How Agentic AI Outpaces Enterprise Governance

WorkAI.TV Editorial Desk
4 Min Read

Share with your CISO

Agentic AI, meaning AI systems that act autonomously across enterprise systems without a human approving each step, is moving faster than the governance frameworks meant to contain it. Richard Cassidy, CISO international at Rubrik, argues that the foundational problem isn’t the agents themselves but the data and identity hygiene underneath them, a problem enterprises have failed to solve for three decades. His core position, covered in this BankInfoSecurity interview, is that scoping agent permissions narrowly and knowing exactly what an agent can touch is the minimum viable control before any deployment goes live.

What this means for your business

Most enterprises deploying agentic AI are doing it with identity and data access models that were designed for humans logging into systems, not for software agents that can query, write, and act across dozens of systems simultaneously. If your organization has broad, inherited permissions sitting in your data environment, and most do, every agent you launch inherits that blast radius. The question isn’t whether you trust the agent at launch. It’s whether you’ve constrained what it can reach when it does something unexpected, because it will.

Cassidy’s framing of agentic AI incidents as analogous to ransomware recovery is the sharpest idea here, and it deserves to be taken seriously rather than treated as vendor positioning from a company that sells data protection. The operational logic holds independently: if an agent corrupts or exfiltrates data, you need a clean rollback point and a complete audit trail of what the agent touched, at both the data layer and the identity layer. Enterprises that haven’t defined that rollback point before deployment are essentially running without a recovery plan. That’s not a future risk, it’s a current architectural gap.

EMEA regulators are already ahead of North America on mandatory AI controls, which means multinationals running agentic workflows across jurisdictions are managing two different compliance postures simultaneously. The CISO who treats this as a single global governance problem will underestimate the regional specificity required. I’d revise this assessment if North American regulators move meaningfully on agentic AI accountability in the next 18 months, but the current trajectory suggests the compliance gap widens before it closes, and the organizations that built EMEA-grade controls first will find them cheaper to extend than to retrofit.

Concept deep-dive: Least-privilege access for AI agents

Least-privilege access means giving any system, user, or agent only the permissions it strictly needs to complete its task, nothing more. For human users, this is standard security hygiene. For AI agents, it’s harder because agents are designed to be autonomous and flexible, so their scope of action is often defined loosely at deployment. Think of it as the difference between giving a contractor a master key versus a key to the one room they’re working in. The business case is simple: a narrowly scoped agent causes bounded damage when it fails.

Based on reporting from How Agentic AI Outpaces Enterprise Governance, originally published 2026-09-25 17:42:00.

TAGGED:
Share This Article