Agentic AI is moving fast, from experimentation to enterprise deployment and with it comes a new governance challenge for security, identity and technology leaders. As AI agents gain increasing autonomy to access applications, data and business processes, organisations must rethink how trust, access, accountability and oversight are established.
When an AI agent is compromised, over-privileged, or acting beyond its intended scope, the consequences rarely stay contained to IT. They escalate into board-level questions: Who authorised this agent? What could it access? Who is accountable for its actions? And can we prove the right controls were in place?
Brought to you by Trevonix and Ping Identity, this executive session examines why identity is emerging as the critical control plane for governing AI not just at login, but continuously, at the moment an agent acts.
That's the shift at the heart of the discussion: moving governance from static, session-based permissions to runtime control. Rather than trusting an agent because it holds a valid credential, runtime identity evaluates context, risk and policy every time an agent attempts an action: authenticating and authorising AI agents as their own class of identity, enforcing least-privilege access in the moment, and maintaining a continuous audit trail of what agents actually action. We will explore what this looks like in practice by giving every agent clear guardrails, a defined chain of delegated authority, and human accountability that holds up under board and regulatory scrutiny.
Through market insights, interactive audience polling, and ARIA: The Hijacked Assistant, a scenario illustrating how an AI agent can cross a trust boundary, the session will explore the governance gaps that leaders need to close and the principles that shift organisations from reactive risk management to board-ready AI governance.
The session closes with practical next steps for building a more secure, accountable approach to Agentic AI.