AI agents are moving from personal productivity tools into operational workflows. That shift changes the security model.

If employees use ChatGPT, Claude, or Gemini to summarize notes, draft emails, explain code, or help write documentation, the primary security problem is AI usage governance.

If the company builds an AI agent that can read Jira tickets, inspect GitHub pull requests, query AWS, look up Confluence runbooks, post to Slack, or recommend incident response actions, the security problem becomes secure harness architecture.

Those are not the same thing.

This article uses a fictional bank, ZYX Bank, as the scenario. ZYX Bank uses: