TLDRocket
Sign in

AI governance moves from observability to provable control

SiliconANGLE Paul Nashawaty Covered by 9 sources

AI agents are moving into real enterprise work, and governance has to prove what they were allowed to do. That means context, delegation, and evidence — not just logs after the fact.

Based on reporting by SiliconANGLE, Paul Nashawaty — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

AI governance is leaving the comfort of dashboards behind. As agents move from experiments into production, enterprises are running into a harder problem: it is no longer enough to know what happened. They need to prove what an agent was authorized to do, why it was allowed to do it, and whether that authority still held when the task moved across systems.

That matters because agentic software does not behave like a single application with one set of permissions. An agent can get a task from a human, hand part of it to another agent, call an API, and keep passing work along. Each handoff changes the scope of authority. Sudeep Goswami of Traefik Labs put it bluntly: if one agent hands a task to another, that authority should shrink instead of leaking out.

The old model of identity and credentials is too blunt for that. A credential can say who the agent is, but not whether it should make a specific move in a specific context. That pushes governance toward rules that look at the task, the environment, the delegation chain and the surrounding conditions. Andreas Prins of SUSE compared the shift to the move from manual software releases to coded CI/CD pipelines: approvals, security checks and policies had to be built into the process, not bolted on later.

The scale issue is already here. Prins said he recently heard about an engineering organization that had created about 8,000 agents. If nobody knows how many agents exist, nobody really knows what they’re doing. That is the kind of problem that turns governance into a supply-chain question, with explicit identity, delegated authority, policy enforcement and evidence attached to each system.

Logging still matters, but it is no longer enough on its own. Goswami argued that audit trails can be tampered with, and that enterprises need cryptographic records plus third-party verification to check them. On top of that, sovereignty changes the architecture again: research cited in the conversation found that 47% of respondents operate across connected and disconnected environments, while 11% run generative AI in on-premises and air-gapped setups. For regulated sectors, that means the controls, models and verification layers may all need to live inside customer-controlled infrastructure.

My take — AI-written commentary, not fact-checked reporting

The industry keeps pretending observability is the finish line, but for agents it’s just the warm-up act. If an enterprise can’t show who gave an agent power, what it used, and who verified the record, then it’s not governance — it’s decorative logging with a better logo. The sober answer is boring and correct: more control, more evidence, less SaaS magic.

Read more about this at: SiliconANGLE

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.