TL;DR: AI compliance now spans risk classification, human oversight, audit trails, and runtime guardrails as agents call tools, write to databases, and send communications, according to Akto. The practical shift is that compliance teams must treat agentic AI as a governed identity and access surface, not a policy checklist.
NHIMG editorial — based on content published by Akto: AI Compliance Guide for frameworks, regulations, and security
By the numbers:
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%).
Questions worth separating out
Q: How should security teams govern AI models that can call tools and access data?
A: Security teams should govern AI models as non-human identities with named owners, limited scope, short-lived credentials, and continuous authorization.
Q: Why do AI agents complicate traditional IAM controls?
A: AI agents complicate traditional IAM controls because they do not behave like human users with short, predictable sessions.
Q: What breaks when shadow AI is not discovered early?
A: Teams lose sight of which agents exist, what they can reach, and which credentials they use.
Practitioner guidance
- Implement a living AI asset inventory Track every model, agent, MCP tool, owner, and data path in one continuously maintained inventory.
- Enforce runtime guardrails on tool use Constrain which tools an agent can call, what data it can read, and what outputs it can produce while the workflow is live.
- Log every agent action end to end Record prompts, tool calls, data access, outputs, and decisions so investigations can reconstruct what happened after a policy event or incident.
What's in the full article
Akto's full blog covers the operational detail this post intentionally leaves for the source:
- The article's framework-by-framework mapping of AI compliance controls to EU AI Act, NIST AI RMF, and ISO/IEC 42001 requirements
- The step-by-step operational model for discovery, policy enforcement, and incident response across agentic AI deployments
- The practical detail behind Akto Argus and Akto Atlas, including continuous testing and shadow AI visibility workflows
- The article's discussion of how regulated sectors such as healthcare, finance, and HR interpret AI compliance differently
👉 Read Akto's AI compliance guide for agentic AI and LLM security →
Agentic AI compliance is now an access-control problem for teams?
Explore further
AI compliance is now an identity governance problem in disguise. Once agents can act independently, the main question is no longer only whether the model is safe. It is whether the system has bounded identities, auditable permissions, and enforced scope for every action. That makes AI governance inseparable from IAM, PAM, and NHI controls in any environment where tools or data are involved.
A question worth separating out:
Q: Who is accountable when an authorised AI agent causes a breach?
A: Accountability usually sits with the organisation that assigned the access, defined the workflow, and failed to instrument runtime oversight. The hard part is proving whether the failure was an entitlement decision, a workflow design issue, or a missing behavioural control, which is why governance ownership must span IAM, security engineering, and application teams.
👉 Read our full editorial: AI compliance for agentic systems is becoming an access-control problem