Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AI agent sprawl at Kantar: what security teams should take away


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 12387
Topic starter  

TL;DR: As AI agents multiplied across Kantar, the company needed systematic discovery, adversarial testing, and governance to keep pace with non-deterministic behaviour and emerging attack vectors, according to Noma Security. The broader lesson is that manual guardrails alone cannot govern fast-growing agent fleets, especially where access, data exposure, and policy coverage are already hard to measure.

NHIMG editorial — based on content published by Noma Security: Kantar's AI agent discovery and red teaming journey

By the numbers:

  • 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%).

Questions worth separating out

Q: How should security teams govern AI agents that can access enterprise systems?

A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring.

Q: Why do AI agents create more risk than traditional automation?

A: AI agents create more risk because they can interpret context, choose actions, and invoke tools autonomously.

Q: What do security teams get wrong about prompt guardrails?

A: Teams often treat prompt guardrails as if they were authorisation controls, but they are only one layer of defence.

Practitioner guidance

  • Build a live agent inventory Catalogue every AI agent, model, and connected data source across business teams, then assign ownership and review cadence.
  • Tie policy enforcement to runtime behaviour Move beyond static guardrails by checking how agents actually behave under multi-turn prompts, tool calls, and data access attempts.
  • Adopt mapped adversarial testing for agents Test agent applications against recognised attack techniques so findings are repeatable, comparable, and auditable across releases.

What's in the full article

Noma Security's full post covers the operational detail this post intentionally leaves for the source:

  • Step-by-step explanation of how Kantar integrated AI discovery into developer and data science workflows.
  • Examples of the adversarial test process used to catch multi-turn prompting issues before production release.
  • Operational detail on how the security score improved from 65 percent to 85 percent across iterative testing.
  • Discussion of how the team used dashboards to make findings actionable for developers and data scientists.

👉 Read Noma Security's analysis of Kantar's AI agent discovery and red teaming journey →

AI agent sprawl at Kantar: what security teams should take away?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 2 months ago
Posts: 11961
 

AI agent sprawl creates a governance problem, not just a model-risk problem. Once business teams can deploy agents independently, the control surface expands faster than policy teams can classify it. The issue is not simply that models may be unsafe, but that the enterprise now has distributed, semi-independent actors with data access and tool reach. Practitioners should treat every agent fleet as a governed identity estate, not an isolated AI project.

A question worth separating out:

Q: Which governance evidence should compliance teams expect for AI agents?

A: Compliance teams should expect an inventory of agents, a record of what data they can access, mapped test results against known attack techniques, and a remediation trail for failed findings. That evidence shows whether policy is operating in practice, not just whether it exists on paper.

👉 Read our full editorial: AI agent sprawl forces Kantar to rethink discovery and testing



   
ReplyQuote
Share: