by Kelly Knight

The dual-threat landscape of enterprise AI security is coming into focus. The same autonomous agents transforming workforce productivity are also expanding the attack surface — and most organizations have no governance framework to manage either risk.

As a matter of fact, the gap between adoption and governance has become the defining security risk of the current technological moment. Most enterprises do not yet have a trust and governance framework in place for the agents running inside their own systems, according to Bryan Palma (pictured), president and chief executive officer of KnowBe4 Inc. The solution starts with treating agents the way KnowBe4 once treated humans — as untrained assets that need to be understood before they can be secured, he added.

“[Agents] haven’t been trained, they don’t know. Think about them as elementary school students; they don’t know that there’s bad people out there that may misdirect them or want them to download malware,” Palma said. “We’re working right now very hard to make sure, one, we can inventory the agents. Second is to identify what are those agents doing — what do they have access to? What creates trust is transparency. If I know what you’re doing, then I’m more able to feel good about it.”