Autonomous AI agents are becoming a part of most enterprise workflows today. But how are enterprises protecting their platforms from rogue agents? For instance, the recent attack on Hugging Face was discovered to be carried out by an OpenAI rogue AI model that escaped testing from a secure environment.
To answer how best enterprises can protect themselves from unique, unpredictable attacks by upcoming technologies such as rogue AI agents, Sagi Rodin, CEO and Co-Founder of Agen.co by Frontegg, joins host Alejandro Leal, Lead Analyst at Kuppinger Cole Analysts firm, on an episode of The Security Strategist podcast.
They talk about the constantly changing nature of AI agent governance, identity management, and security in enterprise environments.
They further explore how autonomous AI agents challenge traditional security models and what strategies enterprises need to adopt to stay secure.
What is Agen.co?
When asked about the dynamics of AI agents and how they individually carry risk, the focus seems to be moving to governance of specific actions in real-time. Instead of relying on the agent's initial authentication status, agents are going beyond identity to “per-action” governance.
Rodin puts it into context: “We [Frontegg] released Agen.co, a product that governs runtime agentic activity. We take an identity-first approach by connecting to identity providers, agent repositories, and user directories. In addition to managing users, we now maintain a registry of AI agents.”
The goal is to connect all those principles and manage unique identities in an enterprise. These include conventional automated machines, human users, user-controlled AI agents, autonomous AI agents that run on their own post-deployment, as well as malicious bots that need to be identified quickly and blocked. Rodin said that Frontegg is bringing all of those identities together under a single governance model.
How to Stop AI Agent-Driven Malicious Actions in Real-Time?
As an identity-native platform that connects to the IDP, the agent repository and user repositories, Agen.co by Frontegg has become a registry for agents.
“The industry has a broken mental model today,” Rodin tells Leal. When asked why, he said that while identity tools pose the question of identity, they may not ask the purpose of entry. That means an agent with valid credentials passes every identity check. It’s called “role-based access”, originally designed for humans.
An agent conducts thousands of actions per day, but each of those actions carries a risk. This is why individual governance of each action by those AI agents is critical. This is why Agen.co provides a very quick verdict in under thirty milliseconds to avoid obstructing workflows while stopping malicious actions in real-time.
“We must operate on the runtime side because an agent can bypass static gates established during login or registration,” Rodin says. “We need to be present the moment an agent accesses organisational data, attempts a prompt, or executes a potentially damaging command, like 'rm -rf' on an endpoint.”
Simply granting an agent a ticket at registration is insufficient to keep up with the dynamic and fast-paced scale of modern agent operations.
While enterprises cannot be obstacles in the path of automation, they can use a platform to operate extremely quickly and efficiently to stop threats from occurring.
As AI agents adapt with more autonomous capabilities and proliferate across departments in an enterprise, be it engineering, finance or marketing, these AI agents act without clear ownership.
Rodin says there shouldn’t be any agents running without a named human owner. He says that with governance, enterprises must take accountability.
“Every single action needs to be traced back to a person. AI agents don't get a pass on ownership.”
When Access Isn’t Inclusion
Why digital strategies must move beyond coverage metrics to measure skills, trust, identity, and AI readiness as core participation outcomes.
“When the regulator, the board, or the department owner asks who was responsible for this action, at the end of the day you need a name, so this is a core principle we impose for our AI native activity,” he added.
Takeaways
- Identity verifies who; runtime governance verifies every action.
- Identity proves who—runtime proves what's safe.
- Every AI agent action needs its own security decision.
- Static IAM can't govern autonomous AI behaviour.
- Every enterprise AI agent needs a named owner.
- Agent governance is becoming a runtime security challenge.
Chapters
00:00 Introduction to AI Agents and Security Challenges
06:23 The Shift from Identity to Behaviour in Security
10:09 The Importance of Continuous Validation
16:09 Accountability in the Age of Autonomous Agents
20:19 Key Takeaways for Security Leaders
For further information on Agen.co by Frontegg, visit agen.co and https://frontegg.com/.
Comments ( 0 )