Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AI security risk assessments are rising fast, but what still breaks?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15754
Topic starter  

TL;DR: AI security risk assessments have nearly doubled year over year, rising from about 37% to 64%, while 87% of organisations say AI-related vulnerabilities increased, according to AppSOC’s analysis of World Economic Forum and SC Media reporting. The real problem is that many assessments remain one-time exercises, leaving AI and agent risk to drift out of governance between reviews.

NHIMG editorial — based on content published by AppSOC: AI Security Risk Assessments Are Increasing, But the Real Risk Is Still Growing

By the numbers:

Questions worth separating out

Q: What breaks when AI security is handled only at launch time?

A: Controls go stale as the system changes.

Q: Why do local AI agents complicate identity and access management?

A: They can retain legitimate permissions while changing timing, prioritisation, and action sequence outside human presence.

Q: How do security teams know if AI governance is working?

A: Look for evidence that access decisions are reviewable, permissions are revocable, and exceptions are not becoming permanent.

Practitioner guidance

  • Tie AI risk reviews to change events Require reassessment whenever a model, plugin, retrieval source, or permission set changes.
  • Register every AI agent as a governed identity Assign an owner, a scoped purpose, and a permission boundary to each agent or AI-enabled workflow.
  • Reduce standing access before scaling AI use Remove broad read and write permissions from AI systems and limit them to the minimum APIs, datasets, and actions required for the task.

What's in the full article

AppSOC's full article covers the operational detail this post intentionally leaves for the source:

  • The exact breakdown of why the vendor believes AI assessments are not keeping pace with live system change.
  • Context on how organisations are shifting from post-incident review toward pre-deployment and ongoing evaluation.
  • The article's full discussion of AI agents, over-privileged access, and the operational consequences of delegated tool use.
  • The vendor's framing of how security, engineering, and leadership ownership should be aligned for AI risk governance.

👉 Read AppSOC's analysis of why AI security risk assessments still lag behind real-world AI change →

AI security risk assessments are rising fast, but what still breaks?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15339
 

AI governance debt is now an access problem, not just a review problem: the article shows that AI risk keeps changing after launch, which means governance cannot stop at initial approval. Once models, tools, and agents are wired into live systems, the programme inherits identity and access exposure that needs continuous control. That makes IAM and NHI governance part of AI security by default, not by exception. Practitioners should treat every AI integration as a standing control obligation.

A question worth separating out:

Q: Who is accountable when an AI system makes a harmful decision?

A: Accountability should follow the identity chain that authorized, configured, or triggered the action, including the human owner, the platform team, and any delegated agent or tool account. If the organisation cannot name that chain, the governance model is too weak for regulated AI use.

👉 Read our full editorial: AI security risk assessments are rising, but continuous control still lags



   
ReplyQuote
Share: