Imran Aftab, CEO and Co-founder, 10Pearls—driving AI innovation and creating meaningful opportunities that make an impact.gettyLast month, a Claude-powered AI agent deleted one startup's entire database. At the tail end of December, Amazon Web Services (AWS) experienced a similar disaster when an AI agent deleted and recreated part of its environment, causing a 13-hour disruption. Upon hearing these stories, your initial reaction may be one of alarm and an "avoid AI agents at all costs" stance. However, don’t be so quick to pin this down as a model failure. Rather, these experiences underline the real root cause: weak governance. As vibe coding and agentic AI dominate enterprise AI discussions, with firms trying to balance the need for speed with safe, secure modernization, governance must be at the center of every conversation. Moving Fast Only Works With The Governance GroundworkDevelopers are building faster than ever with AI coding tools, while agents are moving closer to full autonomy. Yet governance, which underpins functional, reliable AI models, is too often treated as an afterthought. When safety and security give way to speed, firms are priming their systems for disaster. Weak governance creates a void in the framework that otherwise should be able to shape how AI agents act and how AI-generated code is built. Agentic AI can decide and act, interacting with live systems in ways traditional software never has. Vibe coding is a new approach to software development in which conversational prompts generate entire code sets via natural language processing, often without engineering discipline. But now, research is also showing that thousands of vibe coding apps are leaking sensitive corporate and personal data. Together, they create a compounding consequence: agents operating with broad, unregulated or unsupervised permissions, built by code that was never properly reviewed, interacting with production systems that have no intervention checkpoints.With both innovations, weak governance and undisciplined architecture mean AI can accelerate and amplify risk at scale. And, with so much at stake comes a much greater need for accountability. That accountability doesn’t rest with the models—it rests with the business and technology leaders responsible for AI outcomes. Why Traditional Governance Falls ShortMost enterprises’ governance frameworks were designed for static software and deterministic systems, where the outcomes are scripted. In traditional setups, code review, access controls, and audit logs were created with the expectation that there would always be a human to approve every single step. But vibe-coded AI tools sidestep the former, and agentic AI the latter. This results in security and compliance gaps that go unnoticed until an incident reveals them. The truth of the matter is that many governance models were designed for traditional software systems and were not built to oversee systems capable of generating code, making decisions and taking action autonomously. In highly regulated industries, such as healthcare and financial services, weak governance is an even greater threat. A Four-Step Practical Blueprint Effective AI governance is more than a single policy or review process. It requires organizational accountability and the technical guardrails to dictate how AI systems are built, deployed and monitored. The riskier the AI use case, the more oversight it needs, with controls sized to the real business, operational, regulatory and security stakes involved. Enterprises can begin by focusing on four foundational areas:Govern How AI-Assisted Code Enters ProductionVibe coding is not inherently unsafe, but it requires a clear path from prototype to production, including a security review and architectural sign-off beyond functional testing. Establish review requirements for AI-generated code, including frequency, measured parameters and benchmarks.Scope Agent PermissionsDon’t give AI agents access beyond what’s absolutely necessary to complete a defined task or workflow. High-stakes, high-risk actions that aren’t reversible, such as customer data modifications, need strict human-led checkpoints. Establish Observability RequirementsGoverning agents means tracing what they do, why they take action, the code they operate with, the data they receive and can access, and when human escalation occurs. Structured logging, decision visibility, strong data management, orchestration, interoperability and anomaly alerting must be in place before agents operate in production. It’s also crucial to define precisely where human-in-the-loop intervention takes place, and to establish transparency and accountability accordingly.Build The Data Foundation FirstAI governance depends on strong data governance. Agents operating on poor data will make confident, autonomous decisions based on unreliable or even hazardous inputs. Data quality, visibility, lineage and access controls are critical prerequisites for AI to work securely and safely across your enterprise.Agentic AI and vibe coding are already established pillars of AI’s future. These innovations will continue to define many of the upcoming trends and breakthroughs we see, or at least be an influential force among them. However, the enterprises that move fastest and with the most agility in the long run are those setting out to close the governance gap now, rather than after an incident exposes it.Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?
Why Governance Must Lead The AI Conversation
AI governance depends on strong data governance. Agents operating on poor data will make confident, autonomous decisions based on unreliable or even hazardous inputs.
Claude agent database deletion and 13-hour AWS outages reveal weak governance as the core risk, not model failures. Tech leaders must prioritize governance—scoped permissions, code review, observability—before scaling agentic AI deployment.








