Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AI agent adoption in enterprises: what does it mean for IAM?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Enterprise AI agent adoption is moving from experimentation into production, with Gartner projecting one-third of enterprise software will include agentic AI by 2028 and at least 15% of day-to-day business decisions will be made autonomously, according to Akto. The governance problem is no longer whether agents will spread, but whether organisations can control scope, accountability, and auditability fast enough.

NHIMG editorial — based on content published by Akto: The Current State of AI Agents Adoption in Enterprises

By the numbers:

Questions worth separating out

Q: How should security teams govern AI agents that can access enterprise systems?

A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring.

Q: Why do AI agents complicate existing IAM and PAM controls?

A: AI agents complicate IAM and PAM because they often inherit delegated credentials, operate across multiple systems, and keep acting after the initial approval moment has passed.

Q: What do organisations get wrong when scaling agentic AI?

A: They often treat agents as workflow enhancements instead of governed actors with identity, privilege, and audit requirements.

Practitioner guidance

  • Define a separate agent identity model Create explicit identity types for human users, service accounts, and AI agents.
  • Bound delegated permissions by use case Limit each agent to the smallest tool and data scope needed for its intended workflow.
  • Instrument audit trails for agent actions Log the prompt, tool call, identity, target system, and downstream effect for every agent action that changes state or exposes data.

What's in the full article

Akto's full blog covers the operational detail this post intentionally leaves for the source:

  • The specific enterprise use cases and adoption archetypes the vendor observed across back-office, embedded, and multi-agent deployments
  • The Gartner and PwC context in the original narrative, including how the author interprets productivity gains and execution friction
  • The vendor's framing of trust, governance, and operating-model redesign as AI adoption scales
  • The article's supporting examples and commentary on where enterprises are currently stalling in production

👉 Read Akto's analysis of the current state of AI agent adoption in enterprises →

AI agent adoption in enterprises: what does it mean for IAM?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

AI agent governance is now an identity problem, not just an AI problem. Once agents can act on behalf of an organisation, they become runtime identities that need scoping, accountability, and revocation. Traditional application controls do not answer who authorised the action, which permissions were inherited, or whether the actor was human, automated, or agentic. Practitioners should treat agent governance as part of identity architecture, not a separate AI pilot stream.

A question worth separating out:

Q: When should organisations pause agent deployment and tighten controls first?

A: Organisations should pause when an agent can reach sensitive systems, make decisions with external impact, or operate without reliable logging and human override. Those are the conditions where productivity gains can quickly become governance failures. If access cannot be traced and revoked cleanly, the rollout is ahead of the control model.

👉 Read our full editorial: Enterprise AI agent adoption is broad, but governance lags



   
ReplyQuote
Share: