HRM & Cybersecurity Blog | Living Security

Future of Human Risk Management: Agentic AI Landscape

Written by Crystal Turnbull | July 20, 2026

Human risk management is evolving from a compliance function into a board-level strategic imperative. At HRMCon 2025. Forrester VP and Principal Analyst Jinan Budge and SimSpace Vice President of International Markets Graham Westbrook shared their vision for the future of human risk management. Including the transformative role of agentic AI in reshaping how organizations measure, prioritize, and reduce human risk at scale. This session traced the market's maturation from checkbox compliance to predictive intelligence, examined emerging AI governance challenges. And outlined actionable steps for security leaders preparing for a workforce where humans and autonomous AI agents operate side by side.

Reserve your spot at HRMCon 2026

What Is Forrester's View of Human Risk Management's Maturation?

Jinan Budge opened the session with a clear thesis: human risk management has reached an inflection point. What began as a niche category within security awareness training is now recognized as a distinct market. Validated by Forrester's first-ever Wave evaluation of Human Risk Management Solutions in Q3 2024, which named Living Security a leader across all 35 evaluation criteria.

Budge outlined three distinct phases of HRM maturation, each building on the last:

The compliance era. Organizations focused on checking boxes: annual training completion, policy acknowledgment, and regulatory reporting. Risk was measured in activities, not outcomes. Teams celebrated 95% training completion rates while having no visibility into whether trained employees actually changed their security behaviors. This era prioritized audit readiness over risk reduction.

The measurement era. Organizations began tracking behavioral metrics: phishing click rates, training scores, policy violations, and simulated attack responses. This was a meaningful improvement over the compliance era, but measurement without predictive capability still left teams reacting to past incidents. Security teams could tell you what happened last quarter but could not forecast what might happen next.

The predictive era. The current frontier. Organizations use AI to analyze behavioral, identity, and threat signals in real time, predict risk trajectories, and intervene before incidents occur. Human Risk Management (HRM), as defined by Living Security, now correlates three pillars: behavior, identity and access, and threat intelligence. This is the era of true human risk management where data from 200+ risk indicators across 60+ security tool integrations feeds a continuously updating risk profile for every user in the organization.

EraFocusHow Risk Was MeasuredKey Limitation
Compliance EraTraining completion, policy acknowledgmentActivities completed (e.g., 95% training rate)No visibility into actual behavior change
Measurement EraPhishing click rates, policy violationsBehavioral metrics and historical dataReactive only, no predictive capability
Predictive EraAI-driven risk analysis, real-time intervention200+ risk indicators from 60+ integrationsRequires strong data foundation and governance

The organizations that make this transition fastest, Budge argued, will have a significant competitive advantage. Boards are demanding measurable risk reduction, and predictive HRM delivers it. According to the Cyentia Institute's 2025 "Risky Business" report. Organizations using Living Security's Unify platform saw their population of risky users drop by half over the last year, from 43% to 21%. After completing action plans, users spent an average of 60% less time in a risky state, with a 98% decrease in data-loss exposure time.

The AI Governance Imperative

As organizations deploy AI agents that can autonomously interact with systems and data, the governance challenge intensifies. Graham Westbrook highlighted that AI agents introduce new categories of human risk that traditional security awareness programs were never designed to address:

Shadow AI. Employees deploying AI tools and agents without organizational oversight creates data exfiltration and compliance risks. Unlike traditional shadow IT, shadow AI is harder to detect because these tools operate through browser extensions, API calls, and embedded workflows that bypass standard network monitoring. Westbrook noted that the speed of AI adoption has outpaced most organizations' ability to establish governance guardrails, leaving significant blind spots.

Agent accountability. When an AI agent makes a decision that leads to a security incident, determining responsibility becomes complex. If an autonomous remediation agent misconfigures a firewall rule or an AI-powered chatbot inadvertently exposes sensitive data. The question of accountability spans the developer who trained the model, the administrator who set its permissions, and the organizational framework that authorized its deployment. The governance frameworks for answering these questions are still being developed.

Behavioral contagion. As users observe AI agents making security decisions, their own security behaviors may shift, creating new risk patterns that organizations must monitor and manage. If employees see an AI agent granted broad access to sensitive systems, they may perceive security boundaries differently and adjust their own behavior accordingly. This contagion effect means that HRM programs must extend beyond individual user monitoring to account for the behavioral influence of autonomous agents across the workforce.

Westbrook emphasized that these challenges are not hypothetical. With the global market for agentic AI expected to grow rapidly. Organizations that establish governance frameworks now will be better positioned than those that wait until after an incident forces their hand. AI with human oversight is not optional; it is the minimum requirement for responsible deployment.

How Does Agentic AI Reshape Measuring, Prioritizing, and Reducing Risk?

Agentic AI systems that can autonomously analyze data, make decisions, and take action are transforming human risk management at every level. The Living Security platform, with Livvy as its always-on intelligence engine built on proprietary HRM data spanning five years and billions of signals from more than 100 enterprises. Represents this next generation of autonomous risk management.

Continuous risk assessment. Instead of periodic risk scoring that captures a snapshot in time. Agentic AI continuously analyzes streaming data from 200+ risk indicators, updating risk profiles in real time as new signals arrive. When an employee connects from an unrecognized device, accesses sensitive data outside business hours. Or demonstrates phishing susceptibility trends, the platform adjusts their risk score immediately, not at the next quarterly review. This real-time visibility allows security teams to see risk forming before it materializes into an incident.

Autonomous remediation. The platform autonomously executes 60-80% of routine remediation tasks, including micro-learning delivery, policy nudges, and enforcement actions, with human-in-the-loop oversight for complex cases. When a user exhibits risky behavior, the platform can deploy a targeted 90-second micro-learning module addressing that specific behavior. Send a contextual policy nudge, or escalate to the security team for manual intervention. This automation frees security teams to focus on strategic work rather than repetitive remediation tasks.

Predictive intervention. By analyzing historical risk trajectories and behavioral patterns across the organization, the platform predicts which users are trending toward high-risk behavior and intervenes before an incident occurs. The Cyentia Institute's research found that just 10% of users account for 73% of all risky behavior within their organizations. Predictive intervention allows organizations to identify and address these users proactively rather than reactively, focusing resources where they will have the greatest impact on overall risk reduction.

Read the Forrester Wave on Human Risk Management

What Should Organizations Do Now to Prepare?

Budge and Westbrook outlined a practical roadmap for organizations preparing for the future of HRM, starting with foundational steps that build toward more advanced capabilities:

Build your data foundation. The quality of your predictive intelligence depends on the quality of your data. Identify and connect the behavioral, identity, and threat data sources that will power your HRM program. Leading organizations integrate data from their existing security stack, including SIEM, IAM, endpoint protection, email security, and data loss prevention tools. Living Security's platform natively integrates with 60+ security tools to create a unified data layer without requiring organizations to rip and replace existing investments.

Establish AI governance frameworks. Before deploying AI-driven risk management, establish clear policies for AI oversight, accountability, and transparency. This includes defining which decisions require human approval, establishing audit trails for AI-driven actions, and creating escalation paths for edge cases. Human-in-the-loop governance ensures that AI recommendations are reviewed and validated before autonomous action is taken on high-risk scenarios.

Start with a focused use case. Pick one risk category or population and deploy predictive monitoring. Prove the model works before scaling. Organizations that start with a targeted deployment, such as phishing risk monitoring for their highest-access user population. Can demonstrate value quickly and build organizational confidence in the approach before expanding to additional risk categories and user groups.

Prepare for agentic AI. As AI agents become more prevalent in your organization, extend your HRM program to cover both human and AI agent risk. This means monitoring what agents are doing, auditing their decisions, and ensuring they operate within defined governance boundaries. The Living Security platform covers risk from both humans and AI agents, making it the first HRM platform designed for the modern workforce that includes autonomous AI systems.

Why Does Analyst Validation Matter for Your HRM Strategy?

Forrester's first Wave evaluation of the Human Risk Management market in Q3 2024 named Living Security a leader. This analyst validation carries significant weight for organizations building their HRM strategy. The Forrester Wave evaluation assessed providers across 35 criteria spanning current offering, strategy, and market presence, providing security leaders with an objective framework for evaluating HRM solutions.

Being named a leader in Forrester's inaugural HRM Wave evaluation validates the market shift that Budge and Westbrook discussed in their session. Human risk management is no longer an emerging category; it is an established market with recognized leaders, proven outcomes, and measurable ROI. The Cyentia Institute's independently validated research reinforces this. Showing that organizations using Living Security's platform reduced their risky user population by half and achieved a 98% reduction in data-loss exposure.

As Jinan Budge noted during the session, human risk management is entering a transformative period. Organizations that invest in predictive, AI-native HRM platforms today will be best positioned to manage the workforce risk challenges of tomorrow. Including the governance of AI agents and the continued evolution of the threat landscape. The convergence of analyst validation, independently verified outcomes, and technological capability creates a strong case for organizations to move from awareness training to true human risk management.

Watch the full HRMCon 2025 on-demand library

Key Takeaways for Security Leaders

The conversation between Jinan Budge and Graham Westbrook at HRMCon 2025 yielded several actionable insights for security leaders evaluating their organization's HRM strategy:

  • The market has matured. HRM is now a recognized category with analyst validation, established leaders, and independently verified outcomes. The time for pilot programs and evaluation is over; the evidence base for investing in predictive HRM is clear.
  • Agentic AI is a double-edged sword. The same technology that enables autonomous remediation and predictive intervention also introduces new risk categories, including shadow AI, agent accountability gaps, and behavioral contagion. Governance frameworks must address both sides.
  • Data quality determines outcomes. The organizations that will succeed in the predictive era of HRM are those that invest in connecting and normalizing their behavioral, identity, and threat data sources today. Without a strong data foundation, AI-driven insights will be built on sand.
  • Start narrow, then scale. The most successful HRM programs begin with a focused use case, prove value, and expand methodically. Attempting to solve every risk category simultaneously overwhelms teams and dilutes impact.
  • AI oversight is non-negotiable. Human-in-the-loop governance is not a luxury or a future consideration. It is a requirement for responsible AI deployment in security operations today, and organizations that delay establishing governance frameworks will find themselves playing catch-up.

Frequently Asked Questions About the Future of Human Risk Management

How will agentic AI change human risk management?

Agentic AI enables continuous risk assessment, autonomous remediation, and predictive intervention. Instead of periodic evaluations and manual remediation, organizations can manage human risk in real time with AI-driven automation. The Living Security platform, powered by Livvy, uses AI with human oversight to analyze 200+ risk indicators across 60+ security tool integrations. Automating 60-80% of routine remediation tasks while keeping security teams in control of complex decisions.

What is the role of governance in AI-driven HRM?

Governance is the foundation of responsible AI deployment in HRM. Organizations must establish clear policies for AI accountability, transparency, and oversight, including defining which decisions require human approval and creating audit trails for AI-driven actions. Human-in-the-loop governance ensures that AI recommendations are reviewed and validated before autonomous action is taken on high-risk scenarios.

Is human risk management relevant for organizations using AI agents?

More relevant than ever. AI agents introduce new categories of risk, including shadow AI, agent accountability gaps, and behavioral contagion effects. The Living Security platform covers risk from both humans and AI agents, making it the first HRM platform designed for the modern workforce that includes autonomous AI systems.

What outcomes can organizations expect from a mature HRM program?

According to the Cyentia Institute's independently validated 2025 research, organizations using Living Security's platform saw their population of risky users drop by half. From 43% to 21%, while achieving a 98% decrease in data-loss exposure time. After completing action plans, users spent an average of 60% less time in a risky state.

How do organizations get started with predictive HRM?

Start by building your data foundation: identify and connect the behavioral, identity, and threat data sources that will power your HRM program. Begin with a focused use case, such as phishing risk monitoring for high-access users, prove the model works, and then scale to additional risk categories and user populations.

Explore the other sessions from HRMCon 2025: