Enterprise AI is moving from answering questions to taking action.
Agents can access data, invoke tools, call APIs and execute tasks across business processes. They can act on behalf of employees, interact with other agents and operate at a speed and scale that conventional human-centric security models were not built to handle.
This requires a different governance model. Enterprises need to know which agents exist, who is responsible for them, what identities and privileges they use, what data and tools they can access and what they do with that access. An agent can be properly authenticated and authorized to access a resource and still take a risky action.
Security teams therefore need to answer two questions: What is the agent allowed to do? And is what the agent is doing appropriate for the task and business process?
Conversations across Black Hat 2026 showed an industry working through both questions. Identity, privilege, data security and runtime controls all play a role, but agents expose gaps between controls largely built to govern human users, applications and machines. As agents move deeper into enterprise workflows, governance has to extend from access to action.

Governance Must Start With Inventory
Enterprises are deploying agents across SaaS applications, development environments, productivity tools and AI-focused systems. Some are centrally sanctioned, but many are deployed by individual teams or embedded inside products the organization already uses. “Shadow AI” deployment is moving far faster than governance processes are adapting.
The first step is creating an inventory that captures more than the existence of an agent. The organization also needs to understand why it exists, who owns it, which systems it can reach, which identity it uses and what authority it has been granted. Discovery without ownership still leaves a significant governance gap.
Agent Identity Cannot Be Separated From Human Identity
Agents complicate existing identity models because they can operate independently while also acting on behalf of a person. An employee might ask an agent to complete a task, and the agent can then access systems, retrieve information and take actions using permissions associated with the user, the agent itself or some combination of the two. The enterprise needs to understand where the user’s authority ends and the agent’s begins.
Standing privilege becomes particularly risky when software can exercise it at machine speed. An agent completing one task for an employee should not automatically inherit everything that employee is permitted to do. Its authority should be scoped to the resources and tools required for the work.
Access also has to follow the lifecycle of the person or business process behind the agent. If a responsible employee changes roles or leaves the organization, the agent’s access cannot simply persist. An orphaned agent can retain access and authority after the person responsible for it has changed roles or left, leaving the organization with an active identity whose permissions and actions no longer have clear oversight.
Authorization Cannot Be a One-Time Decision
Scoping an agent’s authority at deployment addresses only the starting point. An agent may take many actions within a workflow, and those actions can carry very different levels of risk. Reading a record, modifying it, transferring its contents to another system and deleting it are not equivalent simply because the agent has legitimate access to the underlying resource.
Working across systems adds another complication. An agent may be authorized to access two applications independently while the movement of information or execution of actions between them creates unacceptable risk. Organizations need ways to grant, narrow or escalate authority as work unfolds, taking into account the task, resources involved and potential consequence.
Data introduces another dimension to authorization. An agent may have legitimate access to information in multiple systems, while the combination, movement or use of that data creates risk that was not apparent in any individual access decision. Governance therefore needs to account for the sensitivity and permitted use of the data involved, not only whether the agent has permission to retrieve it.
Changes in the underlying model can alter that risk profile as well. Anthropic’s August 2026 Risk Report, published in the week following Black Hat, raised its assessment of misalignment risk in high-stakes situations from “very low” to “low” following disclosures related to recent cybersecurity evaluations. The company also said it has no current plans to externally release a more capable internal model known as Model 2 and has acknowledged limitations in existing evaluations as model capabilities advance. For enterprises, an agent operating with the same identity, tools and permissions may warrant reassessment when the model behind it changes materially.
The risk profile can also shift during execution. An agent may encounter external content that influences its behavior or invoke tools that expand the consequences of its actions. A model connected to credentials, APIs and enterprise applications can modify records, send communications or initiate downstream processes while remaining within its authorized access.
Governance therefore has to account for what happens after access is granted. Organizations need visibility into the information and tools involved, whether the agent’s actions remain consistent with policy and the task at hand, and how a sequence of actions produced an outcome. That context can inform intervention while work is underway and provide an audit trail when the organization needs to reconstruct what happened
Human Accountability Cannot Mean Approving Every Action
AI agents may have a level of autonomy, someone in the organization still needs to own the business purpose for which the agent exists and the authority it has been given. Security’s role is establishing guardrails around AI use, while ownership of the business process remains with the business. Governance extends across other stakeholders, including legal, compliance and IT, depending on the process and risks involved.
As agents move beyond employee productivity into finance, customer service, software development, procurement and other operational workflows, the allocation of responsibility needs to remain clear. Security establishes and enforces controls around areas such as identity, permissions, data access and monitoring, while the business remains accountable for the process and its outcome. Delegating execution to software does not transfer that responsibility.
Accountability does not require a person to approve every action. Doing so would undermine much of the scale and speed that make agents useful. Enterprises need thresholds for intervention based on risk and consequence. Routine actions may proceed within established policy, while higher-risk activity may trigger additional evaluation, a change in authorization or human approval. Creating a ticket, deleting production data and initiating a financial transaction warrant different levels of oversight.
A person can therefore remain accountable for a business process without approving every action within it. Governance has to accommodate automated execution while preserving clear human ownership of the process and its outcomes.
Agent Governance Will Span Multiple Control Points
Black Hat reinforced how many existing enterprise controls are converging on agent governance.
Identity systems govern who or what can act and the authority associated with that identity. Privileged access controls can constrain elevated access and reduce standing privilege. Secrets management protects the credentials and tokens agents use to reach systems. Data security governs the information agents can access and use. Runtime controls evaluate behavior while work is underway. Agent platforms have their own policy and security controls, while security operations needs visibility into activity that warrants investigation.
Agents require these controls to work together, with policy, context and accountability carrying across control points as an agent moves through a workflow:
Discovery → Identity → Authorization → Data → Runtime Control → Monitoring → Accountability
Enterprises are already deploying AI across business functions, and that adoption will continue. Restricting agent use until every governance question is resolved is neither a durable security strategy nor a realistic business strategy. Security has to establish the conditions under which agents can perform useful work while retaining control over the authority they exercise.
This is the second piece in our post-Black Hat series. Next, we’ll look at why cyber resilience is becoming an operating discipline focused on the business services that have to keep running through disruption.

