TL;DR: AI in access administration only works when recommendations remain explainable, deterministic, and auditable, according to Nexis and Gartner’s 2026 Hype Cycle for Digital Identity. The real test is whether AI strengthens governed access structures, because probabilistic outputs alone are not enough for regulated access decisions.
NHIMG editorial — based on content published by Nexis: Analysts AI for Access Administration: Why Expainability Decides Wether It Works
Questions worth separating out
Q: How should security teams use AI in GRC without losing auditability?
A: Use AI to classify evidence, surface drift, and route workflows, but keep a clear control map, immutable audit trails, and human approval where exceptions or privileged changes matter.
Q: Why do deterministic access models matter more than probabilistic AI outputs?
A: Deterministic models create entitlement logic that auditors can read and teams can govern consistently.
Q: What do teams get wrong when they automate access administration too early?
A: They usually automate before they standardise the underlying access data and governance process.
Practitioner guidance
- Standardise access data before introducing AI Clean up entitlement naming, role structures, and source data so recommendations are generated from a governed baseline rather than inconsistent inputs.
- Require explainable recommendations in recertification Make every AI-assisted access review recommendation include policy rationale, usage evidence, or anomaly context that a reviewer can test quickly.
- Use AI to maintain deterministic controls Apply AI to draft role models, detect anomalies, and explain policy logic, while keeping final access approval anchored in explicit rules.
What's in the full article
Nexis's full article covers the operational detail this post intentionally leaves for the source:
- How the NICO co-pilot presents recommendations and reasoning inside access review workflows.
- How machine learning is used to detect anomalies and propose role or policy structures from live identity data.
- How GenAI helps draft policy language and authorization concepts in reviewer-friendly language.
- How reinforcement from user feedback shapes future recommendations in the platform.
👉 Read Nexis's analysis of explainable AI for access administration →
AI access administration and explainability: are your controls ready?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Explainability is the control that makes AI acceptable in access administration. When access decisions affect regulated systems, teams need to show why a recommendation was made, not just that a model produced it. A black box may accelerate throughput, but it weakens auditability and makes recertification harder to defend. The practical conclusion is that AI in identity governance succeeds only when explanation quality is treated as part of the control objective.
A few things that frame the scale:
- Only 44% of developers are reported to follow security best practices for secrets management, exposing a significant developer behaviour gap, according to the State of Secrets in AppSec.
- The average estimated time to remediate a leaked secret is 27 days, despite 75% of organisations expressing strong confidence in their secrets management capabilities.
A question worth separating out:
Q: Who should own governance when humans and AI agents share access paths?
A: Ownership should sit with the identity, security, and platform teams jointly, because the control problem spans human delegation, machine credentials, and runtime auditability. If each team manages only its own layer, no one can reconstruct the full action chain or revoke access cleanly when the workflow changes.
👉 Read our full editorial: Explainability is the deciding factor in AI access administration