TL;DR: AI agents expose a deeper security flaw: most organisations still cannot reliably classify sensitive data or determine who and what can access it, according to Sentra. The decisive control is continuous data readiness, because visibility without classification leaves AI governance blind to the real exposure, and OWASP research says 68% cannot distinguish human from agent activity.
NHIMG editorial — based on content published by Sentra: AI data readiness is the real gap behind agent visibility
By the numbers:
- According to OWASP's 2026 research, 68% of organizations cannot reliably distinguish human activity from AI agent activity.
- According to Sentra, 97% of non-human identities carry excessive privileges in the typical enterprise.
- According to Sentra, the typical enterprise operates roughly 100 non-human identities for every human identity.
Questions worth separating out
Q: How should security teams govern AI agents that can access enterprise systems?
A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring.
Q: Why do AI agents make IAM and NHI risk harder to manage?
A: AI agents can request tools, call APIs, and even create new infrastructure at machine speed, which multiplies identity events and privilege decisions.
Q: What breaks when sensitive data is not classified in GenAI pipelines?
A: Without classification, organisations cannot reliably decide what data is allowed into the model, what must be blocked, or what needs special handling after output.
Practitioner guidance
- Implement continuous data classification Classify sensitive data across cloud, SaaS, collaboration platforms, warehouses, and on-premises repositories as an ongoing process, then tie access decisions to that classification.
- Map all identities that can reach sensitive data Build an access view that includes human users, service accounts, applications, and AI agents so entitlement reviews reflect real exposure rather than siloed inventory.
- Prioritise remediation on overpermissioned data paths Use classification results to remove redundant access, right-size privileges, and reduce reach into customer, HR, finance, and M&A data before AI workflows expand exposure.
What's in the full article
Sentra's full article covers the operational detail this post intentionally leaves for the source:
- Continuous discovery workflow across cloud, SaaS, collaboration platforms, on-premises environments, and data warehouses
- The classification approach using more than 250 classifiers across 130 file formats for structured and unstructured content
- How access paths are mapped for humans, applications, service accounts, and AI agents as data moves into workflows
- The remediation sequence for right-sizing access, identifying stale data, and prioritising cleanup actions
👉 Read Sentra's analysis of why AI agents expose the data governance gap →
AI agent visibility is not enough when data access is unknown?
Explore further
AI visibility without data classification is a governance illusion: counting agents, copilots, and integrations tells practitioners little if they cannot classify the data those systems can reach. The article correctly shifts the control question from inventory to exposure. For IAM, PAM, and NHI programmes, that means privilege management must be anchored to data sensitivity, not just to the presence of an identity.
A question worth separating out:
Q: Who is accountable when an AI agent accesses sensitive data it was not meant to use?
A: Accountability sits with the team that approved the agent, its connectors, and its policy boundaries, not with the runtime behaviour alone. Organisations need ownership for intent, permissions, monitoring, and validation so they can prove whether the agent stayed inside its approved purpose. Without that, audit and regulatory response become retrospective guesswork.
👉 Read our full editorial: AI data readiness is the real gap behind agent visibility