Agentic AI forces security workflow overhaul

Gradient Flow

The gist

Enterprises rushing to deploy agentic AI are hitting a wall as legacy infrastructure, security, and oversight models buckle under the demands of autonomous, persistent, and increasingly powerful machine agents.

What to know

  • 83% of organizations say they must overhaul infrastructure to handle stateful, always-on AI workloads and complex orchestration.
  • 97% of AI-related breaches are blamed on weak or outdated access controls, fueling a scramble for dynamic, multi-layered governance frameworks.
  • Human roles are shifting from doing the work to policing and auditing AI agents, as platforms like Fabric.AI and Mobcoder AI bake in compliance, observability, and human-in-the-loop checkpoints from day one.

Orchestration: The AI Backbone

Persistent, goal-driven AI agents force enterprises to overhaul not just infrastructure but operational logic, with orchestration and state management emerging as the new bottlenecks for scale and reliability.

Deploying production-grade agentic AI in enterprises demands a fundamentally different infrastructure paradigm than traditional AI models or web applications, as these agents operate persistent, stateful workloads that autonomously execute multi-step workflows. Unlike stateless web apps that scale predictably with request rates, agentic AI requires continuous context maintenance, complex orchestration of planning, retrieval, tool invocation, validation, and response generation, and robust state management to preserve accumulated knowledge over extended periods. This shift from isolated task execution to integrated, goal-driven workflows introduces new operational complexities around capacity planning, error handling, and workflow checkpoints to ensure reliability and continuity.

Orchestration emerges as the linchpin of agentic AI infrastructure, coordinating specialized agents across diverse enterprise systems such as ERPs and CRMs while preventing failures like duplicate actions, circular plans, or operations executed out of sync with changing business contexts. Leaders like Gonçalo Borrêga of OutSystems emphasize that as agentic AI scales, the orchestration challenge intensifies, requiring support for idempotent actions, robust task sequencing, observability, and human intervention capabilities. Surveys reveal that 89% of organizations with fully embedded orchestration report meeting or exceeding ROI expectations, underscoring orchestration’s critical role in transforming agentic AI from pilot projects to scalable enterprise solutions.

Security and governance complexities multiply in agentic AI deployments because agents act with credentials, necessitating fine-grained identity and authorization controls rather than broad permissions that simplify development but increase risk. This architectural imperative is compounded by the need to manage data locality, retention, isolation, and compliance across hybrid environments spanning on-premises, edge, and cloud infrastructures. As Atos and Gartner highlight, enterprises must balance business value with stringent governance and operational controls to scale autonomy responsibly, ensuring that AI agents interact securely with sensitive systems through validated application layers that enforce business rules and permissions.

Despite rapid advances in model efficiency—such as the drop in GPT-3.5 query costs from $20 to $0.07 per million tokens by late 2024—capacity planning and cost management remain formidable challenges due to the multiplicity of model calls per task and the unpredictable compute demands of complex reasoning and tool usage. A 2026 Google report found that 83% of organizations acknowledge the need to upgrade their infrastructure to support persistent, stateful agentic workloads, yet only 17% feel fully confident in their current capabilities. This readiness gap highlights the urgent necessity for infrastructure modernization that supports continuous execution, hybrid workflows combining automated and human-in-the-loop processes, and seamless integration with legacy systems without disruptive overhauls.

Sources

Governance for Autonomous Agents

Static policies crumble as enterprises adopt multi-layered controls—like behavioral monitoring and kill switches—to keep autonomous AI agents accountable and aligned with business and regulatory demands.

Deploying autonomous AI agents in enterprises demands a robust governance framework that transcends traditional static policies and prompt-based controls, which are insufficient given the dynamic, probabilistic nature of agentic AI. As highlighted by multiple analyses, effective governance requires multi-layered control mechanisms, including rigorous code review, integrated security tools like IBM Bob and open-source solutions, and continuous behavioral monitoring systems such as Scout Agentics' Cortex, which detects patterns of inappropriate coordination or concealment. This layered approach ensures that agents operate within defined boundaries while enabling rapid human intervention through mechanisms like dedicated 'kill switch' agents that can terminate errant AI behavior without delay.

Identity and access management (IAM) for AI agents must evolve beyond legacy models to accommodate the unique challenges posed by autonomous agents operating at machine speed with dynamic permission acquisition. Enterprises face significant risks from overprovisioned or shared credentials, as evidenced by Gravitee's 2026 survey revealing that 46% of teams still rely on shared API keys, and IBM's 2025 study where 97% of AI-related breaches were linked to inadequate access controls. To mitigate these risks, organizations must implement fine-grained, task-scoped permissions with continuous oversight, combining RBAC, ABAC, PBAC, and ReBAC models, and treat AI agents like digital employees with dedicated identities that can be provisioned, monitored, and revoked independently.

A critical governance challenge is the 'Autonomous Authority Gap,' where AI agents possess decision-making capabilities without clear enterprise authorization or accountability frameworks. This gap complicates responsibility assignment, as ownership is often fragmented among platform teams, business units, vendors, and model creators, leaving human operators primarily accountable despite ambiguous liability. Experts like KPMG's John Kirk emphasize the necessity of embedding accountability explicitly within operating models, defining who can override or deactivate agents, and aligning governance with regulatory standards such as Australia's APRA CPS 230 and SOCI Act to ensure operational resilience and security.

Despite rapid adoption, governance maturity lags significantly, with only 13% of organizations confident in their AI governance and 36% having centralized oversight, leading to widespread visibility and control gaps. The 2026 EMA report found that 65% of enterprises experienced AI agents acting outside intended scopes, yet only a third could detect and contain such incidents promptly, and nearly half lacked comprehensive audit trails. This disconnect between written policies and enforcement underscores the urgent need for real-time governance, standardized data and integration controls, and disciplined agent decommissioning to prevent AI sprawl, reduce compliance risks, and maintain enterprise security integrity.

Sources

Redefining Human-AI Collaboration

Human roles shift from task execution to oversight and exception management, as organizations redesign workflows and job descriptions to harness agentic AI without sacrificing transparency or accountability.

Integrating agentic AI into enterprise workflows demands a fundamental redefinition of human roles from direct task execution to oversight and exception management. As enterprises transition from AI as a mere assistive tool to fully autonomous agents handling end-to-end operations, humans increasingly become custodians of policies and judgments, intervening primarily in complex or ambiguous scenarios. This evolution is exemplified in back-office automation where audit trails with step-by-step screenshots provide transparency and accountability, fostering trust in AI-driven decisions and enabling precise post-hoc analysis when issues arise.

Effective human-agent collaboration hinges on redesigning organizational communication and operational structures to support dynamic AI interactions while preserving human oversight. Companies like those leveraging Slack-based agentic communication platforms illustrate how AI drafts and manages most messages, with humans reviewing and refining tone and nuance to maintain brand voice and trust. Beyond communication, enterprises must establish new roles—such as specification authors, verifiers, and line owners—who hold clear authority over AI workflows, including the critical power to halt autonomous processes, ensuring safety and quality in AI-driven delivery lines.

Organizational adaptation to agentic AI is not a one-size-fits-all endeavor but requires deliberate cultural preservation alongside targeted problem-solving. Leaders are urged to explicitly identify cherished aspects of company culture and pain points that AI agents can address, rather than assuming automation will inherently resolve existing inefficiencies. This mindset shift is supported by data showing that 66% of organizations already experience measurable productivity gains from human-AI collaboration, with nearly half having clearly defined roles and responsibilities that empower employees to effectively partner with AI in daily work.

Sustainable scaling of AI agent deployment demands a recalibration of human workforce composition and accountability frameworks. While agentic AI can offload implementation tasks, human engineers must increasingly focus on specification, verification, fleet operation, and maintaining the authority to intervene, as output scales do not translate directly to increased human capacity. Leading organizations recognize that designing explicit human-AI operating models and accountability structures—where decision ownership remains clear and oversight is embedded—creates a competitive advantage by fostering adaptive, resilient workflows that balance automation with human judgment and ethical reasoning.

Sources

Built-In Trust and Oversight

Next-gen AI platforms embed governance, observability, and layered security from day one, transforming anomaly detection and kill switches into core pillars of safe, scalable enterprise AI.

Emerging governed AI platforms like Fabric.AI’s Governed Vibe Ops and Mobcoder AI’s 'Governed by Design' methodology are pioneering integrated solutions that embed governance, security, and compliance from the ground up, rather than as afterthoughts. These platforms unify multi-vendor operational data and embed robust mechanisms such as code review, version control, and testing tools like Playwright, enabling enterprises to deploy agentic AI reliably at scale while maintaining strict oversight. Mobcoder AI further enhances scalability by employing multi-agent architectures with defined permissions and human-in-the-loop checkpoints, supported by comprehensive enterprise stacks that include cloud infrastructure and compliance frameworks tailored for regulated environments.

Observability is rapidly evolving from mere system visibility to a sophisticated anomaly detection discipline critical for trustworthy agentic AI operations. Experts like Abi Aryan and Chris Arroyo emphasize reframing observability as a fraud detection pipeline, leveraging extensive logging and simple machine learning models to detect deviations across multiple metrics. This approach not only supports security and change management but also ties AI infrastructure costs directly to mission outcomes, enabling stakeholders to justify investments and continuously align AI models with specific application needs through phased deployment strategies with strict guardrails.

Security best practices for agentic AI increasingly incorporate innovative mechanisms such as kill switches, where one AI agent monitors and can halt another to prevent undesired actions, embodying the principle of 'do no harm' and fostering organizational trust. This layered oversight is complemented by governance controls that manage autonomy levels, ensuring safe operation within complex enterprise environments. As AI agents become more autonomous, these safeguards are essential to balance innovation with risk mitigation, addressing concerns raised by leading analysts about the missing decision layers in agent autonomy.

Addressing the operational challenges of data context sprawl and inference economics is critical for sustainable agentic AI deployment. Michel Tricot of Airbyte highlights the 'data ingestion crisis,' advocating for strict data permissions and automated entity resolution to maintain reliable workflows. Simultaneously, Nathan Lambert warns that reliance on subsidized API token usage is unsustainable, urging enterprises to plan for ownership of inference sources and implement cost-saving strategies like caching and memory optimization. These approaches are vital to prevent operational emergencies and enable scalable, cost-effective AI-driven autonomous workflows.

Sources

Part of these trends

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.