IDC Warns Agentic AI Rollouts Need Identity And Audit Controls
No Jitter interviewed IDC research vice president Dave Schubmehl on agentic AI risks, including decision debt, non-human identities, red-team tests and audit trails.

Agentic AI adoption plans are advancing faster than many governance programs built for human users, No Jitter reported in an interview with IDC research vice president Dave Schubmehl.
An MIT/Google Cloud report put planned agentic AI implementation at 69 percent of organizations, while compliance, regulation and training-data concerns remain part of the deployment question.
For Schubmehl, the operational risk starts with decision debt.
Autonomous agents can make poorly governed decisions that accumulate across a company, creating a growing surface of authority and accountability problems as more agents and subagents enter production workflows.
Non-human identity governance is the control point organizations often misjudge.
Agents can acquire permissions, create subagents and act across connected systems, leaving a gap between policy documents and actual enforcement when the agent population expands faster than identity controls.
The pre-production checklist therefore has to test more than task completion.
Red-team exercises should probe prompt injection and adversarial attacks, while baseline and stress tests should examine how agents behave across the connected environments where they will actually operate.
Reversible controls such as kill, clamp and rollback functions need validation before launch, not after a failure has already crossed systems.
Auditability is part of the same deployment condition.
Complete audit trails and real-time monitoring instrumentation give security, compliance and operations teams a way to see which agent acted, what permission it used and where escalation should occur.
Without that record, a company may know an agent produced an outcome without being able to reconstruct the decision path behind it.
The runtime signals are concrete rather than theoretical.
Anomalous agent behavior, unexplained permission escalation, sudden cost or token-consumption spikes, model or agent-performance drift, missing audit logs and broken human-in-the-loop escalation can all indicate governance, security or operating failures.
That makes agentic AI a workflow deployment issue as much as an automation upgrade.
The system is not production-ready simply because it completes a task; identity boundaries, rollback options, monitoring and escalation paths have to be operating before autonomous software is allowed to act on behalf of the organization.




















