From the Summer 2026 Issue

AI Without Proper Governance is Dangerous

Justin Petitt
Strategic Capture Manager | Markon Solutions

Larry Letow
CEO | TachTech

Artificial Intelligence (AI) has evolved well past being a technology buzzword into becoming an expected component in day-to-day technology solutions. While AI is still continuing to grow in its scope and capabilities, it has found its way baked into more and more solutions, more devices, and more networks with each passing day. Is it one of the most powerful and capable tools in our current technology generation? Absolutely – much in the same ways that power tools radically changed the capabilities of individual workers, and what they’re able to complete in a much-shortened timeframe. But does that mean we should have three-year-olds working with a table saw, or using a blowtorch? While the answer is easily, and obviously, a resounding “NO” for those scenarios for safety reasons and just general common sense…these same considerations are often failing to be asked and addressed when it comes to implementing and using AI tools, agents, and workflows.

Just about every organization has found ways to implement and integrate AI into their workflows. The promises of AI are too attractive not to – saving time, saving money, acting and reacting faster than regular people can collate, process, and identify next steps to take. It almost sounds too good to be true – and unfortunately for some instances, it is. For all the organizations who have already deployed AI agents, few are paying attention to three core questions that must be included and addressed:

  • What role or persona is the AI Agent operating under, and does its level of access align with what’s actually required to perform its function?
  • What data has the AI Agent touched, and how has it been used? Has any data been altered, retained, or moved outside of its designated secure environment?
  • Is the AI Agent operating within its original configuration and intent, or has its behavior shifted beyond defined boundaries due to user influence or infrastructure limitations?

People aren’t willfully choosing to ignore these questions, and many implement AI Agents and tools with the best of intentions – but with a lack of the technical understanding of what all is actually included, and done, by said tools and users. Good intentions only take you so far, though, and the issue at hand is these AI Agents have the ability to interface and interact in ways that human users simply don’t. Modern AI Agents move faster throughout entire enterprise environments, operate across multiple systems, and don’t leave the same type of audit trail that a person would.

Good intentions only take you so far, though, and the issue at hand is these AI Agents have the ability to interface and interact in ways that human users simply don’t.

The results of all this? AI Agents running with over-provisioned access because of a lack of understanding by those implementing; AI Agents taking actions under shared or unverified identities because of lack of controls; AI Agent behavior that drifts from the original design, quietly, with nobody noticing until something breaks or information starts to show up where it should not. AI is fabulous tool, is absolutely a force multiplier when used correctly, but moving too quickly to adopt and implement without ensuring proper governance of the tools creates a dangerous and rapidly growing gap that most organizations don’t even realize they have.

For those who do recognize this, ideally before problems grow past the point of containment and repair, there are proven solutions available. Make sure your organization or a partner that can assist in the builds and can provide assistance in the governance layer and user friendly interface that answers these focused areas – Identity, Access, and Behavioral Monitoring for AI agents deployed in production and operating environments.

  • Identity— Every AI Agent operating in your environment is issued a verified, scoped identity tied to a defined role and authority level. Every action is attributed – which agent, which user, what was done, and when – eliminating shared credentials, closing gaps in audit trails, and giving you clear, defensible accountability across your entire agent landscape.
  • Access Controls— Agents are granted access to only what their task requires, nothing more. We assess your current access posture, surface areas of excessive or unnecessary permissions, and apply least-privilege policies that are built to hold as your agent deployment scales – so access risk doesn’t quietly compound as your footprint grows.
  • Behavioral Monitoring— We work with your team to define what “normal” looks like for each agent in your environment, then watch for anything that falls outside it. Unexpected data access patterns, unusual API calls, irregular timing -these are the early signals. We help you catch them before they escalate into an incident.

Everyday users, though, are not typically the ones who are focused on the safety, the security, and the restrictions required to ensure tools function as intended.

AI is here to stay, and each day there are new, creative ways to leverage its unprecedented ability to process, analyze, and present data in new and exciting ways. For years now, regular consumers have had access to aspects of these capabilities through ChatGPT, Gemini, Grok, and Claude, and it seems like a natural and easy icebreaker for users to include AI Agents in their day-to-day with their work. Everyday users, though, are not typically the ones who are focused on the safety, the security, and the restrictions required to ensure tools function as intended. This is where AI services companies are able to step in and empower organizations.

Remember, the goal isn’t to slow down your AI initiatives – they’re going to be added and integrated soon, if not already today.

If you’ve deployed agents and haven’t fully and satisfactorily addressed Governance yet, now is the right time before the audit, the incident, the news story, or the question you can’t answer. lock

Larry Letow
Justin Petitt

Leave a Comment