Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Agentic AI governance is shifting from model control to system control


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 17031
Topic starter  

TL;DR: The Great Agent Hack 2025 showed that observability, multi-agent coordination, and systematic red-teaming are becoming the practical baseline for production agentic AI, according to Holistic AI. The lesson is that governance must move from supervising a model in isolation to controlling the behaviour, traces, and failure modes of interacting agent systems.

NHIMG editorial — based on content published by Holistic AI: What We Learned from the Great Agent Hack 2025

By the numbers:

  • The Great Agent Hack 2025 brought together more than 200 builders and produced 51 submissions across three challenge tracks.

Questions worth separating out

Q: How should security teams govern agentic AI that can execute IAM tasks?

A: Start by treating the agent as an NHI with bounded authority, explicit ownership, and revocation procedures.

Q: Why do AI agents complicate existing IAM and authorization models?

A: AI agents complicate IAM because they turn natural language into execution, which can cross systems faster than human review can intervene.

Q: How do security teams know if agent observability is actually working?

A: Observability is working only when teams can tie together token activity, tool calls, and latency for a specific agent session.

Practitioner guidance

  • Define agent identities and privilege boundaries Treat each planner, executor, reviewer, and verifier as a distinct non-human identity with a scoped entitlement set, named owner, and explicit lifecycle.
  • Instrument end-to-end traces for every agent workflow Capture prompts, tool calls, outputs, latency, errors, and policy decisions in a single traceable record so investigators can reconstruct behaviour across the full chain.
  • Run recurring adversarial tests on delegation logic Test how agents behave when instructions conflict, tools return unexpected results, or one agent tries to influence another.

What's in the full article

Holistic AI's full blog covers the operational detail this post intentionally leaves for the source:

  • Track-by-track descriptions of the winning agent designs and the specific techniques each team used to score well
  • Judge and sponsor commentary on why observability, safety, and performance were evaluated together
  • Examples of the red-teaming and behavioural profiling work that led to the grand champion result
  • The collaborative research follow-on that turns hackathon prototypes into broader evaluation work

👉 Read Holistic AI's analysis of the Great Agent Hack 2025 and agentic AI governance →

Agentic AI governance is shifting from model control to system control?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 16618
 

Observability is becoming the first governance requirement for agentic AI. The article shows that teams are converging on traces, dashboards, and step-level inspection because agent behaviour cannot be governed after the fact. When prompts, outputs, tool use, and system events are visible together, teams can separate acceptable variability from policy failure. The practical conclusion is clear: without full-stack observability, agent governance is speculative.

A question worth separating out:

Q: Who is accountable when an AI agent causes a security incident?

A: Accountability should sit with the business owner, the system owner, and the security function together, because agent behaviour crosses operational boundaries. Organisations need a defined owner for approval, monitoring, and retirement, plus audit evidence that shows what the agent accessed and why.

👉 Read our full editorial: Agentic AI governance is shifting from model control to system control



   
ReplyQuote
Share: