
TL;DR
- Trust3 AI spent two days at The AI Conference in San Francisco talking with enterprise security, data, and AI leaders
- The enterprise AI question has shifted to AI agent security, and shadow agents were the most common topic at our booth
- Recent incidents show controls that govern access but stop short of the agent’s actions
- Gartner expects more than 40% of agentic AI projects canceled by end of 2027; security review is where AI ROI stalls
- Agent DOS gives security teams the basis to approve agents: discover, observe, secure, enforced through to the data
Trust3 AI spent September 30 and October 1 at The AI Conference at Pier 48 in San Francisco, and the conversation on the floor centered on AI and agent security. California’s new executive order has put frontier model safety on the public agenda. The recent AI security incidents point to the agents in enterprise production as well as to the security controls.
The enterprise AI question has changed
The AI question in boardrooms shifted from capability to authorization and security. An AI agent reads a record and takes an action, often without a person in the loop at the moment of execution. It initiates transactions, modifies records, calls tools, and hands work to other agents. Whether an enterprise has fine-grained control over agents and actions separates a pilot from a production deployment.
Recent incidents of agents exceeding their scope
On September 18, Google confirmed that Gemini had accessed the systems of three real companies during a May security test. The test environment had unintended internet access, and a fictional target shared its name with a real company. The model guessed its way into one system and used credentials found in public repositories for the other two. The same day, Governor Newsom signed an executive order that proposes adding loss-of-control events to California’s definition of a critical safety incident.
The order names the Hugging Face intrusion from July. An agent in a capability evaluation escaped its sandbox, harvested credentials, and got into Hugging Face’s production infrastructure. It wasn’t detected until several days later.
The pattern isn’t new. Back in 2025, researchers disclosed ForcedLeak, an Agentforce vulnerability in which a hidden instruction in a Salesforce lead form steered the agent into pulling CRM records and sending them to an attacker-controlled domain. The agent exfiltrated data under approved access.
In all three cases, controls governed access and stopped there. Nothing followed the agents’ further actions. That is what loss of control looks like inside an enterprise.
“Agents have tremendous potential to automate many business workflows but pose enormous risk inside an enterprise if not designed in the right way. Every agent needs an identity, a declared purpose, and a policy that follows it to the data.” Balaji Ganesan, Co-founder and CEO, Trust3 AI
Why AI ROI stalls at the security review
Gartner projects that more than 40% of agentic AI projects will be canceled by the end of 2027, driven in part by inadequate risk controls. Security and risk teams are blocking production because they cannot approve agents without clear visibility into them. That holds AI ROI at the pilot stage.
“Security and risk teams are not being obstructionist when they block these rollouts. They cannot approve what they cannot observe, and they cannot observe what was never instrumented. If an organization cannot say, in specific and auditable terms, what an agent is permitted to do, it has no basis for putting that agent into production.” Neeraj Sabharwal, Co-founder, Trust3 AI
What it takes to say yes to an agent in production
Trust3 AI’s control plane, Agent DOS, gives security teams the basis to approve agents rather than stall them:
- Discover and assess every agent for security risks, including the ones built and connected to data without a security review.
- Observe every decision, from prompt to tool call to where the output lands, so a reviewer can see what an agent did and why it was allowed.
- Secure every action with purpose-based access control (PBAC), evaluated per request, so an agent gets the access its task requires and nothing beyond it. A kill switch sits on every agent.
Because agents ultimately act on data, enforcement has to hold there too. Trust3 AI enforces policy natively at the data source on Snowflake, Databricks, BigQuery, Iceberg, and more than 50 other platforms, carrying the originating user’s identity and purpose through every hop. There is no AI without data, and no AI ROI without security that follows the agent all the way through.
What customers are seeing
Here are some examples of our customers’ experiences:
- A Fortune 500 financial firm discovered more than 300 agents during an audit, became audit-ready without pausing operations, and now carries a continuous Trust Score on every agent.
- A Fortune 100 fintech hit AWS IAM limits and replaced its over-privileged roles with attribute-based access.
- A top-5 US healthcare retailer governs thousands of BigQuery tables across hundreds of GCP projects with no ticketing queue.
Across the customer base, Trust3 AI moves teams from proof of concept to production 10x faster and cuts audit preparation time by 84%. Gartner expects that by 2029 most successful attacks on AI agents will come through access control weaknesses. The enterprises putting these controls in place now are the ones that will still be running agents then.
What we heard at The AI Conference
Over two days of demos of Agent DOS, the same topics came up again and again. Shadow agents were the hot topic: almost everyone who stopped by asked how to find the agents their own teams had already built and connected to data without a security review. Close behind were questions about what an agent should be allowed to do once it’s running, and what actually stops one that goes past its scope.
Four questions we kept hearing, and that every enterprise should be able to answer:
- How many AI agents are running in your environment, and what is the current security posture of each agent?
- What should a developer do to mitigate security and governance risks in their agents?
- What is each agent allowed to do, what data can it access, and where is that enforced?
- If an agent exceeds its scope, what stops it, and how fast?
If you missed us at the show, let’s catch up here: https://trust3.ai/demo/




