AI Security

Governing the Agentic Enterprise: From Shadow AI to Autonomous Security

✎ Kieran Sky 📅 2025-11-20 🎓 CISSP, CISM, CRISC, CCSP

The emergence of autonomous AI agents capable of independent decision-making, tool usage, and multi-step reasoning represents a paradigm shift in enterprise technology that existing cybersecurity frameworks were never designed to address. This paper examines the security and governance challenges posed by agentic AI systems, from the proliferation of unsanctioned "shadow AI" agents to the deliberate deployment of autonomous systems in critical business processes.

The paper introduces a governance framework specifically designed for agentic enterprises — organisations where AI agents operate alongside human workers with varying degrees of autonomy. This framework establishes clear boundaries for agent authority, defines escalation pathways for high-risk decisions, and implements continuous monitoring of agent behaviour against established policy guardrails.

Key areas addressed include the taxonomy of enterprise AI agents (from simple chatbots to fully autonomous multi-agent systems), threat models specific to agentic architectures (prompt injection chains, agent impersonation, tool misuse, and cascading failures), and practical controls for managing agent lifecycles. The paper draws particular attention to the risks of agent-to-agent communication in orchestrated workflows, where security failures can propagate across multiple systems without human intervention.

The governance framework is mapped to current and emerging regulations including the EU AI Act's risk classification system, DORA's operational resilience requirements for financial services, and the NIST AI Risk Management Framework. Implementation guidance covers both technical controls (agent sandboxing, permission boundaries, behavioural monitoring) and organisational controls (accountability structures, incident response for autonomous systems, and board-level reporting on AI agent activities).

  1. 01The Rise of the Agentic Enterprise
  2. 02Shadow AI: Unsanctioned Agent Proliferation
  3. 03Taxonomy of Enterprise AI Agents
  4. 04Threat Models for Agentic Architectures
  5. 05Agent Authority & Decision Boundaries
  6. 06Multi-Agent Orchestration Security
  7. 07Regulatory Alignment Framework
  8. 08Technical Controls & Monitoring
  9. 09Organisational Governance Structures
K

Kieran Sky

CISO & Strategic Cyber Consultant · CISSP, CISM, CRISC, CCSP

27 years securing financial services · Big 4 pedigree (Deloitte, PwC, EY, KPMG) · Zero breaches managing £500B+ in assets

https://www.kie.ie · LinkedIn

Privacy Policy

Effective Date: 1 March 2026

Kieran Sky operates kieransky.co.uk. This policy explains how we collect, use, and protect personal data.

Data Collected: When you submit the contact form, we collect your name, email address, organisation, and message content. We do not collect data through cookies or tracking technologies beyond essential site functionality.

Purpose: Personal data is used solely to respond to your enquiry. We do not sell, share, or transfer your data to third parties.

Legal Basis: Processing is based on your consent (form submission) and our legitimate interest in responding to business enquiries, in accordance with GDPR.

Data Retention: Contact form submissions are retained for a maximum of 24 months, after which they are securely deleted.

Your Rights: Under GDPR, you have the right to access, rectify, erase, or restrict processing of your personal data. Contact info@kieransky.com to exercise these rights.

Contact: info@kieransky.com

Terms of Service

Effective Date: 1 March 2026

By accessing kieransky.co.uk, you agree to these terms. This website is provided for informational and professional engagement purposes only.

Intellectual Property: All content, frameworks, and trademarks on this site are the intellectual property of Kieran Sky. Reproduction without written permission is prohibited.

Professional Disclaimer: Content does not constitute legal, regulatory, or financial advice.

Governing Law: These terms are governed by the laws of England and Wales.

Contact: info@kieransky.com

Cookie Policy

Effective Date: 1 March 2026

kieransky.co.uk uses minimal cookies to ensure essential site functionality. We do not use advertising cookies, tracking pixels, or third-party analytics.

Essential Cookies: Required for basic website operation. These cannot be disabled.

Your Choices: You can control cookies through your browser settings.

Contact: info@kieransky.com

Accessibility Statement

Effective Date: 8 March 2026

We are committed to ensuring digital accessibility for all users. This site is designed to conform with WCAG 2.2 Level AA standards.

Measures Taken: Semantic HTML, keyboard navigation, ARIA landmarks, sufficient colour contrast, focus indicators, and accessible forms.

Feedback: If you encounter accessibility barriers, please contact info@kieransky.com.