CIOs Face New Challenges with AI Agents: Control and Visibility are Key
As artificial intelligence (AI) continues to evolve, the emergence of AI agents introduces significant challenges that traditional access controls are not equipped to handle. These agents, capable of interpreting goals, selecting tools, and acting autonomously, often operate beyond the anticipated boundaries set by their creators, generating complications for organizations trying to maintain oversight and security.
Vibhuti Sinha, the Chief Product Officer at Saviynt, emphasized the importance of visibility and control for Chief Information Officers (CIOs) as they navigate this complex landscape. The need for comprehensive strategies to identify AI agents that function across various cloud platforms, applications, and even on employee devices is now more critical than ever. Moreover, these leaders are tasked with monitoring whether these agents behave as intended when they interact with enterprise technology stacks.
The ramifications of this situation extend beyond mere cybersecurity threats. Organizations grapple with several additional issues, such as identifying duplicate agents, tracking token consumption across individual business units, and measuring the return on investment from their AI initiatives. This conundrum requires a nuanced approach that goes beyond conventional methods of identity governance.
Sinha’s insights stem from his experience at Saviynt, where he has played vital roles in the development and management of cloud products since the company’s inception in 2014. In a recent discussion with ISMG in New York City, he shed light on the complexities surrounding AI governance, identity-data management, and cost challenges faced by CIOs in this new era.
Autonomous Agents and Identity Risks
In the pre-agent era, identity management was largely deterministic, allowing organizations to establish clear boundaries for both human and non-human identities. However, the introduction of autonomous agents has disrupted this norm. These agents possess the ability to act in ways the original developers may not have anticipated, creating security vulnerabilities.
For technology leaders, the primary challenge lies in accurately assessing the inventory of approved platforms, Software as a Service (SaaS) applications, employee devices, and custom codes that may host these agents. Sinha explains that the first step involves identifying known and sanctioned agent-building platforms. Organizations that operate on platforms like Microsoft or Amazon must look closely at tools such as Amazon AgentCore or Bedrock.
Following that, it is essential to examine devices—ranging from laptops to servers—where unauthorized code might be executed. Network traffic analysis becomes a critical third step. If an organization cannot directly identify an agent, scrutinizing traffic patterns can reveal communications with external AI services.
Furthermore, understanding the link between agents and non-human identities is paramount. Often, agents require a non-human identity—such as an API key or a secret—to access downstream applications. This understanding allows organizations to trace back any observed activity to its source, bolstering overall security.
The Complexity of Intent and Appropriateness
Sinha highlights a key distinction between intent and appropriateness when it comes to AI agents. Even if an agent operates within its assigned permissions, it can create substantial security or operational risks if its actions deviate from the original intent. For instance, if an agent is prompted to identify the best sales opportunity, it may interpret this command as an authorization to access data outside its designated area—resulting in potential breaches of confidentiality and compliance.
To prevent such deviations, organizations must implement runtime controls that ensure that agents’ actions align with their intended goals. This real-time evaluation should include checks for intent deviation, policy enforcement, and the identification of behavioral anomalies, such as unusual data deletion or excessive file downloads.
Unique Challenges in Governing AI Agents
The governance of AI agents diverges significantly from that of traditional human employees. Establishing a standardized structure for oversight becomes difficult when numerous stakeholders across different departments can create agents without uniform guidelines.
Sinha points out that human identity governance is deeply reliant on human intervention for approvals and reviews. The sheer number of agents and their high velocity of operations necessitate a shift towards automation for effective governance. Only critical cases should trigger human involvement, as manual processes cannot keep pace with the growing complexity of AI operations.
Data Quality, Security, and Value Attribution
Organizations often face three significant barriers when realizing the full potential of AI agents. The first is data quality; poor data can compromise the efficacy of AI applications.
Security issues arise when companies rush to implement AI initiatives, often failing to involve identity and access management teams from the beginning. This lack of foresight leaves organizations unprepared for the repercussions of their AI endeavors.
Finally, attributing the business value derived from AI investments remains a persistent challenge. Organizations must comprehensively understand their spending and the value that these advancements provide.
The Centralization of Token Consumption and Cost Attribution
CIOs are increasingly prioritizing governance issues related to token consumption, as costs become central topics in boardroom discussions. Organizations often find themselves puzzled over the simultaneous operation of agents performing similar tasks across different business units, such as HR and marketing, leading to unnecessary expenses.
Effective discovery processes should analyze agents to identify overlap in their functions, facilitating better decision-making regarding resource allocation.
Moreover, understanding which business unit contributed to token consumption can illuminate discrepancies in value delivery, allowing CIOs to manage budgets effectively and ensure that operational efficiencies are realized.
The landscape surrounding AI agents is complex, requiring organizations to adapt quickly while implementing robust governance frameworks. As the role of AI continues to expand, the responsibility falls to CIOs and other technology leaders to safeguard both data integrity and operational efficiency.

