Most enterprises already have AI agents running, and most security teams cannot say how many. As Claude Code, Codex, and a wave of vendor-shipped agents arrive inside everyday software, the risk shifts from user-driven to agent-driven: an agent can reach systems and data with far more privilege than intended, act on its own reasoning, and even write code to work around a control that blocks it. In this session, Zentera Chief Evangelist Nathanael Iversen lays out a practical approach built on three architectural requirements, and a lifecycle for governing the agents you choose to keep: discover, authorize, contain, observe, maintain.
Key highlights: