TL;DR: AI TRiSM is shifting from documentation and policy-setting into runtime inspection, cataloging, and enforcement for AI models, applications, and agents, according to Akto’s analysis of Gartner guidance. That change matters because static governance cannot reliably control agentic systems that act in real time across data, tools, and approvals.
NHIMG editorial — based on content published by Akto: AI TRiSM Explained, building secure and trusted AI systems
By the numbers:
- According to Gartner, organizations that operationalize AI transparency, trust, and security within their AI initiatives can expect a 50% improvement in AI adoption, business goal attainment, and user acceptance.
- When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes - and as quickly as 9 minutes in some cases.
Questions worth separating out
Q: How should organisations enforce AI TRiSM for agentic AI systems?
A: Start with runtime controls, not policy documents.
Q: Why do AI agents create more governance risk than ordinary integrations?
A: AI agents can connect quickly, run continuously, and accumulate broad permissions across multiple services.
Q: What breaks when AI cataloguing is missing?
A: Security teams lose visibility into what AI systems exist, what data they touch, and who owns them.
Practitioner guidance
- Implement runtime policy enforcement for AI interactions Block or escalate unsafe AI inputs, outputs, and tool calls at the point of execution rather than relying on post-hoc review.
- Build an enterprise AI catalog with ownership and lineage Inventory every model, application, agent, MCP connection, and third-party AI integration, then assign an owner, a purpose, and a data boundary to each one.
- Map AI data exposure to identity and access pathways Trace which datasets, secrets, service accounts, and tokens support each AI system, especially where retrieval, fine-tuning, or delegated tool use is involved.
What's in the full article
Akto's full post covers the operational detail this post intentionally leaves for the source:
- A deeper breakdown of AI TRiSM pillars and how they map to model, application, and agent governance
- Examples of runtime inspection and enforcement patterns for AI interactions and policy violations
- The article's comparison of AI TRiSM with responsible AI, AI governance, and AI security
- Implementation guidance for moving from documentation-led governance to enforceable technical controls
👉 Read Akto's analysis of AI TRiSM and secure AI systems →
AI TRiSM and agentic AI governance: are your controls keeping up?
Explore further
AI TRiSM is becoming the operational layer that AI governance has lacked. Policy documents define intent, but agentic systems need controls that inspect behaviour at runtime. The article correctly shows that cataloguing, data mapping, and enforcement must work together if AI systems are to be governed as living services rather than static artefacts. For practitioners, the lesson is that governance without runtime enforcement is incomplete.
A question worth separating out:
Q: Who is accountable when an AI system makes a harmful decision?
A: Accountability should follow the identity chain that authorized, configured, or triggered the action, including the human owner, the platform team, and any delegated agent or tool account. If the organisation cannot name that chain, the governance model is too weak for regulated AI use.
👉 Read our full editorial: AI TRiSM is moving from policy to runtime enforcement