TL;DR: AI adoption is already moving into production, but security and compliance are now the main reasons programmes stall, with 37% of enterprises citing them as the top blocker and AI-related breaches costing 4.8 million USD on average, according to LEVO. The central issue is that AI risk now lives inside runtime behaviour, so governance needs agent identity, continuous visibility, and enforced access controls rather than perimeter-only review.
NHIMG editorial — based on content published by LEVO: AI security as the blocker to production adoption
By the numbers:
- 37% of enterprises cite security and compliance as the number one reason AI initiatives slow down or fail to reach production.
- More than 80% of enterprises report that AI agents access sensitive data, often daily.
Questions worth separating out
Q: What breaks when AI agents are given access without identity governance?
A: What breaks is accountability.
Q: Why do AI agents that exceed their intended scope create security and compliance risk?
A: AI agents create risk when they can read, move, or disclose data without the same controls applied to human users.
Q: How can organisations tell whether their AI security model is actually working?
A: They should test whether the control stack can explain who acted, what data was touched, and what purpose the action served.
Practitioner guidance
- Define first-class agent identities Assign each AI agent a unique identity, owner, and policy scope so actions can be attributed, audited, and revoked like any other privileged actor.
- Enforce least privilege on tool access Limit every agent to the minimum APIs, datasets, and MCP-connected services required for the task, and remove broad default permissions before production rollout.
- Instrument runtime monitoring and alerting Monitor prompts, tool calls, data movement, and policy decisions in production so abnormal behaviour can be detected while the session is active.
What's in the full article
LEVO's full analysis covers the operational detail this post intentionally leaves for the source:
- Specific runtime security patterns for prompt injection, data leakage, and agent misuse in production environments
- Operational guidance on how AI security and compliance controls affect pilot-to-production decisions
- Examples of where autonomous agents access sensitive data and how that changes governance expectations
- The source's broader discussion of why security guardrails determine whether AI delivers ROI
👉 Read LEVO's full analysis of AI security as the blocker to production adoption →
AI security gaps and runtime control: what practitioners need now?
Explore further
AI governance debt is now an enterprise blocker: organisations that treat AI security as a later-stage control accumulate operational debt that directly slows production adoption. The article shows that security and compliance are no longer afterthoughts but gating criteria for deployment, especially where agents can access internal data and tools. That means AI programmes now fail or scale based on governance maturity as much as model capability. The practitioner conclusion is straightforward: if governance cannot prove control, AI will stay trapped in pilot status.
A question worth separating out:
Q: Should organisations prioritise AI agent governance before expanding autonomous workflows?
A: Yes. The article shows that AI creates both faster discovery and deeper trust exposure, so scaling autonomy without governance multiplies risk. Teams should establish ownership, visibility, and behavioural control first, then expand only where they can explain the agent’s access, decisions, and downstream effects.
👉 Read our full editorial: AI security gaps are slowing adoption and raising breach costs