Join our Newsletter — 33% off our NHI Course

Enterprise AI security and agentic risk: what teams need to know

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Enterprise AI security now spans models, agents, retrieved data, and employee interactions, and the source argues that governance without enforcement creates policy theater while runtime controls, discovery, and continuous validation are becoming essential, according to Lasso Security. That shift means security teams must design for how AI behaves in production, not how it was intended to behave.

Editorial analysis by NHI Mgmt Group, based on content published by Lasso Security: “Enterprise AI Security: Managing Risk Across AI Apps & Agents”.

Key questions

Q: What breaks when enterprise AI is governed but not enforced?

A: Policy-only programmes fail because they can define acceptable use without stopping prompt injection, tool misuse, or data leakage during live execution.

Q: Why do AI agents increase operational risk compared with chatbots?

A: AI agents can take actions, not just generate text, so a bad decision can become an unauthorised workflow, a data exposure, or a transactional error.

Q: What are the signs that prompt based security controls are failing in enterprise AI workflows?

A: Common signs include unexpected data retrieval, tools being invoked outside approved use cases, policy instructions being ignored, and model outputs that expose internal or regulated information.

Practitioner guidance

  • Implement AI discovery and inventory Map sanctioned applications, developer-built agents, low-code tools, browser extensions, and third-party AI services so the security team can see the full estate before applying policy.
  • Enforce runtime controls on prompts and tool calls Inspect prompts, responses, and agent tool executions inline so policy violations, data leakage, and misdirected actions can be blocked as they happen.
  • Map AI dependencies and retrieval boundaries Document every model, MCP server, API, and knowledge source an agent can reach, then verify that each retrieval path aligns with the access policy attached to the requesting identity.

Bottom line: Enterprise AI security is a production control problem, not a policy-only exercise, because live systems can be manipulated through prompts, retrieval, and tool use.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21364
 

Policy without enforcement is not AI security. The article correctly separates governance from security, but the deeper point is that governance becomes performative when agents, tools, and data paths can change faster than policy review cycles. Security programmes need runtime enforcement, asset visibility, and decision logging because written rules do not stop prompt injection or tool misuse. The practical conclusion is that identity teams should treat AI security as an operational control stack, not a compliance document.

A few things that frame the scale:

  • 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, according to The 2024 ESG Report: Managing Non-Human Identities.
  • Two-thirds of enterprises have endured a successful cyberattack resulting from compromised non-human identities, with a quarter encountering multiple attacks.

A question worth separating out:

Q: What should organisations do first when building enterprise AI security?

A: Start with discovery, because you cannot govern AI systems you cannot see. Build an inventory of models, agents, extensions, and third-party connections, then classify what each one can touch. From there, add access controls, monitoring, and audit trails that match the actual runtime behaviour of the system.

👉 Read our full editorial: Enterprise AI security is outgrowing governance-only models



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21364
 

Governance-only AI programmes create policy theater: they define ownership and acceptable use, but they do not stop an agent from being manipulated at runtime. That failure mode matters because AI security is a control problem, not a paperwork problem. The enterprise that cannot enforce prompt, tool, and retrieval boundaries is still exposed even with a complete policy stack.

A few things that frame the scale:

A question worth separating out:

Q: Should organisations prioritise discovery or runtime enforcement first for AI governance?

A: Discovery comes first because runtime enforcement cannot be meaningfully scoped without knowing where AI exists and what it can access. Once the inventory is live, teams can apply policy checks, output controls, and retention requirements to the highest-risk systems first.

👉 Read our full editorial: Enterprise AI security is outgrowing governance-only models


This post was modified 3 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.