TL;DR: AI agents now need lifecycle governance across discovery, policy, detection, prevention, and response, according to Zenity, underscoring Zenity’s recognition in the CyberSecurity Breakthrough Awards. The bigger signal is that agent behaviour, tool invocation, and access scope are becoming identity governance problems, not just application security problems.
Editorial analysis by NHI Mgmt Group, based on content published by Zenity: “Zenity Named “Agentic AI Security Solution of the Year” in 9th Annual CyberSecurity Breakthrough Awards Program”.
Key questions
Q: What breaks when AI agents are treated like standard human users?
A: You lose visibility into effective permissions, expected behaviour, and real blast radius.
Q: Why do AI agents create new risk in non-human identity management?
A: AI agents create risk because they operate as software identities with delegated authority, but many organisations do not track them with the same discipline applied to users or service accounts.
Q: How do security teams know if AI governance is working?
A: Look for evidence that access decisions are reviewable, permissions are revocable, and exceptions are not becoming permanent.
Practitioner guidance
- Map AI agents to governance owners Assign explicit ownership for each agent across business, security, and platform teams so there is a clear account for discovery, approvals, monitoring, and retirement.
- Separate tool permissions from model access Review every agent to ensure access to tools, connectors, and data is constrained independently from the model or application account it runs under.
- Track agent posture continuously Instrument detection for changes in reachable tools, data scope, and workflow position so posture is measured during operation, not only at onboarding.
Bottom line: AI agents turn access governance into a runtime problem because their tool use and execution paths change inside the workflow.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Agentic AI governance is now an identity discipline, not an adjacent security concern. The announcement reflects a broader market reality: once AI agents can act across SaaS, cloud, and endpoint environments, their behaviour becomes an access problem. Traditional application security does not answer who controls the agent, what it can invoke, or how its authority should be bounded across a workflow. The practitioner implication is that identity governance must expand to cover agent capability, execution context, and tool reach.
A few things that frame the scale:
- 69% of security leaders agree identity management must fundamentally shift to address agentic AI systems, according to the 2026 Infrastructure Identity Survey.
- 88% of organisations have embedded AI agents in their workflows, according to KPMG's 2026 report.
A question worth separating out:
Q: How can organisations tell whether an AI agent is acting outside its intended scope?
A: Organisations should look for behaviour that crosses expected tool boundaries, generates unusual credentials, or chains actions across systems that are not part of the original task. The signal is not simply high activity. It is a change in action pattern, delegation, or downstream access context.
👉 Read our full editorial: Zenity’s agentic AI security award spotlights governance needs