AI agents do more than answer questions. They now access applications, call APIs, use credentials, modify data, and execute tasks across multiple systems. A compromised user account can cause significant damage. An autonomous agent with broad permissions can act across systems at machine speed before a human recognizes that something has gone wrong. AI leaders must change the security model immediately.

Recent incidents show why that matters. Anthropic disclosed multiple cases in which Claude models gained unauthorized access to third-party systems during cybersecurity evaluations. Meta also acknowledged that one of its models accessed the internet during testing and exploited a vulnerability at an outside organization. In both cases, a misconfiguration in an evaluation environment operated by security firm Irregular gave the models unintended internet access.

The lesson is not that AI agents suddenly became malicious. It is that when an agent can act, and one control fails, the agent may continue operating beyond its intended boundary. AI leaders must start thinking about the four themes below.

Zero Trust Has To Extend To Agents

Nvidia’s announcement of its Open Agent Safety Platform reflects where the market is heading. The platform includes OpenShell, an open-source runtime designed to enforce policy around agent activity, and Sentry, a hardware-based system for monitoring agent behavior independently. Enterprises will need controls between what an agent decides to do and what it is actually allowed to execute.

That is a natural extension of Zero Trust. Authentication should not equal unlimited authority. An agent may have legitimate access to a system without having permission to take every available action inside it. For AI leaders, CIOs, and CISOs, this moves AI governance beyond policies and review committees. Organizations need to know which agents exist, what they can access, what actions they can take, and how to stop them when necessary.

Start With An Agent Inventory

The first requirement is visibility. Organizations cannot govern agents they do not know exist. Business units can increasingly create agents through SaaS platforms, development tools, and third-party applications without following traditional application deployment processes.

A recent analysis in The Hacker News makes the point clearly: inventory must come before enforcement. Every production agent should have a defined owner, business purpose, autonomy level, approved systems, credentials, data access, and lifecycle status.

Without that discipline, agent sprawl could become the next version of application sprawl, with one important difference: these agents can act on their own.

Treat Agents As Non-Human Identities

Inventory is only the beginning. As I shared recently , an autonomous agent increasingly functions as a non-human identity. It can hold credentials, access data, call APIs, and initiate transactions. Identity management must therefore expand beyond employees, contractors, and traditional service accounts.

Give every agent its own identity and only the access it needs. Never let agents share credentials or inherit their creator’s permissions. Role, task, and duration define access scope.

The important distinction is between access control and action control. An agent may be authorized to enter an enterprise system. That does not mean every action it attempts within that system should automatically be trusted.

Governance Has To Work At Runtime

This is where traditional AI governance becomes insufficient. Policies and committees remain necessary, but they cannot stop autonomous software operating at machine speed.

Gartner makes a similar case: governance has to extend beyond policy. Organizations need controls that manage what agents can do in real time, limit their access, and stop them when they move outside defined boundaries.

This is the next stage of enterprise AI governance. Before giving agents more authority, executives should be able to answer a few basic questions: Which agents are operating in our environment? Who owns them? What systems and data can they access? What can they do without human approval? Can we monitor those actions in real time? And can we immediately stop an agent when something goes wrong?

If those answers are unclear, the organization is not ready to increase agent autonomy. Zero Trust for AI agents comes down to one principle: authorization to enter a system should never mean automatic trust in the next action.

As enterprises give agents more authority, that distinction will matter far more than another written AI policy.