TL;DR: Agentic AI is moving security decisions across identity and data at machine speed, and MIND argues that traditional siloed controls will not keep pace as agents provision access, move data, and act without human approval. The practical shift is toward adaptive governance that treats identity, intent, and sensitivity as one control problem rather than separate ones.
NHIMG editorial — based on content published by Mind: 2026 predictions on how agentic AI is breaking identity and data security
Questions worth separating out
Q: How should security teams govern data access for agentic AI workflows?
A: Security teams should treat data access as part of the agent’s decision boundary, not as a separate storage problem.
Q: Why do agentic AI workflows break traditional DLP assumptions?
A: Traditional DLP assumes predictable human behaviour, manual review and time to intervene.
Q: What do organisations get wrong about governing AI use?
A: They often separate AI governance from IAM and lifecycle management, even though AI adoption depends on who can access tools, what data those tools can reach, and how access ends.
Practitioner guidance
- Define an AI agent identity inventory Catalogue every agent, service account, token, and delegated workflow that can act without direct human approval.
- Apply just-in-time privilege to autonomous workflows Replace persistent access with task-scoped permissions for high-risk AI actions, especially where agents can reach SaaS, cloud, and on-prem systems.
- Enforce context-aware policy at runtime Add decision points that combine identity, data sensitivity, and behavioural context before privileged actions execute.
What's in the full article
Mind's full article covers the strategic argument and trend framing this post intentionally leaves at a higher level:
- How the vendor expects AI regulation to shape accountability, explainability, and data protection expectations in 2026
- The detailed case for moving from rule-based controls to adaptive risk models across identity and data workflows
- Examples of how autonomous agents can create subtle policy drift without triggering obvious breach alerts
- The vendor's view on how CISOs should embed trust into AI workflows while preserving business speed
👉 Read Mind's 2026 predictions on agentic AI, identity, and data security →
Agentic AI and the identity-data gap: are your controls ready?
Explore further
Identity and data can no longer be governed as separate risk planes. Agentic AI collapses the old operating model where IAM answered who could act and data security answered what was being touched. When a software entity can decide and execute across both domains, control ownership has to converge as well. That means identity governance, data classification, and runtime policy must be evaluated together, not by separate teams in separate tools. Practitioner conclusion: build one policy chain that covers actor, action, and data context.
A question worth separating out:
Q: Who is accountable when an AI agent accesses sensitive data it was not meant to use?
A: Accountability sits with the team that approved the agent, its connectors, and its policy boundaries, not with the runtime behaviour alone. Organisations need ownership for intent, permissions, monitoring, and validation so they can prove whether the agent stayed inside its approved purpose. Without that, audit and regulatory response become retrospective guesswork.
👉 Read our full editorial: Agentic AI is collapsing identity and data security boundaries