Join our Newsletter — 33% off our NHI Course

AI agent governance starts with identity, not model security

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: AI agent incidents are now recurring as governance gaps widen, with Zenity citing CSA’s April 2026 survey showing 74% of enterprises expect more than 100 agents live by year-end, 53% saw agents exceed intended permissions, and 47% had an agent-related incident in the last year. The core failure is treating agents as a model-security problem instead of an identity and access problem.

Editorial analysis by NHI Mgmt Group, based on content published by Zenity: “Securing Enterprise AI in Practice: Why Governance Starts and Ends with Agents”.

By the numbers:

  • 74% of enterprises expect their organizations will have over 100 agents live by the end of 2026.
  • 53% of participants noted that agents exceeded intended permissions or acted out of scope.
  • 47% experienced a security incident involving an agent in the last year.

Key questions

Q: What breaks when AI agents are not governed at runtime?

A: Without runtime governance, an agent can shift behaviour after provisioning and still execute actions that were never reviewed in context.

Q: Why do AI agents create new access risk for enterprises?

A: AI agents create access risk because they can operate with delegated authority while processing untrusted inputs.

Practitioner guidance

  • Inventory every live agent and its delegated scope Track each agent as a governed identity with named owner, approved tools, data reach, and expiry conditions.
  • Move authorisation to runtime decision points Require task-scoped approvals, entitlement checks, or session boundaries for agent actions that touch sensitive systems.
  • Separate model controls from identity controls Document which safeguards address prompt and model behaviour, and which ones govern access, tool use, and delegation.

Bottom line: AI agent governance fails when organisations start with model security and leave identity, delegation, and entitlement scope underdefined.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 2 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21423
 

Identity, not model quality, is the primary governance layer for AI agents. Model security can reduce some classes of abuse, but it does not answer the central question of who or what is authorised to act. Once an agent can invoke tools and traverse workflows, governance must start with identity, delegation, and entitlement scope. The practitioner conclusion is simple: if the access model is wrong, the model quality does not matter.

A few things that frame the scale:

A question worth separating out:

Q: How should security teams compare model security and identity governance for agents?

A: Model security reduces unsafe outputs, but identity governance determines whether the agent is allowed to act at all. They address different failure modes. If the article of record is operational control, identity and delegation need to lead; if the concern is content generation or prompt abuse, model controls matter more.

👉 Read our full editorial: AI agent governance starts with identity, not model security


This post was modified 2 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.