Discussion about this post

User's avatar
Pawel Jozefiak's avatar

'60% of organizations lack formal agentic AI risk assessments' while agents are already running in production - the governance is lagging the deployment by months. The 90-day path (inventory → detection → governance) is realistic and correctly ordered. What I'd add before day 1: map which human credential scope each agent inherits in your environment. That single-person-equivalent access scope becoming an attacker's access scope is the risk most security red teams miss when evaluating AI deployments. The credential mapping step alone changes the risk conversation: https://thoughts.jock.pl/p/building-ai-agent-night-shifts-ep1

2 more comments...

No posts

Ready for more?