In-Depth
AI Governance Expert: Give Every Agent Its Own Identity -- and a Kill Switch
Enterprise AI governance gets more complicated when AI stops merely generating content and starts taking action inside business systems. An agent that can read customer data, update records, trigger transactions or call other agents creates a different class of operational risk from a chatbot that drafts text.
That distinction was a central theme of Joey D'Antoni's "Building an Enterprise AI Governance Framework" presentation at today's AI Trust & Governance Summit, now being made available for on-demand replay thanks to sponsor AvePoint. D'Antoni, principal consultant at DCAC, argued that organizations need governance that keeps pace with AI adoption without becoming so burdensome that users simply work around it.
"Automation just amplifies whatever process you already have. So if you automate chaos, you get faster chaos."
Joey D'Antoni, Principal Consultant, DCAC
Speaking to the timeliness of the issue -- just glance at the news headlines -- the event was attended by an active audience of more than 100 people, who had plenty of questions that were addressed by D'Antoni during the Q&A.
He opened with a gap highlighted in Schellman's 2026 State of AI Governance research: 74 percent of surveyed organizations said they believed they could pass an AI compliance audit, while only 27 percent described their AI governance programs as fully mature. D'Antoni used that disparity to frame governance not as a brake on adoption, but as something that can let organizations move faster because they have enough control to approve new uses with confidence.
Treat Agents Like New Employees
D'Antoni said agents deserve particular attention because they break an assumption behind more traditional model governance: that organizations can test a system, approve it before launch and then rely heavily on that point-in-time review. Agent behavior can emerge while the system is running as it decides which tools to call, what order to call them in and whether to invoke other agents.
"A useful mental model for how you can think about this is you want to treat an agent like a new employee," he said.
A new hire would not normally receive unrestricted access to every enterprise system on the first day. D'Antoni recommended the same basic approach for an agent: give it its own identity rather than letting it borrow a human user's credentials, grant only the access required for its job, define its purpose explicitly and restrict which data and tools it can use.
[Click on image for larger view.] Agent Controls for Taking Action (source: Joey D'Antoni).
That control should include what D'Antoni called graduated autonomy. For consequential actions, he recommended starting with a human in the loop and expanding autonomy only after monitoring shows the agent behaves predictably over a meaningful period of time.
He also emphasized full action logging so teams can reconstruct what happened when something goes wrong, along with a kill switch capable of stopping an agent quickly and a mechanism for rolling back its actions. The practical goal, he said, is not to assume an agent will never make a mistake, but to be able to detect the mistake, stop it and explain what happened.
The identity issue resurfaced during the Q&A, when D'Antoni said agents can end up operating under a person's account not necessarily because an IT organization designed them that way, but because employees adopting tools on their own may only know how to use their own credentials. That makes agent identity part of the broader shadow-AI problem: organizations first have to know what is operating in their environments before they can govern it.
Automate the Routine, Not Accountability
D'Antoni then turned to the scale problem. A spreadsheet, email and a monthly governance meeting might be workable when an organization has only a handful of AI systems, he said, but the approach begins to strain as the count rises and becomes impractical when hundreds of AI features and agents are changing continuously.
He compared the transition to the security industry's move toward DevSecOps. Rather than putting a manual security gate at the end of development, organizations increasingly embed automated checks into the pipeline so routine issues are caught early and specialists can focus on harder problems. D'Antoni argued AI governance is moving in the same direction.
That can include automated discovery of AI use across software-as-a-service applications, APIs, repositories and endpoints; intake forms that automatically calculate risk tiers and route requests; control mapping across frameworks and laws; automated testing and red-team checks in continuous integration/continuous delivery pipelines; runtime guardrails and monitoring; evidence collection; and regulatory-change tracking.
But D'Antoni drew a firm boundary around decisions that should remain human. Those include accepting residual risk, making ethical trade-offs or value judgments, granting final approval to high-risk use cases and accountability itself.
[Click on image for larger view.] What AI Governance Shouldn't Automate (source: Joey D'Antoni).
"Automation just amplifies whatever process you already have," he said. "So if you automate chaos, you get faster chaos."
His recommendation was to establish the governance model first -- including risk tiers, owners and policies -- and then automate it. Buying a governance platform without deciding how governance will actually work, he warned, does not create a governance program by itself.
Make the Governed Path the Fast Path
That point connected to another theme running through the presentation: governance can fail both by being too loose and by being too restrictive. D'Antoni called the first failure mode the "Wild West," where teams move quickly until an incident causes a shutdown and loss of trust. The second is the "Department of No," where every AI use case faces the same heavyweight review regardless of risk.
The latter can be especially counterproductive because users who find the official process too slow may simply stop using the official process. "People don't stop using AI; they just stop telling you about it," D'Antoni said.
His alternative is a "paved road" in which the governed path is also the easiest path. Risk tiering is central to that approach: low-risk uses can self-attest against standard guardrails and move quickly, medium-risk uses receive a lightweight review, and high-risk systems receive a full assessment, testing and sign-off. He recommended keeping the initial intake to roughly 10 questions and using the answers to route the request automatically wherever possible.
[Click on image for larger view.] Proportionate Review Through Risk Tiers (source: Joey D'Antoni).
That leaves governance specialists more time for the systems that can materially affect people, expose sensitive data, operate autonomously or fall under specific regulatory requirements. It also supports D'Antoni's broader argument that effective governance should help the business adopt AI rather than merely block it.
Broader Framework
D'Antoni's broader framework consisted of five building blocks: visibility into what AI is actually in use, risk tiering, named human accountability, lifecycle controls from design through retirement, and evidence that proves the controls are working. He also discussed the changing regulatory landscape and recommended building around durable principles -- knowing what AI is in use, assessing risk, being transparent, keeping humans accountable and retaining evidence -- rather than designing a program around one law that may change.
He devoted additional time to AI inventory and discovery, including vendor-embedded AI and employee-adopted tools; lifecycle controls around data provenance, privacy, accuracy, bias, robustness and security; monitoring for drift and vendor changes; and evidence collection that happens as a byproduct of normal workflows rather than as a scramble before an audit.
During the Q&A, D'Antoni recommended that organizations trying to close an AI visibility gap start by understanding what people are actually using, including through network monitoring where appropriate, and then build a cross-functional governance council with executive sponsorship. For a mid-sized organization with limited resources, he prioritized inventorying AI use and moving users away from personal AI accounts toward centrally managed enterprise accounts that provide logging and administrative controls.
And More
While replays are convenient and informative -- especially up-to-date sessions that just concluded -- attending live events offers advantages, including the ability to ask specific implementation questions and receive guidance in real time (not to mention the chance to win great prizes, in this case a Nespresso bundle, thanks to sponsor AvePoint, which also presented at the summit). With that in mind, here are some upcoming online webcasts from Virtualization & Cloud Review:
Also upcoming are these online virtual summits from Redmond:
About the Author
David Ramel is an editor and writer at Converge 360.