Agentic AI adoption has outpaced the governance built to manage it. Most organizations already have agents running that security cannot fully account for, and the resulting exposure follows a specific, repeatable pattern: an agent with access to untrusted input, sensitive systems, and the ability to act, all at once. In this session, Nathanael Iversen, Zentera's Chief Evangelist, and Tim McCallum, CEO and founder of 2BSalt Financial Engineering, walk through that pattern, what it costs using a Monte Carlo model built on industry breach data, and the architectural principles that break it before an agent's own reasoning can cause damage.
Key highlights:
"An AI agent's permitted actions should be declared up front, not figured out at runtime, and enforced at a point the agent cannot bypass. That's declared intent enforcement, applied to agents."
— Nathanael Iversen, Chief Evangelist, Zentera Systems