TL;DR: AI risk management must move from periodic review to continuous control because AI systems now introduce bias, privacy exposure, hallucination, and tool-use risk across the lifecycle, according to Holistic AI. The governance gap is no longer theoretical: 87% of organisations report AI-driven cyberattacks, and current oversight models are too static for adaptive systems.
NHIMG editorial — based on content published by Holistic AI: AI Risk Management: A Strategic Imperative for the Modern Enterprise
By the numbers:
- 87% of organisations say they have already been hit by AI-driven cyberattacks in the past year.
- 80% of organisations report their AI agents have already performed actions beyond their intended scope.
Questions worth separating out
Q: Why do AI governance controls often fail after launch?
A: They usually fail because approval-time review is treated as the finish line.
Q: When should organisations treat an AI agent as a privileged system?
A: Organisations should treat an AI agent as privileged whenever it can reach production data, administrative tools, or sensitive workflows without direct human approval for each step.
Q: What do security teams get wrong about AI access risk?
A: Many teams focus on the model while ignoring the identity path that reaches it.
Practitioner guidance
- Define AI inventory boundaries Create a live inventory of models, copilots, embedded AI features, and autonomous agents, including owners, data sources, tool access, and deployment environments.
- Scope agent tool access as privileged access Treat every AI agent integration as a privileged path and apply least privilege, just-in-time approvals where possible, and revocation controls for broad or persistent permissions.
- Add continuous testing to production AI Test for prompt injection, data leakage, jailbreak behaviour, and drift after release, then tie failures to a documented escalation path and remediation workflow.
What's in the full article
Holistic AI's full blog covers the operational detail this post intentionally leaves for the source:
- A lifecycle-by-lifecycle breakdown of AI governance controls from development through decommissioning
- Specific mitigation patterns for prompt injection, data leakage, and runtime guardrails in production AI
- Practical guidance on mapping AI systems to the EU AI Act and NIST AI Risk Management Framework
- Program design detail for inventorying shadow AI and embedding governance into MLOps and DevSecOps
👉 Read Holistic AI's analysis of AI risk management and governance controls →
AI risk management and governance gaps: what teams need now?
Explore further
AI risk management is now an identity and access governance problem as much as a model-risk problem. Once AI systems can read data, call tools, or act on behalf of users, the question becomes who authorised the action path and how that authority is constrained. That shifts the control boundary toward IAM, PAM, and lifecycle governance, especially where agentic AI can execute without real-time human approval. Practitioners should treat AI governance as delegated access management with stronger evidence requirements.
A question worth separating out:
Q: How should organisations govern external tools used by AI agents?
A: Organisations should review external tools as security inputs, not convenience features. Each tool needs ownership, approval, metadata inspection, and ongoing monitoring for hidden instructions or unexpected behaviour. If an AI agent can act on a tool, then the tool’s provenance and control status should be governed like any other sensitive integration.
👉 Read our full editorial: AI risk management is becoming an enterprise control problem