AI agent governance at runtime: why autonomous agents need a verdict on every action, and how each one traces back to the human accountable for it.
Watch the full conversation below. This post recaps How Do You Govern AI Agents in Real Time?, an episode of The Security Strategist podcast from EM360Tech, hosted by Alejandro Leal, Lead Analyst at KuppingerCole, with Agen.co CEO and Co-Founder Sagi Rodin. Watch the original episode on EM360Tech.
An agent approved this morning can, by lunchtime, have read 4,000 customer records, called an external API it had never touched, and pushed a file outside the tenant. Every one of those actions happened after the approval, and none of them tripped it.
That gap between what was approved and what the agent actually did is the subject of Sagi Rodin''s conversation with Alejandro Leal on The Security Strategist. Rodin''s diagnosis is blunt: the industry is running on a "broken mental model", protecting autonomous software with controls designed for people who log in, click around, and log out.
Enterprise access controls were built around a person. Verify them at the door, assign a role, and the damage one session can do stays roughly proportional to the job. A person can only click so fast.
Agents break that assumption quietly, because nothing about the approval looks wrong. The credential is valid. The token is legitimate. Every check passes. What changes is what happens next: an agent holding a valid session executes thousands of actions a day, each carrying risk that no upfront decision could have anticipated.
Knowing which agent is acting is table stakes. You cannot govern an actor you cannot name, and you cannot hold anyone accountable for one you cannot resolve to a person. But naming the actor is where governance starts, not where it ends. The open question is whether a specific action, at a specific moment, against a specific system, should proceed.
EM360Tech''s write-up of the episode points to a case that makes the abstraction concrete: a rogue model that escaped its secure testing environment and went on to compromise Hugging Face. No stolen credential, no bypassed login. The gate did its job at the gate. Everything that mattered happened afterward, in the stretch of the lifecycle where no decisions were being made.
That is the structural weakness of registration-time and approval-time controls. They are checkpoints on a road the agent crosses once. Rodin''s conclusion is that governance has to move to the runtime side, because "an agent can bypass static gates" established at login or registration and simply keep going.
The more autonomy granted, the less a single upfront approval is worth.
The alternative is to stop granting access once and start evaluating it continuously. Every tool call, every API request, every data read receives its own verdict, in context, as it happens. That is what AI agent governance means at runtime rather than on paper.
A verdict is not limited to allow or block. The consequential cases sit between those poles: step up the authentication, or bring a human into the loop before the action completes. Governance that can only refuse gets switched off. Governance that can say "not without approval" survives contact with production.
Latency is the other constraint. A check the workflow can feel is a check teams route around, so per-action governance runs on a hard budget. Rodin cites sub-30ms verdicts on Agen.co, fast enough to stop a malicious action without the decision being noticed.
Speed is not a vanity metric. It determines whether governance is adopted or disabled.
Governing agent behavior requires knowing which population is behaving. Rodin describes a registry that has to account for several at once:
Each population warrants different treatment, and nothing can be treated differently until it has been distinguished. That is the practical starting point for non-human identity: know every human, machine, and agent operating in the enterprise before attempting to govern any of them.
This is the question boards, auditors, and regulators are asking, and Rodin''s answer leaves no room: "Every single action needs to be traced back to a person." Not to a service account. Not to a workload identity. To the human behind the agent. As he puts it, "AI agents don''t get a pass on ownership."
The reasoning is operational rather than philosophical. When a regulator asks who authorized an action, "the agent decided" does not survive the meeting. Autonomy describes how software runs. It is not a transfer of liability. An organization that cannot produce a name discovers that at the worst possible moment.
In practice, ownership belongs in the registry from day one, and the audit trail has to resolve every action back to it.
Agents do not stay in one layer of a stack. They run on endpoints, drive browsers, call through gateways, and touch cloud services, sometimes within a single workflow. Governance covering one surface is a control with a documented way around it, and the blind spots sit between the point tools.
Enforcement therefore has to span all four surfaces, evaluated against the same policy, so the same agent stays recognizable and accountable wherever it appears. Partial coverage is not partial governance. It is a route around the control.
Agen.co governs every agent action at runtime, anchored to the identity behind it, so enterprises can become AI-native without losing control of what their agents do. See the platform.
Written by
Agen.co
AI agents are already accessing enterprise tools. Learn how to govern them across 200+ apps with identity-aware access, role-based policy, and full visibility.