TL;DR: GenAI awareness training must now address shadow AI, hallucinations, deepfake-enabled social engineering, and AI agents that can exceed intended scope, because blended human and machine risk creates new exposure paths faster than traditional training can absorb, according to Living Security Human Risk Management Platform. The security implication is clear: governance has to move from awareness-only messaging to role-specific controls, visibility, and human-in-the-loop response.
NHIMG editorial — based on content published by Living Security Human Risk Management Platform: 5 Gen AI Risks Your Awareness Training Must Cover
By the numbers:
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%).
Questions worth separating out
Q: How should security teams govern AI features embedded in SaaS applications?
A: Treat embedded AI as a machine identity problem with data access implications.
Q: Why do AI agents create more governance risk than ordinary integrations?
A: AI agents can connect quickly, run continuously, and accumulate broad permissions across multiple services.
Q: What do security teams get wrong about Shadow AI?
A: They often treat Shadow AI as an approval problem for software, when it is usually also an identity problem.
Practitioner guidance
- Inventory sanctioned and unsanctioned AI tools Build an approved AI register that ties each tool to business purpose, data classes allowed, and the identity controls that govern access.
- Treat AI agents as managed non-human identities Assign each agent a named owner, explicit task scope, and least-privilege access boundaries.
- Use role-specific simulations for GenAI risk Target training scenarios to the actual failure modes each team faces, such as finance deepfake fraud, developer code leakage, or analyst over-trust in generated output.
What's in the full article
Living Security Human Risk Management Platform's full blog post covers the operational detail this post intentionally leaves for the source:
- Role-specific GenAI awareness examples for finance, development, and security teams
- The article's full treatment of shadow AI, hallucinations, bias, and deepfake-enabled social engineering
- Practical guidance on human-in-the-loop oversight and how Living Security frames predictive risk correlation
- The vendor's explanation of how HRM connects behaviour, identity, and threat data in one programme
GenAI awareness training and AI agent risk: what changed?
Explore further
Shadow AI is now an identity governance problem, not just a policy problem. The article correctly treats unapproved AI usage as a data-leak risk, but the deeper issue is that unsanctioned tools create unmanaged identity paths between employees, SaaS apps, and external models. Once access is informal, the enterprise loses lifecycle control over what the tool can see, retain, or reuse. The governance lesson is that AI usage must be treated as part of identity governance, not a separate awareness campaign.
A question worth separating out:
Q: How do you know if GenAI training is actually reducing risk?
A: Look for changes in behaviour, not just course completion. Useful indicators include fewer policy violations, better verification in high-risk workflows, reduced use of unsanctioned AI tools, and improved alignment between identity logs, threat signals, and the actions employees or agents actually take.
👉 Read our full editorial: GenAI awareness training now has to cover agent risk