Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Human risk management and AI agents: what changes for security teams?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18936
Topic starter  

TL;DR: The real shift in HRM is not a new label but a measurable operating model, citing Cyentia data showing SAT-only programmes see about 12% of workforce risk while mature HRM reaches roughly 5x greater visibility, according to Living Security Human Risk Management Platform. The post also says HRM is evolving to cover AI agents as non-human identities, which makes connected signals and closed-loop remediation more important than awareness training alone.

NHIMG editorial — based on content published by Living Security Human Risk Management Platform: Human Risk Management Mythbusters: Where We Agree, and What Comes Next

By the numbers:

Questions worth separating out

Q: How should security teams measure whether human risk management is actually reducing risk?

A: Use outcome metrics, not just participation data.

Q: Why do AI agents complicate IAM and data security controls?

A: Because the core controls were built for human sessions and file-centric data movement, while agents act continuously, inherit permissions, and reason over data in context.

Q: What do organisations get wrong about awareness training and human risk?

A: They often treat training completion as the same thing as reduced risk.

Practitioner guidance

  • Implement closed-loop human risk workflows Link risk scoring to remediation actions such as access review, MFA enforcement, coaching, and policy-triggered containment so the programme changes outcomes rather than reporting them.
  • Extend governance to AI agents as non-human identities Define ownership, acceptable behaviour, and escalation paths for agents that use enterprise credentials, then place those agents under the same review discipline used for other privileged identities.
  • Prioritise the highest-risk populations first Use concentration analysis to identify the small user or agent groups generating most exposure, then focus controls where reduction will be measurable fastest.

What's in the full article

Living Security Human Risk Management Platform's full blog post covers the operational detail this post intentionally leaves for the source:

  • The article’s full breakdown of the six HRM myths and how each one maps to programme design decisions.
  • The supporting Cyentia Institute findings behind the visibility, remediation, and behaviour data quoted in the post.
  • The source’s discussion of how agent coverage fits into HRM without turning the category into a new acronym.
  • The company’s closing view on how HRM should evolve as AI agents become part of the workforce.

👉 Read Living Security Human Risk Management Platform's analysis of HRM myths and AI agent scope →

Human risk management and AI agents: what changes for security teams?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 18527
 

Human risk management is becoming an identity governance problem, not just a people problem. Once behavioural signals are tied to access, exposure, and remediation, the programme stops being a soft control and becomes part of the identity control stack. That matters because the same governance logic now applies across users, service accounts, and agents. The practitioner conclusion is straightforward: HRM should be measured alongside IAM outcomes, not treated as a separate awareness function.

A question worth separating out:

Q: How should organisations govern human, machine, and AI agent access in one programme?

A: Organisations should govern all three through one identity model, but with actor-specific controls for provisioning, review, and revocation. Human access still relies on authentication and lifecycle processes, machine identities need secret and credential governance, and AI agents need runtime authority boundaries. The goal is consistent ownership and auditability across different actors.

👉 Read our full editorial: Human risk management now spans people, agents, and AI systems



   
ReplyQuote
Share: