Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Agentic AI governance and enforcement gaps: are controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 13681
Topic starter  

TL;DR: Agentic AI is shifting enterprise risk from user prompts to autonomous action, with Gartner estimating 40% of enterprise applications will incorporate AI agents by year-end, up from less than 5% in 2025, while 78% of organizations already use AI in at least one business function, according to the article and the Stanford HAI AI Index 2025. The governance gap is no longer policy intent but enforcement that can see, interpret, and interrupt agent activity before bulk access becomes bulk exposure.

NHIMG editorial — based on content published by Cyberhaven: Agentic AI Governance Requires a New Enforcement Model

By the numbers:

Questions worth separating out

Q: How should security teams manage permissions for AI agents?

A: Security teams should regularly assess and update the permissions granted to AI agents to ensure they align with their intended scope.

Q: Why do agent frameworks create new access-risk problems for IAM teams?

A: Because they let runtime decisions, tool calls, and stateful workflows happen inside familiar development stacks, which can hide where authorisation actually occurs.

Q: What breaks when organisations use prompt review as their main AI governance control?

A: Prompt review only shows what a user typed, not what the agent read, aggregated, or sent onward.

Practitioner guidance

  • Define agent-specific authorisation boundaries Separate agent permissions from the human user who initiated the workflow.
  • Deploy discovery at the endpoint layer Track local AI processes, MCP-connected tools, and other agent runtimes where they execute, not only where they communicate.
  • Measure governance by interruption capability Test whether policy can stop an agent before it completes a transfer, aggregation, or external share.

What's in the full article

Cyberhaven's full article covers the operational detail this post intentionally leaves for the source:

  • How the vendor distinguishes discovery, observability, and control in agentic AI enforcement models.
  • Operational examples of endpoint-based enforcement for local AI processes and MCP-connected tools.
  • The vendor's recommended policy structure for autonomous workflows, including where human review should still apply.
  • Practical implementation detail on monitoring data lineage across AI-driven aggregation paths.

👉 Read Cyberhaven's analysis of why agentic AI governance requires a new enforcement model →

Agentic AI governance and enforcement gaps: are controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
Share: