Join our Newsletter — 33% off our NHI Course
Home Glossary Cyber Security AI Systems And Agents
Cyber Security

AI Systems And Agents

← Back to Glossary
By NHI Mgmt Group Updated September 2, 2026 Domain: Cyber Security

AI systems and agents are the technologies organisations must discover, assess, and govern when they use artificial intelligence in operations. This includes models, applications, and autonomous or semi-autonomous agents that can influence decisions, actions, or access in business environments.

Expanded Definition

AI systems and agents are not a single product category but an operational surface: models, orchestration layers, applications, and autonomous or semi-autonomous agents that can affect business decisions, execute actions, or request access. For NHI Management Group, the important distinction is between a model that generates output and an agent that can take action with tool access, which creates different governance and security obligations.

Usage in the industry is still evolving. Some teams use “AI system” narrowly to mean a deployed model, while others include surrounding workflows, prompts, retrieval layers, and integrations. “Agent” usually implies persistence, delegated authority, and the ability to act across systems, but definitions vary across vendors and implementation patterns. A useful reference point is the NIST AI Risk Management Framework, which frames AI governance around mapping, measuring, and managing risk across the full lifecycle.

The most common misapplication is treating an agent like a passive chatbot, which occurs when teams overlook tool permissions, memory, and external actions that can change records or trigger downstream workflows.

Examples and Use Cases

Implementing AI systems and agents rigorously often introduces discovery and governance overhead, requiring organisations to weigh automation speed against control, auditability, and access risk.

  • An internal support agent that can create tickets, update records, and query knowledge bases, requiring approval boundaries and logging.
  • A procurement assistant that drafts purchase requests from user prompts, where the model output is harmless but the connected workflow can create real commitments.
  • A security operations agent that triages alerts and enriches incidents, where delegation must be limited to read-only or tightly scoped write actions.
  • A customer-facing assistant that uses retrieval and tool calls, where prompt injection and data exposure risks must be assessed as part of the system, not just the model.
  • An autonomous code agent that opens pull requests or changes infrastructure configurations, where change control and identity governance become inseparable from AI governance. The OWASP Top 10 for Agentic Applications 2026 is useful here because it highlights the risks that emerge once tool use and autonomy enter the workflow.

These examples show why AI systems and agents must be assessed as an ecosystem, not as isolated prompts or model endpoints. The same model can be low risk in one deployment and high risk in another if it gains access to secrets, APIs, or privileged workflows.

Why It Matters for Security Teams

Security teams need this term because many of the hardest failures come from misplaced trust in AI behaviour, weak scoping of authority, and poor inventory of where AI is actually embedded. Once an agent can touch data, call tools, or influence access, it becomes part of the control environment and should be governed accordingly.

That governance intersects directly with identity and NHI concerns: agents often rely on service accounts, API keys, tokens, and delegated credentials, which means access review, secret handling, and least privilege all apply. It also intersects with adversarial AI threat models, especially where prompt injection, tool abuse, or automated social engineering can turn a useful assistant into an attack path. Resources such as the OWASP Agentic AI Top 10, MITRE ATLAS adversarial AI threat matrix, and CSA MAESTRO agentic AI threat modeling framework help security leaders translate that risk into practical controls.

Organisations typically encounter the real impact only after an agent misuses a tool, overreaches its permissions, or produces an unintended action, at which point AI systems and agents become operationally unavoidable to govern.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST AI RMFDefines AI risk governance across the lifecycle of AI systems and agents.
OWASP Agentic AI Top 10Focuses on agentic application risks once models can act via tools.
CSA MAESTROProvides threat modeling guidance for agentic AI systems and their control paths.

Use GOVERN, MAP, MEASURE, and MANAGE to inventory and control AI systems and agents.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 2, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org