Neeraj Sabharwal is Co-Founder at Trust3 AI, passionate about bridging the gap between business and technology. He believes that Your Data Platform Is Not Your AI Security Strategy, and new approaches are required for true protection.
Enterprises have spent a decade learning to secure their data. Who can query which table, what’s encrypted and who gets alerted when something looks wrong. Now that agents have access to that same data, the key question shifts to what they do with it.
Enterprise security leaders cannot find the answer in the data platform.
The Flawed Assumption Driving AI Failure
Data security programs took years and huge budgets to build. Access controls, encryption, role-based permissions: These are mature, well-understood disciplines. So when AI initiatives launch, it’s natural to assume the existing security stack has this covered, too.
It doesn’t.
Data security was designed to answer one question: who can read what. It was never built to define what agents can do, or under what conditions.
This distinction is the reason so many AI pilots that prove ROI in a sandbox never survive contact with production. The model works. The use case is validated. The project stalls at the security check.
Reading Data And Acting On Data Are Not The Same Risk
A traditional data breach is an exposure event. Someone accessed information they shouldn’t have. The damage is limited to what was seen.
An AI agent introduces a different risk category because agents act on data in addition to reading it. They initiate transactions, modify records and trigger downstream workflows, often without a human in the loop at the moment of action.
Consider a healthcare AI agent with access to patient records. Under a data security model, the relevant question is whether the agent’s access is authorized. But the outcome-defining question is: Can this agent update a diagnosis, alter a treatment record or trigger a billing action, and under what constraints?
An agent operating without clearly defined authority is catastrophic. The current generation of data security tooling has no native way to prevent it. Until something goes wrong, an AI agent’s authority is indistinguishable from a human’s, except it can act faster, at greater scale and without the judgment a human brings to ambiguous situations.
Why The Governance Gap Kills Production
Enterprise AI leaders have largely solved the model problem. Performance, accuracy and cost have improved over the past two years. Governance infrastructure built for autonomous action hasn’t kept pace.
Gartner projects that “over 40% of agentic AI projects will be canceled by the end of 2027,” driven in part by inadequate risk controls. A proof of concept succeeds in a controlled environment because the blast radius is small and the stakes are low. Scaling that same agent into production means scaling its authority, too. Most teams find out too late that they never defined what authority should cover.
Security and risk teams are not being obstructionist when they block these rollouts. They cannot approve what they cannot observe, and they cannot observe what was never instrumented. If an organization cannot answer, in specific and auditable terms, what an agent is permitted to do, it has no legitimate basis for putting that agent into production.
Agent Identity And Guardrails Are Not Optional Infrastructure
The enterprises succeeding with AI at scale share a common trait: They stopped treating agents as extensions of the people or systems that launched them. They started treating them as independent actors requiring their own governance model.
That model rests on four nonnegotiable components:
Defined Agent Identity: Every agent needs a distinct, auditable identity, separate from the human or service account that deployed it. Without this, accountability collapses the moment something goes wrong.
Explicit Permitted Actions: Agents should operate under an enumerated, enforceable set of allowed actions, not inherited or default access. If an action isn’t explicitly permitted, it should be technically impossible, not merely discouraged by policy.
Real-Time Observability: Enterprises need continuous visibility into what agents are doing in real time, instead of periodic audits after the fact. By the time a quarterly review surfaces a problem, the damage is already done.
Instant Kill-Switch Capability: When an agent behaves unexpectedly, teams need to halt its actions immediately without taking down the entire system.
None of these four capabilities comes naturally from a data platform, no matter how mature its security posture. They require a governance layer purpose-built for autonomous action, sitting alongside existing data security infrastructure.
Five Questions Every Enterprise Must Answer Before Agents Ship
Before any AI agent moves from pilot to production, leadership should be able to answer the following without hesitation:
1. Does this agent have an identity distinct from the human or system that launched it?
2. Is there an explicit, enforced list of actions this agent is permitted to take?
3. Can we observe, in real time, exactly what this agent is doing right now?
4. Can we shut this agent down instantly, without disrupting the broader system?
5. Who is accountable if this agent takes an unauthorized action, and how quickly will we know?
If any of these questions produce hesitation rather than a confident answer, the agent is not ready for production, regardless of how compelling its pilot results were.
The Path Forward
Data security will not get enterprises through the next phase of AI adoption, because the risk profile has fundamentally changed. Reading data and acting on data are different problems, and only one of them has been solved at scale.
Enterprise AI leaders who want to move past the pilot graveyard need to treat every deployed agent as its own actor, with its own identity, its own explicitly defined scope of action and guardrails enforced at runtime, not just documented in policy. This isn’t an incremental addition to an existing security program. It’s a distinct discipline that has to be built, resourced and owned before the next agent goes live, not after the first incident forces the issue.
Read Full Article: https://www.forbes.com/councils/forbestechcouncil/2026/10/09/your-data-platform-is-not-your-ai-security-strategy/



