As autonomous as possible, as bounded as necessary
AI is terraforming the enterprise, and it is doing so faster than most security architectures were designed to absorb.
Our defenses grew up around people and applications: someone signs in, software does what it was written to do, and we draw lines around both. Agents break that pattern. They act on someone’s behalf, call tools, and increasingly pass work to other agents, each receiving only part of the evidence and deciding whether to act.
The agent risk we face now runs the length of the stack and the depth of the delegation chain, which is a harder shape than the one most of our controls were built to hold.
Length, because a single agent can touch process, data, applications, models, and infrastructure in one motion. Depth, because every handoff is a place where intent drifts and accountability thins. A safeguard that watches one layer, or one hop, sees only part of the picture.
Beneath both sits a question of ontology: what exists in the enterprise, and how those things relate. An agent can only respect a boundary it can name. If we have not agreed on what counts as an asset, an identity, sensitive data, or the authority to act, our rules stay ambiguous, and every handoff reinterprets them. Nor can we let an agent blur what it observed, what it inferred, and what is actually the case. Its confidence rarely tells us which is which.
The discipline it calls for is a familiar one: as autonomous as possible, as bounded as necessary.
Architecture has always worked this way: clear boundaries, real freedom inside them. With agents, that means deciding what each may do, keeping a record of what it actually did, and checking those actions against the evidence rather than the agent’s own account. Autonomy earns its place when we can explain and defend it.