TL;DR: Enterprises are now managing AI agents, applications, service accounts, and other non-human identities at machine speed, with unanswered questions around inventory, access, and accountability, according to Saviynt. The core issue is not visibility alone but whether identity governance can keep pace with autonomous behaviour, runtime authorization, and lifecycle control.
NHIMG editorial — what this means for NHI practitioners
By the numbers:
- 96% of technology professionals identify AI agents as a growing security threat, and 66% believe this risk is immediate.
Questions worth separating out
Q: How should security teams govern AI agents that can access enterprise systems?
A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring.
Q: Why do service accounts and AI agents create different identity risk than employees?
A: Service accounts and AI agents create different risk because they are not managed through HR lifecycle events, yet they often hold broad technical permissions and can act at machine speed.
Q: What breaks when identity governance relies only on access reviews?
A: Access reviews assume the reviewable state is a stable entitlement that reflects real risk.
Practitioner guidance
- Inventory AI agents and non-human identities continuously Build a live registry that ties each AI agent to its owner, purpose, connected systems, and current permissions.
- Move high-risk AI actions to runtime authorization Require policy checks at the moment an agent attempts sensitive actions such as data export, privilege escalation, customer interaction, or cross-system writes.
- Separate agent governance from service account administration Do not treat AI agents as ordinary workload identities with a new label.
What's in the full announcement
Saviynt's full product announcement covers the operational detail this post intentionally leaves for the source:
- The platform's discovery model for consolidating AI agents, applications, owners, and permissions into a single registry.
- The runtime authorization flow behind Intent-Aware Runtime Authorization and how it evaluates a specific action before it runs.
- The governance workflow for access reviews, audit trails, and lifecycle records across AI identities and non-human identities.
- The integration footprint across enterprise AI ecosystems such as AWS Bedrock, Azure Foundry, Agentforce, and Snowflake Cortex.
👉 Read Saviynt's announcement on Zuma for AI identity security →
AI identity security: are your controls ready for agents and NHI?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
AI identity governance has moved from a visibility problem to a runtime control problem. The article correctly centres discovery, authorization, and lifecycle management, because AI agents are not governed well by static access assignment alone. Once agents can act at machine speed across multiple systems, the critical question becomes whether every action is evaluated in context before it executes. Practitioners should treat runtime decisioning as a first-class identity control, not an optional enhancement.
A few things that frame the scale:
- 98% of companies plan to deploy even more AI agents within the next 12 months, despite documented rogue behaviour in 80% of current deployments, according to AI Agents: The New Attack Surface report.
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, inappropriately sharing sensitive data, and revealing access credentials.
A question worth separating out:
Q: Who should be accountable for AI agent actions in enterprise systems?
A: Accountability should sit with the team that owns the agent, its policies, and the connected tools, not only with the person who typed the original prompt. When a software actor can send messages, update records, and move data across systems, responsibility must follow the governed identity and its enforcement layer.
👉 Read our full editorial: AI identity security now spans agents, workloads, and human control