AI agents are going rogue. CIOs are racing to put guardrails around them

WorkAI.TV Editorial Desk
4 Min Read

Share with your CIO

Enterprises are building internal guardrail architectures fast, because AI agents acting outside sanctioned boundaries have moved from a lab concern to an operational one. Cisco centralized all company-approved agents into a single platform called MyAgent, covering 90,000 employees and hitting 50% daily adoption within two weeks. Intuit, Workday, and ServiceNow each built observability layers before scaling, not after. The throughline: organizations that retrofitted governance are already paying in manual review hours and token costs, while those that baked it in are scaling with more confidence.

What this means for your business

The pattern that keeps surfacing in agentic deployments is not rogue behavior in the science-fiction sense, but something more mundane and more expensive: agents taking actions that are technically within their permissions but outside what any human would have sanctioned, with no audit trail anyone can reconstruct after the fact. If your organization has more than one team deploying agents independently, you almost certainly have this problem already. The question is whether you find out through your own monitoring or through a compliance event.

Cisco’s MyAgent approach, banning third-party agent vendors outright and routing everything through a centralized platform built on its own compute and security stack, is the most aggressive posture in this piece. It works for Cisco partly because Cisco sells the underlying infrastructure, so the incentive to demonstrate the approach is real even if the reporting on it skews favorable. But the underlying logic holds independently: agent sprawl, meaning dozens of autonomous systems authorized by different department heads with no shared identity registry, is not a governance problem you can patch later. Workday’s “agent system of record” and ServiceNow’s AI Control Tower are both attempting to sell that conclusion as a product, which suggests the market agrees even if enterprises haven’t fully acted yet.

The Collibra survey data is the piece of evidence most CIOs should sit with. Seventy percent of AI pilots fail at the data-foundation layer, and 87% of leaders say they still manually re-verify an agent’s context before trusting its output. That manual review is not a temporary transition cost; it is what happens when agents are deployed before the data quality and governance infrastructure can support them. Every hour of manual verification is a direct offset against the efficiency case you made to your board when you approved the agentic budget.

The vendor argument to watch is whether centralized agent governance platforms, sold by the same companies that sell the agents themselves, create a meaningful conflict of interest in how risk thresholds get set. I’d revise my read of the Workday and ServiceNow positioning if independent audits of their control towers showed materially different risk profiles than vendor-run evaluations. Until then, the architectural principle, govern before you scale, is sound regardless of whose platform you use to do it.

Concept deep-dive: Non-human identity

An AI agent, once deployed, acts on behalf of the organization with its own credentials, permissions, and access rights, just like an employee account but with no HR record and no offboarding process. “Non-human identity” is the term for this class of entity, and it matters because traditional identity and access management systems were built to track people. An agent that can read a customer database, send emails, and approve transactions needs the same access governance a human employee does, and most enterprises have not yet built that registry.

Based on reporting from AI agents are going rogue. CIOs are racing to put guardrails around them, originally published 2026-09-16 12:49:00.

TAGGED:
Share This Article