TL;DR: European deployment shifts the conversation from AI availability to governance, with tenant data held in the EU and explicit controls for what agents can access, do, and explain, according to C1.ai. The real issue is not hosting alone but whether organisations can prove authorisation, auditability, and revocation across AI agents and existing NHI estates.
NHIMG editorial — what this means for AI and NHI governance
By the numbers:
- Only 5.7% of organisations have full visibility into their service accounts.
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security.
- 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation.
Questions worth separating out
Q: What should teams do first when agent access starts reaching production systems?
A: Start by reducing blast radius.
Q: Why does EU data residency not solve AI agent governance on its own?
A: Because residency answers where data is held, not who approved access or what the agent can do with it.
Q: How do security teams know if an AI agent has too much access?
A: Look for agents that can reach multiple systems without task-specific limits, use persistent tokens, or touch high-value services such as email, chat, cloud consoles, and file stores.
Practitioner guidance
- Define agent ownership before production Assign a named business and technical owner for each AI agent, then require that owner to approve access scope, review cadence, and revocation criteria before go-live.
- Separate residency from authorisation review Treat EU data residency as one control decision and agent entitlement review as another, then validate both in procurement and security sign-off.
- Limit agent permissions to task-scoped actions Map every agent to the minimum systems, actions, and data paths needed for its job, and reject broad delegated access that cannot be explained in plain language.
What's in the full announcement
C1.ai's full article covers the operational detail this post intentionally leaves for the source:
- How the EU instance is provisioned in AWS Frankfurt and how disaster recovery is handled through Ireland
- Which identity and governance controls the platform describes for employees, contractors, service accounts, workloads, and AI agents
- How teams can evaluate tenant data residency alongside access review and authorisation requirements
- What the platform says about maintaining an audit trail and removing access when work is complete
👉 Read C1.ai's article on EU availability and AI agent identity governance →
C1.ai in Europe: what it means for AI agent access governance?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
AI agent governance cannot be separated from NHI governance: once an agent can access tools and business systems, it behaves like a high-impact non-human identity, not a software feature. The same lifecycle questions that govern service accounts now apply to agent approvals, scopes, review, and offboarding. The field should stop treating agent identity as a side effect of AI adoption and start treating it as a first-class governance domain.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
- 91.6% of secrets remain valid five days after the target organisation is notified, which shows how slowly non-human identity exposure is remediated in practice.
A question worth separating out:
Q: Should organisations manage AI agents under the same lifecycle as other NHIs?
A: Yes, because the core risk is the same: an identity with access outlives the purpose for which it was granted. AI agents add more runtime action capability, so lifecycle controls need to cover approval, review, revocation, and offboarding in the same governance stream as service accounts and tokens.
👉 Read our full editorial: C1.ai in Europe raises the stakes for AI agent identity governance