From Answering to Acting
A quiet shift has been happening inside UK IT departments over the past eighteen months. It isn’t the arrival of AI itself. Most organisations passed that milestone a while ago. It’s the arrival of AI that acts, rather than AI that merely answers.
An assistant that summarises a document or drafts an email is, from a security standpoint, relatively contained. An agent that reads your CRM, updates a customer record, triggers a workflow in your finance system, and escalates an exception to a human only when it hits a threshold: that’s a different category of risk entirely. It has permissions. It takes actions. And in many organisations, nobody has quite worked out who owns it.
This is the governance gap, and it’s becoming one of the more pressing problems in enterprise IT. Boards are asking for AI adoption to move faster. Security teams are being asked, often in the same meeting, to make sure that speed doesn’t come at the cost of control. Reconciling the two is proving harder than most roadmaps assumed it would be.
Why Traditional Identity Management Wasn’t Built for This
Traditional identity and access management was built around a simple assumption: the entities requesting access to systems and data are humans, and humans can be onboarded, trained, reviewed and offboarded through fairly predictable processes. Non-human identities existed, but they were mostly service accounts and APIs: narrow, well-understood, and rarely the subject of a security incident.
Agentic AI breaks that assumption. An agent might have standing permissions across multiple systems. It might chain actions together in ways no single human reviewer authorised in advance. It might be spun up by a well-meaning business user in a low-code platform, entirely outside the visibility of the security team, a phenomenon some are now calling shadow AI, echoing the shadow IT problem of the cloud era, except this time the “shadow” software can independently take actions on live systems.
Four Principles for Closing the Gap
A handful of principles are emerging as best practice for organisations trying to close this gap before it becomes an incident report.
- Treat agent identities like employee identities, not service accounts. That means lifecycle management: provisioning, review and deprovisioning, tied to a named business owner accountable for what the agent does.
- Apply least-privilege by default. An agent that only needs read access to a customer record should never have write access “just in case it’s useful later.” Permissions creep is as dangerous for agents as it is for people, arguably more so, because agents don’t get suspicious of their own behaviour.
- Build in observability from day one. If you can’t see what your agents are doing in production (which systems they’re touching, what decisions they’re making, where they’re escalating to a human), you can’t govern them, no matter how good the underlying model is.
- Classify data before you connect it. Agents are only as safe as the data estate they’re plugged into. An agent with broad access to poorly classified, poorly labelled data is a data leakage incident waiting for a prompt.
None of this is exotic advice. It’s largely an extension of Zero Trust principles that most security teams already understand. What’s changed is the speed and scale at which it needs to be applied, and the fact that business teams, not just IT, are increasingly the ones deploying these tools.
See also: Education Technology Trends
Where This Leaves Security Leaders
Microsoft has been fairly explicit that this is where its own AI Cloud roadmap is heading, building governance and observability directly into the control plane for agents rather than treating it as an afterthought. Transparity’s overview of what it takes to become what Microsoft calls a Frontier Firm goes into some detail on the security foundations, namely identity, access and continuous assurance, that organisations need in place before scaling agentic AI responsibly, and it’s a decent checklist for any security leader wondering whether their governance model is still built for a world where AI only answered questions rather than acted on them.
The uncomfortable truth is that most organisations’ AI ambition is currently running ahead of their AI governance. That gap closes in one of two ways: proactively, through the unglamorous work of extending identity and access frameworks to cover agents before they’re deployed at scale, or reactively, after an incident forces the issue. Security teams that have been through both know which one they’d recommend.



