TL;DR: AI risk is being normalized through permissive defaults, weak oversight, and repeated success without consequences, creating a culture where unsafe model and agent behaviour starts to look acceptable, according to AppSOC. The deeper problem is not just technical exposure but governance drift, because teams begin treating probabilistic AI outputs and autonomous actions as if they were reliable controls.
NHIMG editorial — based on content published by AppSOC: AI Risk Is Becoming Normal and That Should Worry Us
By the numbers:
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, inappropriately sharing sensitive data, and revealing access credentials.
Questions worth separating out
Q: How should security teams govern AI agents that can access enterprise systems?
A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring.
Q: Why does normalisation of deviance make AI security harder to control?
A: It makes unsafe behaviour look ordinary.
Q: What breaks when organisations rely on permissive AI defaults?
A: They create hidden trust expansion.
Practitioner guidance
- Define AI action boundaries before deployment Document which decisions, tool calls, and data accesses require human review and which are strictly prohibited.
- Treat agents as governed identities Assign owners, scope permissions narrowly, and review revocation paths for every agent that can access internal systems or sensitive data.
- Challenge permissive defaults before production use Audit logging, data access, tool permissions, and approval flows in each AI platform or workflow.
What's in the full article
AppSOC's full article covers the cultural and operational detail this post intentionally leaves at the framing level:
- The Challenger analogy and the social-science explanation of how unsafe practices become normalised inside teams
- The article's discussion of permissive AI defaults and why convenience often outruns security review
- AppSOC's specific recommendations for visibility, adversarial testing, and runtime guardrails in AI workflows
👉 Read AppSOC's analysis of how normalised AI risk leads to unsafe deployment patterns →
AI normalization of deviance: are your controls keeping up?
Explore further
Normalization of deviance is now an AI governance failure mode, not a cultural footnote. The article is right to treat repeated tolerance for unsafe behaviour as the real danger, because AI teams often reclassify risk as acceptable after a series of non-events. That is especially problematic when the system is an agent or workflow that can act on data and tools without human review at every step. Practitioners should treat repeated success as a signal to tighten controls, not relax them.
A question worth separating out:
Q: Who is accountable when an AI agent makes an unauthorised change?
A: Accountability should be assigned to the governance model that authorised the delegation, the owner of the workflow, and the team that set the policy boundary. In practice, organisations need clear responsibility for agent configuration, monitoring, and incident response because the machine’s speed does not remove human accountability for the delegated identity.
👉 Read our full editorial: Normalization of deviance is the real AI security failure mode