Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

CoSAI and agentic AI standards: what it means for IAM teams


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 2182
Topic starter  

TL;DR: Agentic AI security standards are being shaped now inside CoSAI, where more than 45 sponsors and 91% of organizations already on the adoption curve point to a governance model that is still unfinished, according to Zenity and Gartner. The practical issue is not whether agents are coming, but whether identity, access, and runtime controls are defined before they move into production.

NHIMG editorial — based on content published by Zenity: Zenity Joins CoSAI, explaining why agentic AI standards need practitioners at the table

By the numbers:

Questions worth separating out

Q: How should security teams govern AI agents that can invoke multiple tools in one session?

A: Security teams should govern AI agents as decision-making identities, not just tool users.

Q: Why do agentic AI systems create new identity governance risks?

A: Agentic AI systems create new identity governance risks because they do not simply authenticate and wait for commands.

Q: What breaks when IAM controls are applied to autonomous agents without runtime governance?

A: IAM controls break when they assume access can be reviewed after the fact.

Practitioner guidance

  • Map agent governance to emerging standards now Inventory which of your agentic AI controls reference OWASP Agentic AI guidance, MITRE ATLAS techniques, and CoSAI workstream outputs.
  • Unify identity and tool-access policy for agents Treat agent identity, MCP tool permissions, and data scope as a single governance problem.
  • Review runtime controls before provisioning controls alone Assess whether your current programme can detect or interrupt an agent that chains actions across systems in one session.

What's in the full article

Zenity's full analysis covers the operational detail this post intentionally leaves for the source:

  • The specific CoSAI workstreams and governance mechanics behind each open specification effort
  • Zenity's direct contributions to OWASP, MITRE ATLAS, and the standards credibility stack it describes
  • The article's practitioner questions for CISOs evaluating vendors against emerging agentic AI standards
  • The full argument for why runtime governance matters when agents can chain actions across enterprise systems

👉 Read Zenity's analysis of CoSAI and agentic AI security standards →

CoSAI and agentic AI standards: what it means for IAM teams?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 weeks ago
Posts: 742
 

Agentic AI standards are now part of identity governance, not a side conversation. The article makes clear that CoSAI is building the specifications enterprises will eventually operationalize, which means identity teams are no longer just consuming standards after the fact. They are shaping the access, audit, and runtime assumptions those standards will encode. The implication is that IAM and NHI programmes will inherit agentic control requirements whether they are ready or not.

A few things that frame the scale:

  • 92% agree governing AI agents is critical to enterprise security, yet only 44% have implemented any policies to do so, according to AI Agents: The New Attack Surface report.
  • Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.

A question worth separating out:

Q: Who should be accountable for agentic AI security standards in enterprise programmes?

A: Accountability should sit with the teams that own identity architecture, security governance, and risk acceptance, not only with AI engineering. Agentic AI standards will influence procurement, audit, and control design, so leadership must decide who maps standards to policy, who signs off exceptions, and who validates runtime enforcement in production.

👉 Read our full editorial: Zenity joins CoSAI as agentic AI standards take shape



   
ReplyQuote
Share: