TL;DR: AI agents are spreading across enterprise SaaS, cloud, and endpoint environments, with more than 80% of Fortune 500 companies already deploying autonomous systems, according to Zenity; Gartner naming Zenity a Cool Vendor in Agentic AI TRiSM reflects a wider shift. The security problem is no longer prompt filtering, but governing what agents can access, decide, and do in real time.
Editorial analysis by NHI Mgmt Group, based on content published by Zenity: “Zenity Named a 2025 Cool Vendor in Gartner’s Agentic AI TRiSM Report”.
Key questions
Q: What breaks when AI agents are not governed at runtime?
A: Without runtime governance, an agent can shift behaviour after provisioning and still execute actions that were never reviewed in context.
Q: Why do AI agents create different access review risks than ordinary cloud workloads?
A: AI agents change the review problem because they combine machine speed, delegated permissions, and dynamic invocation patterns.
Q: What are the signs that AI governance is failing in the enterprise?
A: Common warning signs include rapid growth in AI use without matching policy coverage, sensitive files being copied into personal accounts, and a large share of AI apps carrying high or critical risk.
Practitioner guidance
- Inventory AI agents as governable identities Build an inventory of all agents across SaaS, cloud and endpoint environments, then record which data, tools and systems each one can reach.
- Bind permissions to agent lifecycle stages Apply security-by-design controls before deployment and review them again when an agent changes memory, tools or data scope.
- Monitor full execution paths for unsafe actions Instrument step-level telemetry so you can detect when a benign request turns into a chain of risky tool calls, external API access or data movement.
Bottom line: Agentic AI changes the identity problem from checking prompts to governing runtime authority, which makes traditional application security an incomplete control model.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Agentic AI TRiSM widens the governance gap because the control problem has moved from input moderation to runtime authority. Traditional security programmes were designed to inspect prompts, sessions or isolated requests. That model fails when the actor can decide which tool to call next and when to do it. The implication is that identity governance has to treat agent execution as the unit of control, not the prompt.
A few things that frame the scale:
- 69% of security leaders agree identity management must fundamentally shift to address agentic AI systems, according to the 2026 Infrastructure Identity Survey.
- Gartner predicts that more than 40% of agentic AI projects will be cancelled by the end of 2027, citing rising costs, unclear value and insufficient risk controls.
A question worth separating out:
Q: How should IAM teams govern humans, NHIs, and AI agents in one programme?
A: Start by separating the control assumptions for each actor type. Humans need authentication and access review, NHIs need lifecycle control and secret governance, and AI agents need runtime scope enforcement because their tool use can change during execution. One programme can cover all three, but the policy model cannot treat them as interchangeable identities.
👉 Read our full editorial: Gartner’s agentic AI TRiSM signal widens the NHI governance gap