Can You Trust an AI Agent to Act?

As enterprises move from experimenting with AI to deploying agents that can act, communicate, write code, and make decisions, the security conversation is changing too.

For decades, enterprise security has focused largely on authenticating people, applications, and infrastructure. Agentic AI introduces something different: autonomous systems that can take action on behalf of the organization and interact with other agents, systems, and potentially other companies.

That makes security about more than preventing access. Enterprises need to know what an agent is allowed to do, how far its autonomy extends, whether its identity can be trusted, and how to trace its actions.

During a recent ONUG discussion on agentic AI, industry leaders explored what those controls could look like in practice.

Give Agents Room to Act But Not Free Rein

Autonomy is what makes an AI agent useful. But unrestricted autonomy creates an entirely different category of risk.

Forrest Bennett, cybersecurity architect and advisor at FedEx, pointed to guardrails as one of the first requirements for enterprise adoption.

That balance will be critical. An agent that can only follow a predetermined sequence is little more than traditional automation. But an agent with unlimited authority introduces risks that existing security models were never designed to manage.

The goal, then, is not to eliminate autonomy. It is to establish an operating envelope: enough freedom for the agent to reason and act, with clear boundaries around where that authority begins and ends.

Control Requires Traceability

Putting limits around an agent is only part of the equation. Enterprises also need to understand what happens once agents begin acting — especially when multiple agents interact.

Eric Powers of Citi brought the conversation back to a foundational requirement: traceability.

That becomes increasingly important as agentic environments grow more complex.

If one agent triggers another agent, which triggers a change somewhere else in the environment, security teams need a reliable way to reconstruct that chain of events. Without it, organizations may know what happened without being able to determine why it happened, which agent initiated it, or where the breakdown occurred.

In other words, observability is not simply an operational concern in an agentic environment. It becomes part of governance.

Trust Starts With Identity

But before an enterprise can decide what an agent should be allowed to do, there is an even more fundamental question:

Who, or what, is this agent?

Bennett argued that agent identity will be foundational to controlling how autonomous systems communicate and share information.

That distinction is important.

Agents do not fit neatly into the identity models enterprises already use. They are not human users, but they may have far more discretion than a conventional service account. As their capabilities expand, simply granting credentials to an agent will not be enough.

Organizations will need to understand their identity, purpose, permissions, and relationship to the enterprise and establish mechanisms for other systems to verify them.

Bennett later described what that could mean when agents begin communicating across organizational boundaries.

This is where identity and trust begin to converge.

In a future where autonomous agents routinely interact across systems and organizations, enterprises will need more than authentication. They will need confidence that the agent is legitimate, that it represents the organization it claims to represent, and that its request falls within its authorized role.

Keep Agents in Their Lane

As the number of agents grows, another challenge emerges: agents may have different goals, policies, or instructions that conflict with one another.

Powers suggested that role definition and arbitration could become essential pieces of the architecture.

Clip #5 – Role Definition 

“Stay in your lane” may become one of the simplest ways to describe one of agentic AI’s most complicated governance challenges.

As enterprises deploy more autonomous systems, control cannot depend solely on securing each agent individually. Organizations will also need mechanisms for coordinating them, resolving conflicts, defining authority, and preventing one agent’s actions from interfering with another’s responsibilities.

Trust Has to Be Designed In

Agentic AI promises to move enterprise automation far beyond predefined workflows. That is exactly what makes it powerful and what makes control so important.

The answer is unlikely to be removing autonomy from agents. It will be designing environments in which autonomy can exist safely.

That means building security into the agent from the beginning. Establishing verifiable identities. Defining roles and permissions. Creating guardrails around actions. Maintaining visibility into agent-to-agent activity. And ensuring organizations can reconstruct what happened when something goes wrong.

The enterprises that succeed with agentic AI will not simply be the ones that deploy the most capable agents.

They will be the ones that can trust those agents enough to let them act.

Watch the full conversation here.

Continue the Conversation in New York

These questions around security, control, identity, and trust are only becoming more important as enterprises move further into agentic AI.

At the AI Networking Summit NYC, we’ll continue conversations like these with enterprise leaders, practitioners, and technology experts working through what it takes to build AI-ready infrastructure that organizations can actually trust.

Join us October 28–29 in New York City to be part of the conversation.

Learn more and register.

Author's Bio

Guest Author

ONUG Staff