Adoption percentage shows how widely a tool is used, but not how much sensitive data it handles or what level of privilege it carries. A small number of highly active agentic tools can create more exposure than a larger number of lightly used ones. Security teams need workflow-level metrics, not seat counts alone.
Why This Matters for Security Teams
Adoption percentage is a usage metric, not a risk metric. A broad rollout can look impressive while hiding a narrow set of agentic tools that hold API keys, can invoke downstream systems, or can access regulated data. That is why security teams need to measure privilege, data reach, and tool chaining rather than counting seats or activations. The gap is visible in NHIMG research: only 1.5 out of 10 organisations are highly confident in securing NHIs, according to The State of Non-Human Identity Security.
This matters because an agent or workload with low user adoption can still be the highest-risk identity in the environment if it has standing access to cloud control planes, CI/CD, or customer data. Current guidance suggests using adoption as a context signal, not a proxy for exposure, and pairing it with control-plane permissions, secret lifetime, and observable behaviour. The same lesson appears in Top 10 NHI Issues, where over-privilege and weak monitoring matter more than raw footprint. In practice, many security teams discover that the smallest workflow is the one causing the largest blast radius after an incident has already spread.
How It Works in Practice
Security teams should rank AI systems and NHIs by what they can do, not how many people touch them. A workflow that runs once per hour but can create tokens, query proprietary data, and trigger actions in production is far riskier than a widely used chat interface with no downstream privileges. That is especially true for agentic AI, where autonomy changes the threat model. The relevant question is not “How many users adopted it?” but “What can this identity reach at runtime?”
A practical approach is to build a workflow-level inventory that captures:
- Data sensitivity: what records, prompts, embeddings, or files the system can read or write.
- Privilege scope: which APIs, queues, cloud resources, and admin actions it can invoke.
- Credential type: whether it relies on static secrets or short-lived JIT tokens.
- Execution path: whether the system can chain tools, call sub-agents, or escalate laterally.
- Policy enforcement: whether access is checked at request time using current context.
That aligns with the direction of the CSA MAESTRO agentic AI threat modeling framework and the NIST Cybersecurity Framework 2.0, both of which push teams toward function, context, and governance rather than superficial inventory counts. NHIMG research on the Ultimate Guide to NHIs — Why NHI Security Matters Now reinforces that visibility gaps and over-privileged accounts are persistent attack drivers. These controls tend to break down when teams cannot map an AI workflow’s downstream tool use because the actual privilege chain spans multiple services and owners.
Common Variations and Edge Cases
Tighter risk scoring often increases operational overhead, requiring organisations to balance better precision against incomplete telemetry and faster delivery cycles. That tradeoff is especially visible in early-stage AI programs, where teams may only know adoption counts from licensing or dashboard data and not yet have complete workflow instrumentation. In those cases, current guidance suggests using adoption as a triage input, then enriching it with privilege, data classification, and secret management evidence.
There is no universal standard for this yet, but some patterns are clear. A low-adoption internal agent that can access finance systems may deserve higher priority than a popular assistant with read-only access. Likewise, an externally exposed bot with few users can still be dangerous if it holds long-lived secrets or can act on behalf of high-trust service accounts. The risk picture becomes even less stable when autonomous systems can re-plan, call other agents, or switch tools mid-task. For that reason, adoption should never be the headline metric for AI security. It is one input among many, and often not the most important one.
For practitioners comparing mature and immature environments, the most useful companion measures are secret rotation frequency, effective privilege set, runtime policy hits, and the number of systems each agent can influence. That is the operational lesson behind OWASP NHI Top 10 and the broader NHI security research from NHIMG.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10, CSA MAESTRO and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | A02 | Adoption counts miss agent tool abuse and runtime privilege expansion. |
| CSA MAESTRO | TM-1 | MAESTRO centers threat modeling on agent behavior, not seat counts. |
| NIST AI RMF | GOVERN | AI RMF requires governance metrics beyond simple adoption reporting. |
| OWASP Non-Human Identity Top 10 | NHI-01 | NHI exposure depends on privilege and secret handling, not usage volume. |
| NIST CSF 2.0 | ID.AM-1 | Asset inventory must capture what identities do, not just how many exist. |
Model workflows, privilege chains, and autonomous actions before deployment.
Related resources from NHI Mgmt Group
- How should security teams measure whether AI is helping rather than hiding risk?
- How do teams decide whether AI adoption is increasing security risk or improving control?
- Why does AI adoption increase burnout risk in security teams?
- How should security teams measure human cyber risk across employees and AI agents?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org