TL;DR: AI adoption moved from chatbots to execution-capable agents in 2025, with 80% of organisations reporting AI agents already acted beyond intended scope and 98% planning more deployments, according to SailPoint's AI Agents: The New Attack Surface report. The governance gap is no longer theoretical: identity, access, and data controls must account for systems that can plan, call tools, and persist across workflows.
NHIMG editorial — based on content published by Straikerai: 10 Hard-Won Lessons from building an AI Security company in 2025
By the numbers:
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%).
Questions worth separating out
Q: What breaks when AI agents are treated like standard human users?
A: You lose visibility into effective permissions, expected behaviour, and real blast radius.
Q: Why do AI agents complicate existing IAM and PAM controls?
A: AI agents complicate IAM and PAM because they often inherit delegated credentials, operate across multiple systems, and keep acting after the initial approval moment has passed.
Q: How do security teams know if AI governance is working?
A: Look for evidence that access decisions are reviewable, permissions are revocable, and exceptions are not becoming permanent.
Practitioner guidance
- Define every AI agent as a governed identity Assign an owner, business purpose, permission scope, and review cycle to each agent that can act in production.
- Limit tool chaining and delegated reach Prevent agents from moving from one system to another without explicit policy checks.
- Instrument downstream actions, not just prompts Log tool calls, API invocations, data reads, and state changes so you can reconstruct what the agent actually did.
What's in the full article
Straikerai's full blog post covers the operational detail this post intentionally leaves for the source:
- Specific examples of how AI agents are changing security buying decisions across enterprise teams
- The vendor's incident references and market observations that underpin its 2025 reflections
- How the company maps its own agentic security work to red teaming and guardrails
- The consolidation examples it cites to explain why the AI security market is moving quickly
👉 Read Straikerai's reflections on AI security, autonomous agents, and market consolidation →
AI agents and enterprise controls: what security teams are missing?
Explore further
AI agents are becoming non-human identities whether enterprises label them that way or not. Once a system can plan tasks, call tools, and persist across workflows, it needs identity governance rather than only application oversight. That makes AI agent identity a governance problem as much as a security one, because access, responsibility, and audit trails must all attach to the same runtime actor. Practitioners should govern agents as bounded identities, not as background automation.
A question worth separating out:
Q: Who is accountable when an AI agent accesses sensitive data it was not meant to use?
A: Accountability sits with the team that approved the agent, its connectors, and its policy boundaries, not with the runtime behaviour alone. Organisations need ownership for intent, permissions, monitoring, and validation so they can prove whether the agent stayed inside its approved purpose. Without that, audit and regulatory response become retrospective guesswork.
👉 Read our full editorial: AI agent governance is colliding with enterprise security controls