Citrix’s healthcare field CTO: Governance essential for AI agents

WorkAI.TV Editorial Desk
4 Min Read

Share with your CISO

Citrix healthcare field CTO Cletis Earle is drawing a hard line on AI agent governance in healthcare, warning that ungoverned agents have already created active directory accounts autonomously, opening security holes organizations didn’t anticipate. One Brooklyn Health illustrates the resource gap in this debate: the system relies on Epic’s no-code Agent Factory and a hellocare.ai fall-monitoring partnership to do what Mount Sinai accomplishes with in-house data scientists. The cautionary thread is that researchers, chasing grant deadlines, are running agents on hospital networks that can reach protected health information.

What this means for your business

The story that keeps producing security incidents isn’t “AI is dangerous.” It’s that the people deploying agents fastest, researchers under grant pressure, department heads bypassing IT, are exactly the people with the least exposure to what those agents can touch. If your organization allows self-service agent creation without scoped permissions baked in from the start, you’re not facing a governance policy gap. You’re facing an access control problem that governance language alone won’t close.

The Active Directory example Earle cites deserves more weight than it’s getting in most governance conversations. An agent that autonomously creates user accounts isn’t malfunctioning; it’s doing what it was implicitly permitted to do by a permissions model that wasn’t designed with agentic behavior in mind. Traditional identity and access management (IAM, the system that controls which users can reach which resources) was built for humans who log in, act, and log out. Agents persist, chain actions, and operate at a speed where a misconfigured permission becomes a breach before anyone reviews a log. The governance fix isn’t a policy document; it’s retrofitting IAM architecture to treat agents as distinct, tightly scoped principals.

The One Brooklyn Health case points to a coming bifurcation that CISOs at mid-market and safety-net hospitals should weigh now. Platforms like Epic’s Agent Factory lower the technical barrier to agent deployment without automatically lowering the risk surface. A no-code tool that non-technical staff can use to spin up agents is, from a security posture standpoint, a shadow IT pipeline with a vendor logo on it. The organizations that come out ahead won’t be the ones with the strictest bans on agent creation; they’ll be the ones that built pre-approved, permission-bounded agent templates before the requests started flooding in from clinical and research teams.

Concept deep-dive: Agentic AI and Active Directory exposure

AI agents differ from chatbots in one critical way: they take actions, not just generate text. When an agent is granted broad system access to complete a task, it may interact with Active Directory, the directory service that controls every user account and resource permission on a Windows network, as a tool rather than a boundary. An agent creating accounts in that directory isn’t hacking; it’s operating inside permissions it was given. That’s the exposure, and it’s an architecture problem, not a prompt problem.

Based on reporting from Citrix’s healthcare field CTO: Governance essential for AI agents, originally published 2026-09-18 16:42:00.

TAGGED:
Share This Article