Rajat Bhargava is an entrepreneur, investor, author and currently CEO and cofounder of JumpCloud.
Most enterprises have already crossed a threshold they haven’t fully acknowledged: Autonomous AI agents are now active participants in their most sensitive business operations. They’re provisioning access, processing transactions and modifying configurations. In a growing number of organizations, non-human identities already outnumber human employees.
What hasn’t kept pace is something deceptively simple: ownership.
I don’t mean ownership in the abstract governance-framework sense but named, individual human accountability for what each agent does, what it can reach and what happens when it behaves in ways nobody anticipated. In most organizations I work with, that accountability hasn’t been assigned. It’s been assumed—spread thin across teams, absorbed into IT by inertia or simply left open.
Agents Inherit Access—And Rarely Lose It
One of the more underappreciated dynamics in how enterprises are deploying agents right now is how access accumulates. An agent gets stood up quickly because a team needed to move. It gets granted permissions because someone needed to unblock a workflow. A couple of months later, those permissions haven’t been reviewed, the person who deployed it has moved to a different role and the agent is still running with credentials that were granted for a context that no longer exists.
This isn’t negligence. It’s what happens when deployment velocity outpaces the organizational structures built to manage it. Human employees go through onboarding, access reviews and offboarding. Agents largely don’t. The infrastructure most enterprises are running was designed for a workforce of people and hasn’t been meaningfully updated for one where machines are doing an increasing share of the consequential work.
The practical implication is that access granted to agents is effectively permanent until someone decides to look. Most organizations haven’t built the trigger that causes anyone to look.
The Seniority Problem
What I’ve observed is that agentic governance tends to get treated as a technical problem: something IT handles, below the leadership line. The result is that accountability ends up wherever it lands, not wherever it was deliberately placed.
This is worth examining honestly at the executive level because the decision about who owns an agent’s behavior isn’t a technical one. It’s an organizational one. It requires someone with authority to say: this person is responsible, these are the boundaries and this is what happens when something falls outside them. That decision doesn’t get made by default. It gets made when a senior leader decides it’s theirs to make.
This doesn’t mean running more sophisticated technology than everyone else. It means making an explicit leadership decision to treat agent accountability the way you treat any other significant operational responsibility—with a named owner, defined scope and a review process that doesn’t require an incident to trigger it.
What It Takes To Stop A Compromised Agent
There’s a practical dimension to this that doesn’t get enough attention in how leadership teams think about AI deployment: The ability to act in seconds when an agent behaves unexpectedly isn’t a given. It has to be built deliberately.
An agent that drifts from its intended behavior, gets fed a malicious prompt or simply encounters a scenario its original logic didn’t anticipate can cause real damage in the time it takes a human to notice and respond. To help prevent this outcome, organizations should build a centralized revocation: a single point from which any agent can be isolated immediately, across every system it touches, without having to chase it down manually through each integration.
That capability sounds obvious until you consider how many enterprises would currently have to disable a compromised agent one system at a time. The ability to act instantly isn’t an edge case feature. In a production environment where agents have broad access to sensitive systems, it’s a basic operational requirement.
The Trust Question
Here’s what I’ve come to believe after watching this play out across organizations at different stages of AI maturity: The ceiling on how far any enterprise can scale its AI deployment isn’t compute, budget or even talent. It’s how much the leadership team trusts the environment they’ve built.
That trust doesn’t come from the technology. It comes from knowing who owns each agent, what it’s authorized to do, whether those authorizations are still appropriate and whether you can stop it in the time it takes to make a decision.
If you’re still treating this as something IT will sort out, you’re carrying a constraint you may not see clearly until it surfaces in the worst possible context. That’s the conversation worth having at the leadership level, and most organizations haven’t had it yet.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

