A Leader’s Guide To Agentic Governance
In an interview, Yahoo CISO Sean Zadig told me agentic AI is putting storied tech firms—even giants like Yahoo—in uncharted waters.
“As an industry, we’re all building the plane as we’re flying it,” Zadig said. “And so there’s not a ton of well established best practice.”
Companies everywhere are rapidly adopting AI, excited by its promises of efficiency, comprehensive research and assistance in content creation. But as AI technology advances, models become more capable—and more likely to take unwanted actions. In the last month, OpenAI, Anthropic and Meta have all disclosed that their most advanced AI models hacked into external systems without being directly prompted to do so.
AI risk management and security expert T.J. Marlin, who is founder and CEO of Guardrail Technologies, told me he wasn’t surprised by the news, and said it likely foreshadows what’s to come.
The time is now for companies to start taking agentic AI governance seriously. This edition of the Forbes CEO newsletter focuses on how that’s being done. I talked to Zadig, Marlin, as well as Amazon Chief Security Officer Stephen Schmidt about ways to shore up AI governance.
This is the published version of Forbes’ CEO newsletter, which offers the latest news for today's and tomorrow's business leaders and decision makers. Click here to get it delivered to your inbox every week.
AI agents are sophisticated programming functions that use artificial intelligence to take actions, ranging from handling customer support calls and chats to automatically generating reminder emails to generating refunds for product returns. But Guardrail Technologies’ Marlin has a more blunt way to describe AI: “It’s almost like a drug.”
“Everybody is adopting it because they believe that they need to use it to create content to make their life easier, whether you’re in an organization or an individual,” he said. “But the problem is the nature of the technology has a lot of considerations. And it’s not just about what the model says. It’s what the agent can do.”
Marlin spent most of his career investigating large corporate crises as a principal at EY, and started Guardrail last summer to channel those skills toward the tech sector. He spent more than a decade digging into the root causes of “when situations go sideways,” leading a huge section of EY’s business and developing a software platform to find corporate issues and respond to them.
Based on what he knows about the aforementioned AI hacking incidents from OpenAI, Anthropic and Meta, Marlin isn’t sure if any were situations that went sideways—but he can say it appears it was AI that went beyond its mandate. AI should only be able to do the bare minimum possible to perform its job, and considering that the agents hacked into other systems, either the governance........
