TL;DR: AI adoption is widening access to sensitive data faster than many security teams can see it, with Cyera citing 83% daily AI use and only 13% strong visibility into AI-data interactions. The real issue is that identity governance and data security still operate on separate assumptions, so access decisions lack the context needed to enforce least privilege at AI scale.
Editorial analysis by NHI Mgmt Group, based on content published by Cyera: “Cyera and Saviynt Secure AI’s Data Access at Scale”.
Key questions
Q: What breaks when AI agents and service accounts are governed separately from data sensitivity?
A: Least privilege becomes an assumption rather than an enforced decision.
Q: Why do AI identities increase risk when organisations rely on standing access and broad permissions?
A: AI identities increase risk because they often operate with more access than they need and can act at machine speed across many systems.
Q: How can teams tell whether identity governance is actually reducing risk?
A: Look for fewer unmanaged identities, faster revocation of unnecessary access, and lower reliance on standing privilege.
Practitioner guidance
- Unify identity and data inventories Map human users, service accounts, automated workflows, and AI agents against the sensitive datasets they can reach, then review the highest-risk overlaps first.
- Tie access reviews to data sensitivity Move recertification and owner attestation from role-only review to entitlement review with PII, financial records, secrets, and other sensitivity labels included.
- Automate revocation for exposure changes Trigger entitlement revocation or conditional approval when data exposure, sharing, or anomaly signals change, rather than waiting for the next review cycle.
Bottom line: AI agents, service accounts, and automation are expanding sensitive-data access faster than many identity programmes can assess the resulting risk.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Identity governance without data context creates a false sense of least privilege: Access reviews can only be as accurate as the asset intelligence behind them. If governance teams do not know whether an entitlement reaches PII, financial records, or secrets, the review outcome is a permission audit, not a risk decision. The practical conclusion is that entitlement governance must be evaluated against data sensitivity, not just role membership.
A few things that frame the scale:
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: How should organisations respond when a machine identity is suspected compromised?
A: Containment should start by revoking the token, disconnecting linked apps, and searching for any secrets that may have been exposed in downstream systems. Then teams should validate which integrations inherited the same trust and whether additional principals share the same exposure path. The goal is to stop reuse before it becomes a wider intrusion.
👉 Read our full editorial: AI agent data access outpaces identity governance controls