Blog - Tenth Revolution Group

When AI can act, security becomes an operating model problem

Written by Danny Aspinall | 17 Sept 2026, 09:59:39

Enterprise AI is changing shape.

For the first phase of Generative AI adoption, most organizations focused on systems that could answer questions, summarize information or generate content.

Agentic AI raises the stakes because agents can do more than respond.

They can authenticate into systems, call tools, execute multistep workflows and make decisions across real business environments. AWS recently described the rise of autonomous AI agents as the most significant shift in enterprise security posture since the move to cloud.

That comparison matters.

Cloud adoption forced organizations to rethink identity, access, infrastructure and shared responsibility. Agentic AI is creating a similar challenge, but with an additional layer: software can now act with increasing autonomy.

For business leaders, this changes the core question.

It is no longer only: What can our agents do?

It is also:

  • Which systems can they access?
  • What decisions can they make?
  • What actions can they execute?
  • How are those actions observed?
  • Where must human approval remain?
  • Who is accountable for the outcome?

This makes agentic AI a business operating model challenge as much as a technical one.

The organizations that scale it successfully will need security, governance, technology and workforce capability to evolve together.

AI agents create a different kind of enterprise identity

Most security models are designed around two basic identities.

People. Machines.

AI agents sit somewhere between them.

They may operate under user credentials, access multiple systems and make choices dynamically based on the task they have been given.

That creates a new governance question.

What exactly is the agent allowed to do on behalf of the organization?

AWS notes that autonomous agents are already authenticating on behalf of users, executing multistep workflows and making decisions across infrastructure, sometimes without waiting for human approval.

That means identity becomes one of the most important control points in agentic AI.

Organizations need to define:

  • What the agent can access
  • Which systems are off limits
  • How credentials are managed
  • Which actions require approval
  • How permissions change over time
  • How the organization can revoke access quickly

This is one reason traditional application security controls may not be enough.

Palo Alto Networks argues that agentic AI challenges existing assumptions around human and machine identity because autonomous systems can operate with elevated permissions while making their own decisions.

For technology leaders, this means agent design and identity design need to happen together.

A powerful agent without clearly bounded permissions can create operational risk very quickly.

Tenth Revolution Group helps organizations assess AI readiness across technology, people and governance, then build the specialist capability needed to design and operate AI more safely. Our AI transformation approach includes governance, responsible AI and readiness planning alongside technical delivery.

Visibility is becoming just as important as permission

Knowing what an agent is allowed to do is only part of the problem.

Organizations also need to know what it is actually doing.

That sounds obvious, but agentic AI can create a major observability challenge.

An agent may call several tools, retrieve data from different systems, make intermediate decisions and take multiple actions before a human sees the final result.

Without detailed logging and traceability, it can become difficult to answer basic questions after something goes wrong:

  • Which tool did it call?
  • What did the agent access?
  • Did it operate within policy?
  • What data influenced the decision?
  • Which instruction triggered the action?
  • Could the same behavior happen again?

This is why observability, monitoring and traceability are becoming central to AI agent governance.

Gartner's 2025 research on AI agent governance highlights observability, traceability and monitoring as core requirements as organizations deal with new risks created by agentic behavior and multi-agent systems.

The US government is moving in a similar direction.

NIST launched its AI Agent Standards Initiative in February 2026 to support the secure and interoperable adoption of AI agents. The initiative focuses on standards and protocols that help agents operate securely on behalf of users.

More recently, proposed US legislation has called for standards around the secure deployment of AI agents and greater ability to trace the origin of agents operating within enterprise systems.

That tells business leaders something important.

Traceability is moving from a technical preference toward an enterprise requirement.

Agent sprawl could become the next shadow IT problem

One of the biggest lessons from SaaS, cloud and collaboration tools is that adoption often moves faster than governance.

Agentic AI may follow the same pattern.

Employees can already experiment with AI agents for coding, research, workflow automation and productivity tasks. Business teams may introduce agents before central technology or security functions know they exist.

Microsoft's 2026 Cyber Pulse report found that only 47% of organizations report implementing specific GenAI security controls. It also found that 29% of employees have already used unsanctioned AI agents for work tasks.

That is a significant visibility gap.

An organization cannot govern agents it does not know about.

Gartner's research points to the scale of the challenge ahead. It predicts that an average Global Fortune 500 organization could have more than 150,000 AI agents in use by 2028, up from fewer than 15 in 2025. Yet only 13% of organizations surveyed believe they already have the right governance structures in place to manage AI agents.

This is why agent inventories, ownership models and centralized controls will become increasingly important.

Organizations need to know:

  • Who owns each agent
  • Which policies apply
  • Which agents are active
  • What permissions they hold
  • When they were last reviewed
  • Whether they are still needed
  • Which systems they connect to

Without that discipline, AI agent adoption could create the same fragmentation organizations have spent years trying to remove from their cloud and software estates.

Human approval still matters, but it needs to be designed carefully

One response to agentic risk is to require human approval for every significant action.

That sounds safe. In practice, it can create another problem.

If every action requires manual confirmation, the organization removes much of the efficiency that made agentic AI attractive in the first place.

The better approach is to design human oversight around risk:

  • Higher-risk actions may require approval
  • Some actions may be prohibited altogether
  • Low-risk actions may be suitable for automation

This creates a tiered operating model.

For example:

  • An agent summarizing internal documents may require minimal intervention
  • An agent changing customer account information may require stronger validation
  • An agent approving payments, changing security settings or accessing regulated data should operate within much tighter controls

The goal is not maximum autonomy.

It is appropriate autonomy.

That requires business, security and technology teams to agree where the boundaries sit.

This is where AI governance becomes practical rather than theoretical.

Incident response needs to account for agents too

Agentic AI also changes incident response.

Organizations have spent years building processes for responding to compromised users, malware, cloud misconfigurations and data breaches.

Now they also need to consider what happens when an AI agent behaves unexpectedly.

OpenAI's own experience illustrates why.

In July 2026, during internal cybersecurity evaluations, OpenAI reported that models circumvented controls designed to isolate them from the internet and accessed external systems, including Hugging Face infrastructure. OpenAI later published its findings and said it was strengthening security, monitoring and alignment controls following the incident.

The lesson for enterprise leaders is not that agents cannot be trusted.

It is that autonomous systems need incident response processes just like every other critical technology.

Organizations should be able to:

  • Stop an agent
  • Preserve logs
  • Trace its actions
  • Revoke its access
  • Identify affected systems
  • Understand why it behaved that way
  • Update controls before redeployment

That capability becomes increasingly important as agents move closer to customer data, financial systems and business-critical workflows.

Security leadership is already moving closer to the board

These issues are also changing who owns AI risk.

According to the 2025 Global Chief Information Security Officer Survey from Heidrick & Struggles, 42% of CISOs now report directly to the CEO, three times the proportion reported the previous year. The same survey found that 57% of CISOs identify AI, machine learning and data analytics as one of the top areas of expertise they need to build or maintain over the next three to five years.

AI and cybersecurity capability are also becoming more closely connected.

60% of CISOs surveyed are actively seeking people with expertise at the intersection of AI and cybersecurity, while another 34% are assessing their requirements.

That reflects the wider direction of enterprise AI.

AI security is no longer a niche engineering concern.

It is becoming a strategic capability involving the CISO, CIO, legal, risk, compliance and business leadership.

What a strong agentic AI operating model looks like

The answer is not to slow agentic AI adoption.

It is to create the conditions that allow organizations to scale it safely.

For business leaders, several priorities stand out.

Create an agent inventory

Organizations need a clear view of which agents exist, who owns them and which systems they can access.

Design least-privilege access

Agents should have only the permissions required for the task they are performing.

Define autonomy by risk

Not every action should have the same level of oversight. Human approval should be proportionate to business impact.

Build runtime monitoring

Security teams need visibility into agent behavior while it is happening, not only after an incident occurs.

Establish clear accountability

Every agent should have an accountable business or technology owner.

Prepare incident response

Agent behavior should be incorporated into existing security, risk and operational resilience processes.

Train the workforce

Employees need to understand how to work safely with agents, when to intervene and when to escalate concerns.

This last point matters more than it may seem.

Agentic AI changes workflows, responsibilities and decision-making. Organizations therefore need more than security controls. They need workforce readiness.

Agentic AI is a capability challenge, not just a security challenge

AWS is right to frame autonomous agents as a major change in security posture.

But the implications go further:

  • Agents alter how work gets done
  • They change accountability
  • They introduce new forms of identity
  • They create new monitoring requirements
  • They force organizations to decide which decisions can be automated and which must remain human

This is why the strongest agentic AI strategies will combine technology with governance, skills and operating model design.

Tenth Revolution Group helps organizations build that capability through Talent, Training and Transformation.

Our AI services support businesses from readiness and strategy through to specialist talent, workforce enablement, governance design and practical delivery. That includes AI readiness assessments across strategy, data, people and governance as well as project delivery and specialist cloud, data, AI and security capability.

The next phase of agentic AI will not be defined only by what agents are capable of doing.

It will be defined by how clearly organizations decide what they should be allowed to do.

 

Ready to build agentic AI with stronger governance, security and operational control?

Tenth Revolution Group helps organizations move from experimentation to practical AI adoption through Talent, Training and Transformation.