Urgent.News

What's breaking now, across thousands of outlets.

AI

AI governance moves from observability to provable control

As artificial intelligence agents move from experimental tools into production systems, enterprise governance is being forced to answer a harder question. It is no longer enough to know what an agent did. Organizations increasingly need to prove what the agent was authorized to do, why it was allowed to take a specific action and whether […] The post AI governance moves from observability to…

AI governance moves from observability to provable control

As artificial intelligence agents begin to play a more significant role in enterprise systems, governing their behavior is becoming increasingly complex. Traditional methods of observing and logging agent activity are no longer sufficient. Enterprises must now prove the authority that each agent has been granted, understand why a particular action was permitted, and verify that the agent's authorization remains valid throughout the execution of tasks that may span multiple systems and agents.

Sudeep Goswami, CEO of Traefik Labs, and Andreas Prins, SUSE Group's lead on sovereignty strategy, discussed these challenges on theCUBE Research’s AppDevANGLE podcast. Goswami noted that when an agent delegates a task to another agent, that delegation should not expand the authority of the original agent, but rather shrink it. This means that simply having credentials is not enough to determine if an agent can perform a specific action, as the surrounding context and conditions must also be considered.

Prins likened the transition from traditional enterprise access models, designed primarily for human users and applications, to the emerging landscape of agentic systems. These new systems involve a complex web of machine-to-machine interactions, where authority can shift rapidly across different components. To address these challenges, Prins emphasized the need to rethink and codify governance policies directly into the governance process, much like how continuous integration and continuous delivery (CI/CD) systems have evolved to automate software releases.

With the proliferation of agents, managing them all becomes a significant hurdle. Prins cited an example where a single executive discovered that an engineering team had created around 8,000 agents, highlighting the potential for governance to become unmanageable without robust controls. Enterprises may eventually require a system akin to software supply chain controls for these agents, including explicit identity management, delegated authority, policy enforcement, and evidence of both allowed and denied actions.

Ensuring the integrity of these governance mechanisms is crucial, as the system that generates evidence of compliance may itself control that evidence. Goswami compared this situation to vehicle odometers, which can be tampered with by the owner. Similarly, cryptographic signatures can be used to provide an independent verification mechanism, ensuring that audit logs and other proofs of compliance cannot be altered without detection.

In essence, the governance of AI agents requires a multi-layered approach that includes policy definition, real-time enforcement, and cryptographic evidence, all of which must be interconnected and verified to maintain the security and sovereignty of enterprise systems.

Written by urgent.news from SiliconANGLE's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at siliconangle.com →

More in AI

More from Saturday 19 September →