal assistant exposes the agent identity gap


This post was modified 21 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.