South African organisations are looking to adopt artificial intelligence without losing control of sensitive data or creating new routes into critical systems. The reported work between Solid8 and Saviynt places identity governance at the centre of that challenge: AI adoption is not only a technology question, but also a question of who, or what, can access data and services.

The governance problem

AI initiatives often connect models, applications, datasets and human operators across environments that were not designed as one security perimeter. Permissions accumulate quickly. A developer may need temporary access to a production dataset; a service account may support a model pipeline; an AI-enabled application may call several downstream systems. If those relationships are not visible and governed, organisations can end up with excessive entitlements that persist long after the business need has passed.

This is where identity lifecycle management matters. Traditional joiner, mover and leaver processes focus on employees, but modern environments also include contractors, workloads, bots and service identities. Each needs an accountable owner, a defined purpose and controls that change as its role changes.

Making AI access governable

An IGA programme can help establish a reliable inventory of identities and their access. That inventory is a prerequisite for meaningful oversight: teams cannot review or revoke permissions they do not know exist. Linking identity records to authoritative sources, applications and business roles can help distinguish justified access from inherited or orphaned privileges.

Access decisions should also be proportionate. AI projects may require sensitive information, but broad standing access is rarely the only option. Least-privilege policies, time-bound approvals and regular certification can narrow exposure. Where workflows support it, access can be granted for a specific task and removed automatically when that task ends.

Organisations should treat non-human identities with the same discipline. Assigning each service identity an owner, documenting its dependencies, rotating credentials and detecting dormant accounts reduces the risk that automation becomes an unmonitored back door. Changes to models or pipelines should trigger a review of the permissions those components retain.

Operational measures

Governance needs to fit local operating realities, including data residency, sector regulation and the responsibilities of regional teams. Security leaders can begin by mapping the identities and data flows involved in a limited AI use case, then test whether approvals, reviews and offboarding work end to end. Useful measures include the proportion of AI-related identities with named owners, time to remove access after a project ends, and the number of excessive or unused entitlements remediated.

Partnerships and platforms can provide tools, but accountability remains with the organisation. A clear policy should define acceptable AI use, the data each use case may reach, who approves exceptions and how incidents are investigated. Connecting those rules to identity governance administration turns principles into enforceable controls, helping businesses expand AI adoption while retaining a practical view of access risk.