Building agent-first governance and security


According to the Deloitte AI Institute 2026 State of AI report, nearly 74% of companies plan to deploy agentic AI within two years. Yet only one in five (21%) reports having a mature model for governance of autonomous agents. Executives are most concerned with data privacy and security (73%); legal, intellectual property, and regulatory compliance (50%); followed closely by governance capabilities and oversight (46%).

Enterprises may not even realize they are treating agents within their environment as first-class citizens with the keys to the kingdom, creating looming blind spots and potential points of exposure. What is needed is a robust control plane that governs, observes, and secures how AI agents, as well as their tools and models, operate across the enterprise.

“A control plane is the shared, centralized layer governing who can run which agents, with which permissions, under which policies, and using which models and tools,” according to Andrew Rafla, principal, Deloitte Cyber Practice.

“Without a true control plane, you don’t really have the ability to scale agents autonomously—you just have unmanaged execution, and that comes with a lot of risk,” he says. “If you can’t answer what an agent did, on whose behalf, using what data, under what policy—and whether you can reproduce or stop it—you don’t have a functional control plane.”

Governance must make those answers obvious, not aspirational, he says. Governance is what turns AI pilots into production use cases. It’s the bridge that lets companies move from impressive experiments to safe, repeatable, enterprise-wide automation.

Without governance, agent deployments don’t fail safely. They fail unpredictably and at scale.

Download the article.

This content was produced by Insights, the custom content arm of MIT Technology Review. It was not written by MIT Technology Review’s editorial staff. It was researched, designed, and written by human writers, editors, analysts, and illustrators. This includes the writing of surveys and collection of data for surveys. AI tools that may have been used were limited to secondary production processes that passed thorough human review.



Source link

  • Related Posts

    Microsoft removes Call of Duty from Game Pass, lowers subscription pricing

    Microsoft announced Tuesday that subscribers to its Game Pass service will see significant price reductions starting today. But those subscribers will also be losing included day-one access to Activision’s popular…

    Mozilla Used Anthropic’s Mythos to Find and Fix 151 Bugs in Firefox

    Amid a raging debate over the impact that new AI models will have on cybersecurity, Mozilla said on Tuesday that its Firefox 150 browser release this week includes protections for…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Sarah Pidgeon’s Airport Look Includes French Girl Jeans and Flats

    Sarah Pidgeon’s Airport Look Includes French Girl Jeans and Flats

    Winnipeg council to vote on removing member accused of sex crime from duties

    Winnipeg council to vote on removing member accused of sex crime from duties

    Venezuela Creditors Met With Trump Officials to Discuss Rebuild

    Slain Mountie's family decries 'systemic failure' after suspect ruled unfit for trial

    Slain Mountie's family decries 'systemic failure' after suspect ruled unfit for trial

    Microsoft removes Call of Duty from Game Pass, lowers subscription pricing

    Microsoft removes Call of Duty from Game Pass, lowers subscription pricing

    First attack ad churns Georgia’s uncertain Republican Senate primary

    First attack ad churns Georgia’s uncertain Republican Senate primary