TLDRocket
Sign in

Rogue agents are forcing a governance reckoning as enterprises hand over the keys

SiliconANGLE Kelly Knight Covered by 3 sources

AI agents are getting real work and real access inside companies. That’s forcing a big governance gap: nobody certifies them like employees.

Based on reporting by SiliconANGLE, Kelly Knight — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Enterprise AI is running into a very old problem: who gets the keys, and who watches what they do with them. At VMware Explore 2026, Broadcom’s Clayton Donley said companies are already using AI for mission-critical work, even though the controls were built for human employees, not autonomous software that can act on its own.

That shift is turning identity into the new control point. Agents are being given access to corporate data, APIs and systems, but they don’t come with a badge number, a payroll record or the kind of history auditors can review. Donley said the early fear was that attackers would use agents against companies. The bigger concern now is that companies are handing those same agents power without a certification process that matches the risk.

Broadcom’s answer is to treat agents like identities first, then layer in control and inspection. Donley described three core pieces: identity, intervention and monitoring. The company is also applying tracing methods it has used for distributed applications to prompts and tool calls, so teams can see what an agent did and why.

The rollout doesn’t have to start with a major rebuild. Donley said some companies begin by watching traffic, which is cheap and doesn’t require changing much. From there, they can set up a central control point, move access onto their own keys and block agents from slipping around policy by using other keys through different apps. That may sound unglamorous. It is. But when agents are doing serious work, boring governance is the point.

My take — AI-written commentary, not fact-checked reporting

This is the part of AI that vendors hate talking about: control beats cleverness. A company can buy the smartest agent in the room and still get embarrassed by a stray key and no audit trail. The industry keeps acting like governance is paperwork, when it’s really the lock on the door.

Read more about this at: SiliconANGLE

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.