Use a unified model that combines behaviour, identity and access, and threat context. A single metric like a phishing click is too narrow. The useful signal is whether risky behaviour is paired with meaningful access and active targeting, because that combination predicts impact. Teams should track leading indicators, not just incident counts, so they can intervene before misuse becomes a breach.
Why This Matters for Security Teams
human cyber risk is no longer just an employee awareness problem. Security teams now have to measure how people, service accounts, and AI agents behave when they have access to sensitive systems, data, and tools. A narrow score based on phishing clicks or training completion misses the bigger question: who can actually cause harm, and under what conditions. That is why leading teams combine behaviour, identity, privilege, and threat context into one model, aligned to the governance principles in the NIST AI Risk Management Framework.
This matters because AI agents can act with speed, scale, and persistence that changes the exposure profile of the organisation. A careless employee and an over-permissioned AI agent are not equivalent risks, even if both trigger a policy violation. The practical challenge is to measure risk in a way that reflects actual blast radius, not just individual behaviour. In practice, many security teams only recognise this gap after a privileged account, automation workflow, or agent has already been misused to move data or execute actions that should never have been available in the first place.
How It Works in Practice
A usable model usually starts by separating three dimensions: behavioural indicators, identity and access context, and threat activity. Behavioural indicators include risky actions such as repeated policy bypass, unusual data handling, or suspicious interaction with prompts, files, or links. Identity and access context asks what the person or agent can reach, whether privileges are standing or just-in-time, and whether the identity is governed with strong lifecycle controls. Threat context looks at whether that user, workload, or agent is being targeted by current campaigns, attacker tooling, or active exploitation patterns.
For AI agents, the same logic applies but the evidence looks different. The signal may include tool usage anomalies, prompt injection susceptibility, unsafe delegation, or unexpected calls to external systems. That is where the MITRE ATLAS adversarial AI threat matrix and the OWASP Agentic AI Top 10 become useful. They help teams map risk to concrete adversarial techniques rather than treating AI failure as a generic trust problem.
- Track leading indicators, not just incidents, such as risky actions, privilege concentration, and repeated control bypass.
- Weight scores by access tier, data sensitivity, and whether the identity is human, service, or agentic.
- Overlay external threat intelligence so a user or agent under active targeting is scored differently from routine noise.
- Use the score to trigger interventions such as step-up controls, access review, containment, or retraining.
For broader operational alignment, many teams also map this to the NIST Cybersecurity Framework 2.0 and control baselines such as access monitoring, identity governance, and logging. These controls tend to break down when identity data is fragmented across HR, IAM, PAM, and agent management platforms because risk scoring then becomes stale before it can drive intervention.
Common Variations and Edge Cases
Tighter human cyber risk scoring often increases monitoring overhead and false positives, so organisations have to balance precision against operational burden. That tradeoff becomes sharper when AI agents are introduced, because the same action can be either harmless automation or an unsafe autonomous decision depending on the workflow and guardrails around it.
There is no universal standard for this yet, especially for scoring AI agents alongside employees. Current guidance suggests treating agent risk as a separate but comparable category, rather than folding it into employee awareness metrics. A contractor with limited access, a developer with production credentials, and an AI agent with API keys should not share the same scoring logic. The score must reflect identity type, privilege depth, data sensitivity, and exposure to current threats. The CSA MAESTRO agentic AI threat modeling framework is helpful where teams need a more explicit way to reason about autonomous workflows and control points.
For executive reporting, the best practice is evolving toward a portfolio view: how much risky behaviour exists, where the highest-impact identities sit, and whether controls are reducing exposure over time. The useful output is not a single universal human risk number. It is a ranked view that shows which people or agents need intervention first, and why. For active campaign awareness, teams can also cross-check against CISA cyber threat advisories. Best practice breaks down when organisations try to score AI agents with employee-awareness KPIs, because autonomous systems behave differently, fail differently, and require different control thresholds.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATLAS and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST AI 600-1 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | ID.AM | Risk scoring depends on knowing which identities and agents exist and what they can access. |
| NIST AI RMF | GOV | Governance is needed to assign accountability for AI agent behaviour and risk decisions. |
| MITRE ATLAS | Adversarial AI techniques shape how agent risk should be measured and monitored. | |
| OWASP Agentic AI Top 10 | A01 | Agentic systems introduce unique failure modes like unsafe autonomy and tool misuse. |
| NIST AI 600-1 | GV | GenAI systems need operational controls that inform acceptable risk thresholds and monitoring. |
Score agents for misuse potential, delegated authority, and guardrail failures, not just task completion.
Related resources from NHI Mgmt Group
- How should security teams govern AI agents that translate human intent into cyber actions?
- How should security teams unify human and AI agent risk management across the workforce?
- How should security teams limit the risk from AI agents that have access to production systems?
- How should security teams reduce risk from AI agents and developer tools that use secrets locally?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org