Skip to main content

AI adoption is accelerating. Is your governance keeping up?

If you've followed the AI conversation over the past year, you've probably seen headlines about autonomous agents behaving unexpectedly, prompt injection attacks, and AI scenarios that sound more like science fiction than everyday business technology.

29 September 2026

Those discussions matter. But they are often not the challenges organizations are dealing with today. What we're seeing across customer and partner environments is much more practical. Employees are already using Microsoft Copilot. Teams are experimenting with agents. Developers are connecting AI into business applications and workflows. AI is no longer something that sits in a controlled pilot environment. It is steadily becoming part of everyday business operations.

And that's where the conversation starts to change.

The challenge is no longer whether AI can create business value. The challenge is making sure visibility, ownership, and governance keep pace with adoption.

During our recent Beyond Copilot webinar, our experts Martijn Zantinge and Angelo Coetzee encouraged attendees to look beyond the most dramatic AI headlines and focus on the risks that are much closer to home.

As Martijn explained: "The real risk is not with a single rogue agent that you read about on your news feed. It's really those vast amounts of agents that exist in your environment nowadays and that you probably don't have proper governance on."

That observation reflects a shift we're increasingly seeing. Organizations are not struggling with a single AI system. They are gradually accumulating many of them, often across different teams, use cases, and business processes.

 

AI adoption rarely happens all at once

Most organizations do not wake up one morning with hundreds of AI agents. Instead, adoption happens gradually.

Many start by exploring Microsoft Copilot and identifying practical use cases. From there, a department may create an agent in Copilot Studio. A developer may build an AI-powered workflow. Another team might start using AI capabilities embedded within a platform they already rely on every day.

Each decision makes sense in isolation. Over time, however, those individual decisions become harder to track. Visibility decreases, ownership becomes less clear, and governance struggles to keep up.

One of the clearest observations from our webinar was that not all AI systems operate in the same way. Some act as assistants that help users find information and work more efficiently. Others can perform tasks on behalf of users, access organizational data, interact with business systems, or execute actions across multiple applications.

As agents become more capable, governance becomes more important.

For IT decision-makers, that means understanding not only where AI is being used, but also how it is being used. For MSPs, it creates an opportunity to help customers understand their current environment before recommending additional controls and tooling. And it often starts with a surprisingly simple question: Do you know which agents are operating in your environment today?

If the answer is uncertain, that's usually where governance should begin.

 

Treat agents like identities, not features

One question comes up repeatedly when organizations start looking more closely at AI governance: Who owns the agent?

At first glance, that sounds like a technical question. In reality, it is a business question.

We've seen organizations spend considerable time discussing what an agent can do, while giving far less attention to who remains accountable for it. Yet ownership becomes increasingly important as agents gain access to information, support business processes, or perform actions on behalf of users. That is why we encourage organizations to think of agents as identities rather than features.

Every agent should have a clear purpose, a defined owner, and appropriate oversight. Organizations should be able to answer practical questions such as:

  • Why does this agent exist?

  • What information can it access?

  • What actions can it perform?

  • Who approved it?

  • Who remains accountable for it?

  • What happens if the person who created it leaves the organization?

These are not purely technical questions; they are governance questions.

Lifecycle management becomes particularly important when an agent evolves from a useful experiment into something that supports day-to-day business operations. Without clear ownership, that agent can continue operating long after its original purpose has changed.

In our view, effective governance starts with accountability. Every agent should have an owner, a sponsor, and a lifecycle that covers discovery, assessment, approval, monitoring, and retirement.

 

AI security starts with the foundations you already have

One of the most common assumptions around AI security is that it requires an entirely new set of controls. What we're seeing in practice is often the opposite.

Many AI systems rely on identities, permissions, and data controls that already exist within the environment. If sensitive information is broadly accessible today, introducing AI can simply make that exposure more visible.

As Martijn summarized during the discussion: "If you have your data security on par, you basically have 80% of your AI security also in place."

The exact percentage is less important than the principle behind it.

If an organization understands its data, classifies it appropriately, and restricts access to the people and systems that need it, those boundaries can also support secure AI use. Angelo expanded on this point by explaining that effective enforcement depends on understanding the data landscape, applying appropriate sensitivity labels, and managing permissions correctly. Broadly labelled or unlabelled data may remain available to agents through the access rules already in place. AI does not always create a new data security problem. Sometimes it exposes one that was already there.

For IT leaders, this provides a useful reality check. Before acquiring another AI security product, review the organization’s data classification, identity management, and access permissions to determine whether existing controls provide the boundaries the business intends.

For MSPs, this creates a practical starting point for customer conversations. They can assess the foundations the customer already has, identify where controls are missing or poorly configured, and prioritize the gaps that present the greatest business risk.

Strong AI governance starts with getting the fundamentals right.

 

Access and action are two different things

Knowing what an agent does is only part of the picture.

An agent may be authorized to retrieve information. That does not automatically mean it should be able to modify records, trigger workflows, send information externally, or execute operational actions. As organizations introduce more AI-enabled processes, this distinction becomes increasingly important.

Organizations therefore need to distinguish between three areas:

    • What an agent can access
    • What an agent can do
    • What information it can disclose

The required enforcement points are spread across identity controls, data protection, application permissions, connector policies, runtime security, and network controls. The difficulty is bringing them together into a governance model that the business can understand and manage.

Microsoft Agent 365 can help establish an aggregated view of agents, owners, privileges, activity, and data protection. However, it does not replace the controls within services such as Microsoft Purview, SharePoint, Entra, and Defender.

Platform-specific enforcement remains within those services.  

This distinction matters because no single dashboard removes the need for correctly configured controls in the systems where agents access data and perform actions.

Technology can enforce governance. The organization still needs to define it.

 

Start by observing before you start blocking

When organizations identify potential AI risks, the natural reaction is often to block activity as quickly as possible.

That instinct is understandable. But blocking activity before understanding normal use can disrupt legitimate work and create unnecessary resistance among employees.

A more practical approach begins with visibility.

Start in audit mode where appropriate. Review what the control detects, which teams and processes are affected, and whether the activity represents a genuine risk. Once the behaviour and any required exceptions are understood, the organization can move towards targeted enforcement.

Our experts recommend this staged approach during the webinar. Organizations should begin by auditing activity and understanding the alerts generated, then move into blocking once the behaviour has been validated and the correct scope has been defined. The same principle applies to runtime protection on managed endpoints.

Prepare the devices, introduce protection in audit mode, review the resulting activity, and move into block mode once the expected behaviour has been confirmed. The objective is not to prevent employees from benefiting from AI. It is to introduce effective controls without unnecessarily interrupting legitimate work.

There is another important consideration here. The availability of a security feature does not mean the risk has been addressed. As Angelo put it: “The tools exist. It’s whether you have them on and configured correctly.”

Someone still needs to assess the environment, configure the controls, validate that they work, monitor what they detect, and respond when an alert appears. Security is not a one-time configuration exercise. It requires ongoing guidance, monitoring, and improvement.

This aligns with our purpose of helping clients understand complexity, take the right actions, and maintain continuous protection.

 

What we've learned from using AI in our own SOC

At Nedscaper, we're not only helping customers navigate AI adoption. We're also exploring how AI can improve our own operations.

One example shared during the webinar involved the use of AI within our Security Operations Centre. The goal is to help analysts investigate security events more efficiently by querying information using natural language, connecting evidence across systems, and supporting investigations with cited findings.

Importantly, the environment remains read-only.

The AI supports the investigation process. The analyst remains responsible for validating the evidence and making decisions. That philosophy can be summarized in a single sentence: The agent investigates. The analyst validates and decides.

Our early internal testing has shown promising results. During the webinar, we shared measurements that compared an average manual investigation time of 22 minutes against a median automated-agent runtime of 2 minutes and 23 seconds. At the same time, our experience has reinforced an important lesson. Speed should never be confused with certainty. An AI system may produce an answer quickly and confidently. That does not automatically make it correct. That's why evidence, transparency, and human review remain central to our approach.

Technology can accelerate analysis, but accountability still belongs to people.

As Martijn highlighted during the discussion: "At this stage, we don't let agents actually isolate the machine. That's always a human decision."

That principle reflects our broader view on AI and cybersecurity. Technology should help people work faster, see more, and make better decisions. Human expertise remains responsible for the outcome.

 

Autonomy also needs boundaries

Security is not the only consideration when agents gain more autonomy. Cost and resource consumption matter too.

As organizations explore more advanced AI capabilities, they also need to think about operational guardrails. Without clearly defined limits, agents can repeatedly call tools, execute workflows, or consume resources in ways that were never intended. Angelo summarized this challenge clearly: "Autonomy needs a budget."

That observation applies beyond cost management. Organizations should establish clear boundaries around what agents can do, how frequently they can perform actions, where approval is required, and when humans need to remain involved. The model itself is only one part of the solution. The surrounding governance determines how safely and responsibly it operates.

 

AI governance is becoming a shared responsibility

The organizations that benefit most from AI will not necessarily be the ones that adopt it the fastest. More often, they will be the organizations that understand what exists in their environment, establish clear ownership, and build governance that can evolve alongside adoption.

For IT decision-makers, that means treating agents as business assets rather than experimental tools. Every agent should have a purpose, appropriate access, clear ownership, and defined governance boundaries.

For MSPs, it means helping customers embrace AI without forcing them to choose between innovation and control. What we're seeing today is not a future challenge. It is happening now.

Organizations are already introducing AI into business processes, customer interactions, workflows, and decision-making. The sooner visibility, ownership, and governance become part of that conversation, the easier secure adoption becomes.

Our recommendation is simple: start with discovery.

Understand which agents exist. Identify who owns them. Review what they can access. Establish appropriate boundaries. Then build from there because secure AI does not start with blocking every new tool; it starts with understanding what you have and ensuring the right governance is in place as adoption continues to grow.

Webinar on demand

See what Agentic AI means for security in practice

Explore the real-world risks, governance challenges, and lessons learned from organizations navigating the next evolution of AI.

 

Relevant posts