Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Agentic AI in human risk management: are controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19382
Topic starter  

TL;DR: Human risk management is moving from compliance scoring to predictive control, and Living Security Human Risk Management Platform’s HRMCon 2025 session says agentic AI is now central to measuring behavior, prioritising interventions, and automating routine remediation across 200+ risk indicators and 60+ integrations. The governance challenge is no longer visibility alone but accountability for autonomous actions, shadow AI, and the identity and access signals that shape human risk.

NHIMG editorial — based on content published by Living Security Human Risk Management Platform: The Future of Human Risk Management: Market Landscape and the Role of Agentic AI

By the numbers:

Questions worth separating out

Q: How should security teams govern AI agents that can access enterprise systems?

A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring.

Q: Why do agentic AI systems create hidden cost and risk exposure?

A: Because one user request can fan out into multiple model calls, evaluations, and tool invocations that are invisible in aggregated billing.

Q: What breaks when shadow AI is not included in identity governance?

A: When shadow AI is excluded, the organisation loses discovery, ownership, and enforcement at the same time.

Practitioner guidance

  • Build a unified risk data layer Connect IAM, endpoint, email security, SIEM, and data loss telemetry so behavioural scoring has enough context to predict risk instead of merely describing it.
  • Define approval boundaries for AI-driven actions Document which AI recommendations can auto-execute, which require human review, and which must be blocked until a manager or control owner signs off.
  • Inventory shadow AI access paths Identify browser extensions, embedded copilots, API calls, and delegated workflows that can consume enterprise credentials or data without central oversight.

What's in the full article

Living Security Human Risk Management Platform's full blog covers the operational detail this post intentionally leaves for the source:

  • The full session context from HRMCon 2025, including how Jinan Budge and Graham Westbrook framed market maturation and analyst validation.
  • The underlying Forrester Wave and Cyentia references that support the reported outcome metrics and market positioning.
  • The detailed examples of predictive HRM workflows, including the 60-80% routine remediation automation model.
  • The specific recommendations for building data foundations and AI governance frameworks before scaling agentic workflows.

👉 Read Living Security Human Risk Management Platform's analysis of the future of human risk management and agentic AI →

Agentic AI in human risk management: are controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 18973
 

Predictive HRM is becoming an access-governance discipline, not a training discipline. The article shows that the market has moved past counting completions and toward correlating behavior, identity, and threat signals. That is materially closer to access governance than awareness training because the programme now influences who gets flagged, nudged, or remediated. For IAM and GRC teams, the lesson is that behaviour analytics must be treated as a governed control plane, not a reporting layer.

A question worth separating out:

Q: Who is accountable when an AI agent causes a security incident?

A: Accountability should sit with the business owner, the system owner, and the security function together, because agent behaviour crosses operational boundaries. Organisations need a defined owner for approval, monitoring, and retirement, plus audit evidence that shows what the agent accessed and why.

👉 Read our full editorial: Agentic AI is changing human risk management governance



   
ReplyQuote
Share: