The Rise of the Guardian: Securing the Era of Agentic Autonomy In 2025, AI agents officially became “a thing.” A mid-year CISO survey found that two thirds of enterprises already run AI agents in production and a further 23% planned to do so this year. This warp-speed adoption is already outpacing established security controls, with Gartner reporting in their Market Guide for Guardian Agents that “enterprises are rapidly adopting AI agents, but governance and control mechanisms are not keeping pace.” Embodying the unprecedented combination of the boundless improvisation of humans with the endless stamina of software, the benefits have immediately become clear. (What enterprise wouldn’t want its most creative employees working 24/7/365, without complaint, illness or personal time off?) However, more recently, so too have the risks- unplanned, if unintentional, business interruption; an exploitable target for threat actors seeking access; a source of identity dark matter, the unseen layer of unmanaged identity. To add insult to injury, AI agents not only expand identity dark matter, they also exploit it. Despite the endless stamina highlighted earlier, AI Agents are, by design, lazy- always looking for the most efficient path to return a satisfactory outcome to each prompt. However in doing so, identity dark matter- like orphan, dormant accounts or loose tokens, usually with local clear-text credentials and excessive privileges- often provides the shortcuts necessary to reach the “end of job,” regardless of whether they should have been allowed to do so. So, how does an enterprise unlock the value of AI Agents while managing the risk of this new- neither human nor machine- element of the workforce? 1. Use Agents to Supervise Agents Expand your identity governance program to cover this new class of workers, with a new extension to identity and access management (IAM)- the Guardian Agent. Gartner defines Guardian