In an interview, Yahoo CISO Sean Zadig told me agentic AI is putting storied tech firms—even giants like Yahoo—in uncharted waters.

“As an industry, we’re all building the plane as we’re flying it,” Zadig said. “And so there’s not a ton of well established best practice.”

Companies everywhere are rapidly adopting AI, excited by its promises of efficiency, comprehensive research and assistance in content creation. But as AI technology advances, models become more capable—and more likely to take unwanted actions. In the last month, OpenAI, Anthropic and Meta have all disclosed that their most advanced AI models hacked into external systems without being directly prompted to do so.

AI risk management and security expert T.J. Marlin, who is founder and CEO of Guardrail Technologies, told me he wasn’t surprised by the news, and said it likely foreshadows what’s to come.

The time is now for companies to start taking agentic AI governance seriously. This edition of the Forbes CEO newsletter focuses on how that’s being done. I talked to Zadig, Marlin, as well as Amazon Chief Security Officer Stephen Schmidt about ways to shore up AI governance.

This is the published version of Forbes’ CEO newsletter, which offers the latest news for today’s and tomorrow’s business leaders and decision makers. Click here to get it delivered to your inbox every week.Addicted To Agents

T.J. Marlin, founder and CEO of Guardrail Technologies

LinkedIn

AI agents are sophisticated programming functions that use artificial intelligence to take actions, ranging from handling customer support calls and chats to automatically generating reminder emails to generating refunds for product returns. But Guardrail Technologies’ Marlin has a more blunt way to describe AI: “It’s almost like a drug.”

“Everybody is adopting it because they believe that they need to use it to create content to make their life easier, whether you’re in an organization or an individual,” he said. “But the problem is the nature of the technology has a lot of considerations. And it’s not just about what the model says. It’s what the agent can do.”

Marlin spent most of his career investigating large corporate crises as a principal at EY, and started Guardrail last summer to channel those skills toward the tech sector. He spent more than a decade digging into the root causes of “when situations go sideways,” leading a huge section of EY’s business and developing a software platform to find corporate issues and respond to them.

Based on what he knows about the aforementioned AI hacking incidents from OpenAI, Anthropic and Meta, Marlin isn’t sure if any were situations that went sideways—but he can say it appears it was AI that went beyond its mandate. AI should only be able to do the bare minimum possible to perform its job, and considering that the agents hacked into other systems, either the governance was too permissive or the controls were not tight enough.

“AI is going to find a way,” he said. “But just like a bad actor outside, it’s going to try different things.

“You want to have controls in place that make it like a video game: To get to the top level, you [almost] can’t get there because it’s so freaking hard, essentially,” Marlin said. “And that kind of thinking has not been applied at scale today in the world.”

AI Agents As People (Sort Of)

Yahoo CISO Sean Zadig

Yahoo

Yahoo’s Sean Zadig said that while AI agents are the result of sophisticated programming, he looks at them as the equivalent of “very fast people.”

And Yahoo treats them that way. AI agents are non-deterministic—meaning that, like people, they may provide different answers when asked the same question more than once. But they’re trained to quickly weigh options, do research and make decisions: the same kinds of things that people could do.

In general, he said, businesses are gung-ho about bringing agents to their companies’ operations as quickly as possible. They’ve heard about the possibilities, and they want those capabilities right now.

Information security teams, on the other hand, are much more cautious about deploying AI agents everywhere. Zadig said that they’re technical people who are excited about what AI agents can do, but they also readily see the areas that might be vulnerable, or not as secure as they should be.

Zadig’s cybersecurity team has nicknamed itself “The Paranoids,” and he tries to ensure they’re not seen as innovation blockers. He said they’ve adopted a “Yes, and…” philosophy for when they’re approached with ideas involving AI agents.

“We can say, ‘Great, we’re there with you, but we need to do things in a safe way,’” Zadig said. “And I think we’ve built that trust so the business is accepting of that, and understands that we want to move as fast as they do, but we got to slow down a little bit.”

At Yahoo, the company decided to regulate AI agents more or less in the same way they regulate humans, and has worked with security provider Okta to create a solid system. Agents have identities in the system, which give them access to what they need—but also logs their actions, giving the cybersecurity team visibility into what agents are doing. Zadig said it’s important to be able to go back and see why agents made decisions: Were they acting on a human’s prompt, or was it a failure (or success) of governance? Having that trail is important—especially because agents move faster than people.

“They started out as assistants, and then they became co-workers, and now with a fully agentic enterprise, you’re their manager and they’re your employees, basically,” Zadig said.

Agent Babysitting Duty

Amazon Chief Security Officer Stephen Schmidt

Amazon

Amazon’s Stephen Schmidt said for a long time, the company worked with two types of identities: people and machines. But AI agents are neither, though they need identities because they need permissions to take actions. Amazon built a third type of identity classification for agents—not only so they can tell if an action was taken by a person or an agent, but also to grant specific permissions to agents so they only have access to the data they need to complete a task.

Because agents have the ability to act—but not the ability to reason like a human—the distinction is important, Schmidt said.

“Agents are like 2-year-olds with a hammer,” he said. “They will find a way to smash the nail, regardless of what’s going on, or whether it makes sense. And so you have to put different guardrails around agents than you would around a person.”

Schmidt said Amazon has two rules of agentic identity. The first is that agents have the absolute minimum permissions to perform the tasks asked of them. Amazon also logs everything that agents do so they have a record of how decisions were made.

Amazon has also strengthened identity guardrails for both agents and people. Schmidt said that for a person to authenticate, they need more than credentials: All employees have a physical key to put into the computer and touch in order to gain access. (Incidentally, Schmidt said, this also stops hackers from accessing sensitive information.)

There are jobs that are perfect for AI agents, Schmidt said at this summer’s AWS Summit in Washington, D.C. They’re great at building new ways to detect potential cybersecurity attacks, which used to need to be done by people. With AI agents, detections have gone up more than 300%. But not all jobs are great for AI agents. At the time, Amazon’s agents were about 83% accurate—an impressive number, he said, but falling short when you consider cybersecurity applications really should be 100% accurate.

So how can companies make up for that imperfect percentage? Schmidt said Amazon has different agents that double-check and supervise what the agents are doing. For cybersecurity applications, a “red team” of agents has fought against the agents protecting the company. And they do keep humans in the loop, but they’ve got some backup as well. Vulnerability in the software stack isn’t the biggest source of problems, he said.

“The biggest is your insider. Your authorized person who has access to those systems, who may not be your friend, but also somebody who may be in a situation where their identity gets compromised by somebody else,” Schmidt said.

And how does Amazon deal with that threat? Another agent, Schmidt said: One that knows a person’s normal behavior, and can flag when they deviate from it—like if a user is logging in from Chicago when they live and work in San Francisco, or doesn’t perform their usual email and weather forecast check within minutes of getting online.

Misplaced Trust

Many non-technical company leaders, boards and employees are relatively unaware of the threats and potential issues AI agents bring, Marlin said. And because the large frontier models are generally deemed “safe,” they tend to incorrectly think that everything they do with data is also completely “safe.”

But that’s far too simplistic, he said. Security—especially when dealing with AI—is extremely nuanced. Marlin compared it to social media: It can be a good tool to connect people, but there’s also the dark side of addiction, an abundance of advertising and scams, as well as a proven deterioration in mental health for young people.

Marlin said the recent incidents have amplified awareness of the need for better AI governance, but what’s actually needed are changes in behavior.

How can they get there? Marlin said they need to understand their AI and systems. Boards and executives need to exercise some professional skepticism, he said. After all, the Securities and Exchange Commission requires publicly traded companies to disclose cybersecurity risks—and if they don’t explore the risks of AI, they’re not in compliance.

Marlin said it helps to start with revisiting the company’s AI strategy: What do they want to do, how do they want to do it, and how is it currently governed and secured? Ask questions about the agents they have: How many are there, what are they supposed to do, who has access to them, and what data can they get? Executives also should get a bit more hands on with their AI so they can understand it and ask the right questions. “The C-suite is supposed to be the driver of the organization,” he said. “How can they drive without a steering wheel?”

He put it another way. “The question for CEOs is not whether they trust AI,” Marlin said. “It’s a question of whether their organization has engineered AI so that trust isn’t the control.”

Strategies + Advice

The world learned last week that President Donald Trump secretly left July’s NATO Summit in Turkey in a smaller plane, using Air Force One as a decoy following Iranian threats. And while the public may understand a leader’s deception for security reasons, there are many other situations in which people may not forgive a lie. Here are five questions to ask yourself before being less-than-honest.

Reading the news nowadays can bring about anxiety—especially because stories on the economic situation and tariff issues seem to dramatically change the situation every day. Instead of focusing on the top issues in the news, here’s how to build an economic dashboard to get a truer sense of what’s happening.

Quiz

Activist investor Nelson Peltz’s Trian Fund Management is reportedly preparing a bid to take which fast food restaurant chain private?

A. Domino’s Pizza

B. Jack in the Box

C. Wendy’s

D. Shake Shack

See if you got the answer right here.