Agentic AI
,
Artificial Intelligence & Machine Learning
,
Identity & Access Management

BRG’s Amy Worley on Identity, APIs and Governing Autonomous AI

Jennifer Lawinski
July 28, 2026    

Amy Worley, managing director and data protection officer, BRG

Autonomous artificial intelligence agents are creating a visibility and accountability problem that many enterprise security programs weren’t designed to manage, said Amy Worley, managing director and data protection officer at BRG.

See Also: OnDemand | Security Operations in the Age of AI

Agents can move through corporate environments, access sensitive information and make external API calls without leaving the identity trails organizations expect from human users or conventional service accounts, said Worley.

Traditional identity and access management systems record when a named user opens a file, enters a database or accesses an application. But agents frequently operate through shared API keys after they’ve already been granted access to an environment. That can make it difficult for organizations to determine which agent took an action, what data it accessed or where that information was sent. “You can’t govern what you don’t see,” Worley said.

The risk increases when third-party software vendors activate agentic features by default or grant broader permissions than technology teams realize. An agent optimized to complete a task may find that it needs additional information, retrieving sensitive data and transmitting it to an outside service through an API call that existing monitoring tools don’t inspect.

Worley advises CIOs and CISOs to inventory every AI system and agent operating in the enterprise. Organizations should provide employees with sanctioned AI tools, restrict access to unauthorized public services and assign each agent its own identity, credentials and accountable human owner.

In this video interview with ISMG, Worley discussed:

Why shared API keys and autonomous activity weaken enterprise traceability;
How shadow AI and default agentic features expose sensitive corporate data;
What CIOs and CISOs should prioritize when building agent governance by design.

Worley is a managing director at BRG and leads its privacy and information compliance practice group. A former attorney and global chief privacy, records and digital transformation officer, she advises organizations on global data protection, privacy risk and AI governance. She is also a certified AI governance professional and the author of a book on the subject.