As organisations across the UK deploy AI agents and autonomous workflows, they'reintroducing a new class of digital actor into the enterprise - one that doesn't authenticate like aperson and doesn't follow the rules we’ve built for human users. The scale of this shift hasalready triggered structural warnings at the highest levels, with the Bank of England launchingtargeted investigations into the systemic risks of autonomous AI trading agents operatingwithout human intervention. These agents execute tasks across systems, access data, andmake decisions with the same privileges as your employees. Yet most organisations lack aframework to govern them with equivalent rigour.