Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AI governance frameworks: are agent identities getting enough control?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: AI governance frameworks are increasingly defined by policy, monitoring, and accountability controls, but enterprise practice still leaves a gap around agent permissions, workflow visibility, and runtime guardrails, according to Akto and broader governance guidance. The real issue is not whether governance exists, but whether it governs dynamic AI behaviour before it becomes operational risk.

NHIMG editorial — based on content published by Akto: AI Governance Framework: Building Responsible AI Systems

By the numbers:

Questions worth separating out

Q: How should security teams govern agentic AI as it moves into production?

A: Security teams should govern agentic AI as a class of non-human identity, not as a generic application feature.

Q: Why do AI agents create a governance problem for IAM teams?

A: AI agents create a governance problem because they authenticate and act as autonomous software entities with tool access.

Q: What breaks when AI governance relies only on fixed rules?

A: Fixed rules break when the same model is used by different people for different purposes with different data.

Practitioner guidance

  • Tie AI policies to enforced identity controls Map every governance rule to a specific control for AI agents, service accounts, tokens, and API access.
  • Scope agent permissions to task boundaries Limit tool access, data access, and workflow reach to the minimum required for the current job.
  • Instrument full workflow observability Log prompts, tool calls, data transfers, approvals, and exceptions so governance and incident response teams can reconstruct what happened.

What's in the full article

Akto's full blog post covers the operational detail this post intentionally leaves for the source:

  • Concrete examples of how to structure AI governance across policy, technical, and operational layers
  • Implementation detail for runtime guardrails, monitoring, and audit logging in AI workflows
  • Security control patterns for agent permissions boundaries and tool access restrictions
  • Practical guidance on embedding governance checks into CI/CD for AI systems

👉 Read Akto's analysis of AI governance frameworks and responsible AI security controls →

AI governance frameworks: are agent identities getting enough control?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

AI governance is becoming an identity governance problem the moment AI systems can act. The article correctly treats governance as policy, accountability, and oversight, but that frame is incomplete unless agent permissions and credentials are brought into scope. Once an AI system can invoke tools or move data, it becomes a governed actor in practice, even if it is not an autonomous system in the strictest sense. Practitioners should treat agent identity and access as part of the governance operating model.

A question worth separating out:

Q: Which frameworks should organisations use for autonomous AI governance?

A: Use OWASP agentic and LLM guidance for application risk, NIST AI RMF for governance structure, and MITRE ATLAS for adversarial technique mapping. Then translate those frameworks into operational controls that restrict tool access, define approval boundaries, and produce auditable runtime evidence. Frameworks help classify the risk, but enforcement must happen in execution.

👉 Read our full editorial: AI governance frameworks still leave agent identities under-governed



   
ReplyQuote
Share: