Enterprises must prioritize governance amid agentic AI boom

by
0 comments
Enterprises must prioritize governance amid agentic AI boom

Agentic AI governance is becoming an urgent priority for enterprises as autonomous agents move into mainstream business use. Security leaders from Okta and Accenture argued in a recent joint discussion that companies should treat AI agents as formal digital identities — managed, monitored, and audited much like human employees — because most organizations are far less prepared for the security risks than their adoption rates suggest.

The agentic AI governance gap

The numbers behind the warning are stark. According to Okta research, 91% of organizations already use AI agents in some capacity, but only about 10% have an effective strategy for managing them. Accenture’s State of Cybersecurity Resilience 2025 research points in the same direction, finding that roughly 90% of organizations lack a clear strategy for managing AI-related threats. The gap between adoption and governance leaves over-privileged, unmanaged agents operating inside enterprise systems.

Harish Peri, senior vice president and general manager of AI security at Okta, warned that 2026 could bring a new form of identity sprawl: organizations may soon have tens or even hundreds of agents working on their behalf, and every one of them needs access to internal systems to be useful. In his framing, the question of what an agent is, and what it is allowed to access, becomes the key to everything else.

Why agents need identities

Unlike traditional chatbots, modern agents can directly interact with and control enterprise systems, performing tasks previously reserved for human workers. Accenture’s identity security lead in the discussion argued that agents should therefore be treated as individual entities with defined identities and lifecycle management — onboarded, governed, and eventually deprovisioned, not unlike employees.

Stripped of the hype, the panelists described a familiar problem: authentication, authorization, and access control at scale. A machine is talking to a resource, and someone must decide whether it should be allowed there, who grants the access, for how long, and who revokes it. What makes the agentic era different is pace. Engineering teams are often pushed to prioritize speed over governance, which produces large numbers of unmanaged non-human identities across enterprise environments.

Practical implications for organizations

The identity-first approach has concrete consequences. Once each agent has its own identity, standard machinery follows naturally: role-based access control can scope what an agent may touch, audit logs can attribute every action to a specific agent, credentials can be rotated or revoked centrally, and compliance reporting can cover human and non-human actors alike. Okta and Accenture have published a joint point of view on securing AI agents at scale that develops these themes.

Speakers also stressed sequencing: governance models and standards should be in place before large-scale deployment, not retrofitted afterwards. Regulatory pressure is expected to reinforce this, with compliance regimes taking shape in the US and EU that will demand greater transparency and accountability for automated agents. For smaller organizations, the same logic applies at reduced scale — an inventory of which agents exist, what they can access, and who owns them is a realistic first step. Related technical questions about how agents behave under resource constraints are covered in this post on agent planning under budgets.

Limitations and what to watch

Some caution is warranted when reading vendor-led research. The headline statistics come from surveys commissioned by companies that sell identity and security products, so definitions of “using AI agents” and “effective governance” may be generous. Survey figures also vary between studies and years. That said, the underlying trend — rapid agent adoption outpacing governance — is corroborated across multiple independent surveys and by regulators’ growing attention. Key developments to watch include emerging standards for agent identity and delegation, how the EU and US regulatory frameworks define accountability for autonomous agent actions, and whether identity platforms converge on a common way to represent non-human workers.

Related Articles