TL;DR: Human risk management is moving from compliance scoring to predictive control, and Living Security Human Risk Management Platform’s HRMCon 2025 session says agentic AI is now central to measuring behavior, prioritising interventions, and automating routine remediation across 200+ risk indicators and 60+ integrations. The governance challenge is no longer visibility alone but accountability for autonomous actions, shadow AI, and the identity and access signals that shape human risk.
NHIMG editorial — based on content published by Living Security Human Risk Management Platform: The Future of Human Risk Management: Market Landscape and the Role of Agentic AI
By the numbers:
- Organizations using Living Security's Unify platform saw their population of risky users drop from 43% to 21% over the last year.
- Users spent an average of 60% less time in a risky state after completing action plans.
- The platform's independently validated results showed a 98% decrease in data-loss exposure time.
Questions worth separating out
Q: How should security teams govern AI agents that can access enterprise systems?
A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring.
Q: Why do agentic AI systems create hidden cost and risk exposure?
A: Because one user request can fan out into multiple model calls, evaluations, and tool invocations that are invisible in aggregated billing.
Q: What breaks when shadow AI is not included in identity governance?
A: When shadow AI is excluded, the organisation loses discovery, ownership, and enforcement at the same time.
Practitioner guidance
- Build a unified risk data layer Connect IAM, endpoint, email security, SIEM, and data loss telemetry so behavioural scoring has enough context to predict risk instead of merely describing it.
- Define approval boundaries for AI-driven actions Document which AI recommendations can auto-execute, which require human review, and which must be blocked until a manager or control owner signs off.
- Inventory shadow AI access paths Identify browser extensions, embedded copilots, API calls, and delegated workflows that can consume enterprise credentials or data without central oversight.
What's in the full article
Living Security Human Risk Management Platform's full blog covers the operational detail this post intentionally leaves for the source:
- The full session context from HRMCon 2025, including how Jinan Budge and Graham Westbrook framed market maturation and analyst validation.
- The underlying Forrester Wave and Cyentia references that support the reported outcome metrics and market positioning.
- The detailed examples of predictive HRM workflows, including the 60-80% routine remediation automation model.
- The specific recommendations for building data foundations and AI governance frameworks before scaling agentic workflows.
Agentic AI in human risk management: are controls keeping up?
Explore further
Predictive HRM is becoming an access-governance discipline, not a training discipline. The article shows that the market has moved past counting completions and toward correlating behavior, identity, and threat signals. That is materially closer to access governance than awareness training because the programme now influences who gets flagged, nudged, or remediated. For IAM and GRC teams, the lesson is that behaviour analytics must be treated as a governed control plane, not a reporting layer.
A question worth separating out:
Q: Who is accountable when an AI agent causes a security incident?
A: Accountability should sit with the business owner, the system owner, and the security function together, because agent behaviour crosses operational boundaries. Organisations need a defined owner for approval, monitoring, and retirement, plus audit evidence that shows what the agent accessed and why.
👉 Read our full editorial: Agentic AI is changing human risk management governance