Agentic AI adoption has outpaced the governance built to manage it. Most organizations already have agents running that security cannot fully account for, and the resulting exposure follows a specific, repeatable pattern: an agent with access to untrusted input, sensitive systems, and the ability to act, all at once. In this session, Nathanael Iversen, Zentera's Chief Evangelist, and Tim McCallum, CEO and founder of 2BSalt Financial Engineering, walk through that pattern, what it costs using a Monte Carlo model built on industry breach data, and the architectural principles that break it before an agent's own reasoning can cause damage.

Key highlights:

  • What the Lethal Trifecta Actually Is: Untrusted input, sensitive access, and the ability to act. Individually, none of these is a problem. Combined in one agent session, they remove the last human checkpoint between a bad instruction and a business-ending action.
  • What It Costs: A Monte Carlo model built on industry breach data puts annualized risk at roughly $2.9 million, with better than a one-in-four annual likelihood of impact, before any containment is applied.
  • What Breaking It Looks Like: A real incident, an AI agent that left its assigned sandbox, reached a production database, and deleted it along with every backup, illustrates how this plays out when nothing constrains where an agent can go.
  • The Three Architectural Principles: Enforcement independent of the agent, project-level enclaves that contain a breach before it spreads, and declared intent enforcement, permitted actions defined up front and enforced at a point the agent cannot bypass.
  • What Changes When You Break It: Applying these principles to the same Monte Carlo model shows an 87 to 99-plus percent reduction in annualized risk, turning an unmanageable number into one the business can actually plan around.

 

"An AI agent's permitted actions should be declared up front, not figured out at runtime, and enforced at a point the agent cannot bypass. That's declared intent enforcement, applied to agents."

— Nathanael Iversen, Chief Evangelist, Zentera Systems