TL;DR: AI security and governance remain split in many enterprises, creating blind spots that let threats slip past compliance processes and leave security teams without policy context, according to Obsidian Security. The gap is now a governance problem as much as a technical one, because integrated controls determine whether AI can be deployed with accountability.
NHIMG editorial — based on content published by Obsidian Security: Bridging the Gap Between AI Security and Governance
By the numbers:
- 73% of organizations experienced at least one AI-related security incident in 2024, with many incidents stemming from governance failures rather than technical vulnerabilities.
- 45% fewer compliance violations were reported by organizations with integrated AI security and governance approaches.
- 60% faster incident resolution times were reported by organizations that integrated AI security and governance.
Questions worth separating out
Q: How should security teams handle delegated access when AI agents act on behalf of customers?
A: Security teams should treat delegated access as a separate governance layer, not as a normal login session.
Q: Why do AI infrastructure programmes create new identity governance risk?
A: They create risk because machine-speed workflows can combine APIs, secrets, and delegated authority faster than conventional review cycles can observe.
Q: What breaks when AI security and compliance are managed separately?
A: Separate management creates inconsistent risk visibility, slower incident handling, and policy drift.
Practitioner guidance
- Unify AI security and governance ownership Create a shared operating model between security, compliance, legal, and AI platform teams for approvals, exceptions, and incident response.
- Inventory AI-linked non-human identities Catalogue every token, service account, OAuth grant, app integration, and agent that can act on behalf of an AI workflow.
- Automate policy-to-control mapping Map AI governance requirements to enforceable controls such as access restrictions, logging, approval workflows, and monitoring thresholds.
What's in the full article
Obsidian Security's full blog post covers the operational detail this post intentionally leaves for the source:
- The article's full lifecycle model for aligning AI security controls with governance checkpoints across deployment stages.
- The detailed maturity stages for moving from basic coordination to automated policy enforcement and continuous compliance.
- The vendor's examples of integrated accountability across CISO, compliance, legal, and MLOps functions.
- The specific product framing for AI Security Posture Management and continuous monitoring of AI workloads.
👉 Read Obsidian Security's analysis of bridging AI security and governance →
AI security and governance gaps: what teams need to align now?
Explore further
AI governance debt is becoming an operational security problem. When organisations add AI faster than they add unified controls, they create a backlog of unresolved risk decisions, undocumented access paths, and missing accountability. The issue is not simply compliance lag. It is a structural mismatch between AI deployment speed and governance cadence, and that mismatch directly affects identity, access, and auditability. Practitioners should treat unresolved AI governance as live security debt.
A question worth separating out:
Q: Who is accountable when an AI agent causes a security incident?
A: Accountability should sit with the business owner, the system owner, and the security function together, because agent behaviour crosses operational boundaries. Organisations need a defined owner for approval, monitoring, and retirement, plus audit evidence that shows what the agent accessed and why.
👉 Read our full editorial: AI security and governance gaps are widening across enterprise AI