TL;DR: Generative AI is expanding both attack capability and defensive opportunity, with Living Security Human Risk Management Platform arguing that security teams must move from reactive detection to predictive controls across behavior, identity, and threat signals. The broader lesson is that AI security now depends on governing both people and AI agents, not just filtering prompts.
NHIMG editorial — based on content published by Living Security Human Risk Management Platform: A Guide to AI Cybersecurity for Generative AI Applications
By the numbers:
- 80% of identity breaches involved compromised non-human identities such as service accounts and API keys.
- Only 5.7% of organisations have full visibility into their service accounts.
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface.
Questions worth separating out
Q: How should security teams govern AI agents that can access enterprise systems?
A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring.
Q: Why do generative AI tools create non-human identity risk?
A: Generative AI tools create NHI risk because they often have access to corporate data, APIs, and workflows while operating outside traditional user-account models.
Q: What do teams get wrong about AI security awareness training?
A: They treat it as a substitute for governance.
Practitioner guidance
- Define AI agent ownership and scope Assign every production AI agent a named business owner, an explicit task boundary, and a documented approval path for high-risk actions.
- Correlate identity, behaviour, and threat signals Join identity events, user behaviour telemetry, and threat intelligence into a single risk workflow so analysts can spot pattern-based attacks earlier.
- Test for synthetic social engineering exposure Run phishing and deepfake simulations against finance, service desk, and executive workflows to measure whether verification steps actually work under pressure.
What's in the full article
Living Security Human Risk Management Platform's full blog covers the operational detail this post intentionally leaves for the source:
- Specific examples of AI-powered phishing, deepfake, and malware scenarios used to illustrate human-risk exposure.
- Operational guidance on using machine learning to correlate behaviour, identity, and threat intelligence across security workflows.
- Examples of synthetic data use in security model training without exposing sensitive information.
- Additional context on how Human Risk Management is positioned for AI agents and employee behaviour programs.
Generative AI security: what it means for human risk management?
Explore further
Predictive security is becoming the only defensible posture for AI-heavy enterprises. Traditional detect-and-respond models assume the attacker leaves a clean trail after the fact. Generative AI collapses that assumption by increasing attack speed, content quality, and scale at once. Security programmes that correlate behaviour, identity, and threat signals can intervene earlier, which is why predictive control is now a governance issue, not just an analytics preference.
A question worth separating out:
Q: How can organisations reduce the risk of deepfake-driven social engineering?
A: They can reduce risk by combining user education, high-assurance verification, approval segregation, and incident escalation rules. The goal is to make it difficult for a convincing fake to move directly from perception to action. Any process that depends on belief alone is too easy to exploit.
👉 Read our full editorial: AI cybersecurity for generative AI demands predictive human risk