TL;DR: Enterprises are moving from copilot-style add-ons toward AI-first architectures where agents orchestrate tools through protocols like MCP, while GPU provisioning delays and static capacity assumptions expose a growing mismatch between AI adoption and infrastructure reality, according to WitnessAI. The governance problem is no longer just adding AI features, but deciding how identities, access, and runtime control work when AI becomes the orchestration layer.
Editorial analysis by NHI Mgmt Group, based on content published by WitnessAI: “The Coming AI Architecture Shake-Up: What Enterprises Must Prepare For in 2026”.
Key questions
Q: How should security teams govern MCP servers used by AI coding assistants?
A: Treat MCP servers as privileged trust boundaries, not simple data sources.
Q: Why do AI-first architectures change identity governance for enterprise systems?
A: Because the agent, not the application, becomes the entity that chooses which systems to query and which actions to take.
Q: What breaks when AI systems need multiple enterprise tools at runtime?
A: Static access models break first, because the system cannot predict every tool combination in advance.
Practitioner guidance
- Define agent-scoped access policies Classify each AI workflow by the exact tools, datasets, and actions it may invoke, then separate those permissions by task or agent role instead of reusing broad application accounts.
- Inventory MCP-exposed tools and data paths Document every service published through MCP, including read and write capabilities, downstream data returned, and the business owner responsible for revocation.
- Replace app-centric review logic with runtime governance Review whether your access reviews and entitlement approvals still make sense when AI systems orchestrate actions across multiple systems in a single session.
Bottom line: AI-first architecture shifts governance from application-centric controls to runtime control of agent tool use across enterprise systems.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
AI-first architecture turns the agent into the new control plane: once AI systems orchestrate enterprise tools, identity governance can no longer stop at the application boundary. The real subject is not whether AI is present, but where authorisation is enforced when the agent chooses the sequence of actions. That makes tool access, runtime scoping, and delegation policy the core governance objects for IAM, PAM, and NHI teams.
A few things that frame the scale:
- Organisations that describe themselves as confident in their AI deployment actually experience a 72% security incident rate, compared to 33% for those who remain cautious, according to the 2026 Infrastructure Identity Survey.
- Only 13% of organisations feel extremely prepared for the reality of agentic AI despite the majority racing toward autonomous adoption, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: How do infrastructure constraints affect AI identity controls?
A: When GPU capacity is slow to provision or fixed in advance, teams are tempted to relax security controls to keep services online. That can turn temporary access exceptions into standing privilege. The governance question is therefore not just whether AI can run, but whether the control model survives under load.
👉 Read our full editorial: AI-first architectures are reshaping enterprise identity governance