June 22, 2026 · 9 min read
Your Agent Stayed in Its Lane and Still Crashed
The AI governance research that landed this week says something that should stop every executive cold. Security firm Zenity found that agents can act outside their intended purpose while staying entirely inside their permission set. Read that slowly. The agent never broke a rule. It had access it was granted, used it in a way nobody intended, and there was no rule on the books that said it could not.
This is arriving at the worst possible moment to be unprepared. The same research roundup notes that production AI agents are being rolled back at high rates, with leaked personal data and hallucination as the leading causes, while agentic adoption has raced to roughly seventy percent and governance has crawled to maybe forty. And the agents arriving now do not just read from your systems. They write to them.
An agent that can read is a research assistant. An agent that can write is an employee with a keyboard and no judgment. Most companies handed theirs the keyboard months ago and never changed how they govern it.
Permission Is Not Control
For thirty years our entire security model has rested on one idea: decide who is allowed to touch what, and you have controlled the risk. Permissions. Access lists. Least privilege. It worked because the things holding the permissions were humans, and a human with access to the refund system still has judgment, context, and a healthy fear of getting fired.
An agent has none of those brakes. Give it the same access you would give a competent employee and it will use every inch of that access in ways the employee never would, because it has no instinct for when a technically permitted action is an obviously terrible idea. It refunds the whole queue. It emails the whole list. It rewrites the record because something in its prompt made that look like the goal. Every step inside its permissions. The sum a catastrophe.
So the question that used to govern your systems, what is this allowed to access, is no longer enough. The new question is what is this allowed to do, how much can it decide on its own before a human signs off, and what does it cost you if it does the wrong permitted thing a thousand times before anyone notices. That shift, from governing access to governing autonomous action, is the entire subject of The Sentinel Leader: The Executive's Playbook for Governing AI.
The Calendar Is Not on Your Side
If the operational risk does not move you, the regulatory one should, because the deadlines are no longer theoretical. Colorado's AI Act takes effect June 30. The EU AI Act's high-risk obligations become enforceable August 2. That is weeks, not years, and the regulators have stopped writing principles and started writing penalties.
And note what the serious governance frameworks published this month all converge on, no matter who wrote them. Every autonomous agent gets a unique identity. Every action it takes gets logged in an audit trail you can actually read. And every agent has a named human who owns what it does. Not a committee. A person. If you cannot produce those three things for every agent running in your company right now, you do not have a governance gap. You have a governance absence, and a date on the calendar when it becomes someone else's job to point that out.
Govern the Behavior, Not Just the Badge
The fix is not to rip the agents out. They work, they are valuable, and that train has left. The fix is to add the layer your permission model never needed when the actors were human: behavioral limits. A decision budget that says this agent can act on its own up to here, and past here a human approves. Runtime boundaries that watch what the agent is actually doing, not just what it is allowed to touch. An audit trail that lets you reconstruct, after the fact, exactly what it did and why.
This is not bureaucracy slowing down innovation. It is the opposite. A company that can prove what its agents do is a company that can let them do more, faster, because it can see the edge of the cliff. The ones flying blind are the ones who will have to yank everything back the first time an agent does something permitted and ruinous, which on current trends is not a question of whether.
Do This Monday
Pick the single most powerful AI agent running in your company, the one with the most write access to real systems. Now answer three questions about it, in writing, and do not move on until you can. Does it have a unique identity you could trace an action back to? Is there an audit trail that would let you reconstruct what it did last Tuesday? And is there one named human who owns its behavior and would answer for it? If you cannot answer all three for your most dangerous agent, you have just learned exactly where to start, and the EU and Colorado deadlines just told you how long you have.
Govern what your agents do, not just what they can reach. The executive's playbook is The Sentinel Leader.
Get the Book on Amazon →