Centric Consulting’s CEO Larry English was interviewed by The Financial Times on the security risks of shadow AI agents and how organizations can govern them.
The Financial Times article, “How to Stop Shadow Agents Accessing Sensitive Content,” examines a fast-growing security gap: AI agents that access company data and systems without approval or oversight.
As agent adoption accelerates across the enterprise, the article explores why these “shadow agents” create risks that traditional, human-centric security models were never built to catch, and what leaders can do to close the gap.
Left unchecked, forgotten or unmonitored agent access points can expose organizations well beyond the initial use case. “Companies are opening themselves up to regulatory violations, IP loss and reputational damage,” English said.
English’s guidance centers on applying the same governance discipline to agents as to human employees.
“Onboard them properly,” English said. “Scope them to a role and apply the same identity and access management disciplines you’d use for any employee or service account.” He extended the analogy further: “If a sales representative can’t see opportunities outside their territory, the agent supporting that representative shouldn’t be able to either.”
English also pointed to the importance of an agent system of record for tracking every agent’s provenance, scope, and activity across its lifecycle. “Catching a problem at the moment an agent’s behavior changes is what keeps it from becoming a workflow-wide failure,” he said.
For English, strong governance is not at odds with the productivity gains agents promise. “None of this is about slowing people down,” he said. “It’s about making sure you’re getting productivity gains but not exposing the organization to new and very real risks.”
Read the full article in The Financial Times.