Agents already outnumber employees 82 to 1, and 97% carry excessive privileges. Three things to plan for:
Correct-but-wrong — an agent does exactly what it was told across ten thousand records. No breach, no alert, and you need surgical rollback, not a full restore.
The agent as insider — standing privileges make a hijacked agent the fastest lateral path you own.
Corrupted AI assets — datasets, embeddings and model weights are recoverable objects now. Most plans don’t list them.
Enforce control at the data source, not at the agent. You can’t govern an agent you don’t know exists.