Skip to main content
Back to News Hub
📐SiliconANGLE AI
August 31, 2026
Regulation & Policy

Rogue agents are forcing a governance reckoning as enterprises hand over the keys

Overview

As autonomous AI agents take on critical enterprise tasks, businesses face growing governance and security challenges. Companies lack established auditing frameworks for these digital workers, leading firms like Broadcom to advocate for treating agents as distinct identities. By applying controls around identity, intervention, and inspection, organizations aim to monitor and secure agent actions across their systems.

Key Takeaways

  • Enterprises are increasingly deploying autonomous software agents to handle important workflows involving corporate data and application programming interfaces.

    Unlike human employees, these digital tools operate without badges, paychecks, or established audit records.

  • While historical regulations like Sarbanes-Oxley mandated strict employee access certification, no equivalent standard currently exists for artificial intelligence agents.

    To address these security vulnerabilities, experts recommend treating software agents as unique digital identities.

  • The proposed framework relies on three fundamental principles: identity, intervention and inspection.

    Rather than rebuilding existing infrastructure, organizations can begin by watching traffic patterns to identify active agents.

  • Autonomous AI agents are taking over core enterprise operations without traditional employee access controls or audit histories.

    Clayton Donley of Broadcom Inc. highlights that compliance regulations such as Sarbanes-Oxley currently lack established practices for certifying agent permissions.

  • Security teams can start controlling agents passively by monitoring network traffic before swapping third-party developer keys for centralized enterprise keys.
Rogue agents are forcing a governance reckoning as enterprises hand over the keys

Enterprises are increasingly deploying autonomous software agents to handle important workflows involving corporate data and application programming interfaces. Unlike human employees, these digital tools operate without badges, paychecks, or established audit records. Clayton Donley, vice president and general manager of the Identity Management Security Division at Broadcom Inc., noted at VMware Explore 2026 that business units are moving quickly to implement agents even though IT oversight structures remain underdeveloped.

While historical regulations like Sarbanes-Oxley mandated strict employee access certification, no equivalent standard currently exists for artificial intelligence agents. To address these security vulnerabilities, experts recommend treating software agents as unique digital identities. Broadcom is extending distributed application tracing to monitor prompts and tool calls, offering clear visibility into an agent's precise actions.

The proposed framework relies on three fundamental principles: identity, intervention and inspection. Rather than rebuilding existing infrastructure, organizations can begin by watching traffic patterns to identify active agents. Security teams can then replace individual access tokens, such as a Claude key or OpenAI key, with central corporate keys to prevent agents from bypassing governance rules.

For more details please read the original article at SiliconANGLE AI.

Continue Learning

Comments

Comments appear only after moderation. Your email identifies your submission to the moderator and is never displayed here.

No approved comments yet.

Originally published by SiliconANGLE AI
Read the original