Join our Newsletter — 33% off our NHI Course

Legacy IT and agentic AI governance: what breaks first?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: As AI tools spread across departments, legacy IT becomes a control and visibility bottleneck, with JumpCloud citing that 37% of IT professionals see unauthorized access by automated agents as a serious threat and more than 50% of enterprises say legacy IT slows scaling. Old identity and device foundations no longer match the pace of agentic adoption.

Editorial analysis by NHI Mgmt Group, based on content published by JumpCloud: “Unanchoring Legacy IT to Secure the Agentic Future”.

By the numbers:

  • Over 50% of enterprises find legacy IT actively slows their ability to scale.

Key questions

Q: How should security teams govern AI use in developer tooling?

A: Security teams should govern AI use as a data and access problem, not only a productivity feature.

Q: Why do legacy systems create more risk as agentic AI spreads?

A: Legacy systems create risk because they fragment ownership, permissions and audit trails across tools that were never designed to coordinate at machine speed.

Q: What are the signs that AI governance controls are not keeping pace with adoption?

A: Common warning signs include unclear ownership for AI use cases, inconsistent approval processes, limited visibility into where sensitive data enters models, and weak evidence for audits or assessments.

Practitioner guidance

  • Consolidate identity and device governance Build a shared control plane for users, devices and automated tools so permissions and trust state are visible in one place.
  • Review departmental AI tool access Inventory locally adopted AI tools, then map which identities can access data, systems and delegated actions outside central approval flows.
  • Align interoperability with authorisation Apply explicit permission checks and logging to MCP and A2A-connected workflows so collaboration does not outpace governance.

Bottom line: Legacy infrastructure weakens agentic AI governance because it splits identity, device and permission control across systems that do not move at the speed of AI adoption.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Legacy identity tooling is the wrong control plane for agentic work. The article is really describing an identity governance failure, not just an IT modernization problem. When access decisions are split across legacy systems, AI tooling, and departmental shadow adoption, no single control plane can reliably answer who or what is acting. Practitioners should treat that fragmentation as the core risk surface, not the surrounding productivity story.

A few things that frame the scale:

  • 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job, according to The 2026 Infrastructure Identity Survey.
  • Only 13% of organisations feel extremely prepared for the reality of agentic AI despite the majority racing toward autonomous adoption.

A question worth separating out:

Q: Who should be accountable when departmental AI tools access sensitive systems?

A: Accountability should sit with the business owner, the platform owner, and the identity team together, because no single group can explain the full access chain alone. The owner must justify the access, security must constrain it, and IAM must be able to attest it. Without that shared model, governance becomes symbolic rather than operational.

👉 Read our full editorial: Legacy infrastructure is the bottleneck in agentic AI governance



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Legacy IT has become a governance bottleneck, not just an efficiency drag: The article is right to frame old infrastructure as a control problem because fragmented data, manual workflows and siloed tools make it hard to know what is connected, who approved it and what it can reach. That is exactly where agentic adoption collides with identity governance. The practitioner conclusion is simple: if visibility is weak at the foundation, AI scale will amplify the weakness rather than mask it.

A few things that frame the scale:

  • Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: How should organisations balance interoperability with permission control in agentic AI?

A: Treat interoperability as a governance requirement, not just an integration feature. Standard protocols make it easier for AI tools to collaborate, but that collaboration must still be constrained by authorisation, logging and scope review so the organisation can see and limit what each tool can do.

👉 Read our full editorial: Legacy infrastructure is the bottleneck in agentic AI governance


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.