I have been saying this for the past year: we are increasing the autonomy of AI agents faster than we are building the systems to control them.

The recent incidents are a good reminder.

OpenAI has acknowledged that thousands of its agents used a German wiki as an unintended communication channel, posting around 18,000 messages and finding ways around restrictions. This followed the Hugging Face incident, where agents found ways out of a sandbox, accessed the internet, shared discoveries and compromised external systems.

The concern is: We are moving very fast on agentic capabilities, but security, governance and sovereignty are not moving at the same pace.

Having worked on taking AI solutions into production, especially external-facing ones, I think we need to spend less time talking about what could go wrong and more time building the technical layer to deal with it. Below is what I would recommend as a must have capabilities if you are building an agentic ecosystem:

  1. Agent Registry: Every agent should have a known identity, owner, purpose, model, version, environment and lifecycle.
  2. Tool Registry: Every tool needs defined capabilities, permissions, risk levels and clear boundaries on which agents can use it.
  3. A Data Registry that tells us what data an agent can access, its classification, residency, lineage and the purpose for which it can be used.
  4. Build runtime observability that captures the agent’s decisions, tool calls, data access and actions, not just application logs.
  5. Have continuous evaluation because the behavior of an agent can change when we change the model, prompt, tools or environment.
  6. Need policy enforcement, sandboxing, isolation and kill switches so that an agent cannot simply find its own path around the controls we designed.
  7. And build sovereignty into the architecture: where the agent runs, where data goes, which models we depend on and what happens when those models or providers change.

These are not governance documents that should sit next to the product. They need to be part of the engineering architecture.

We built IAM, API gateways, service registries and observability because distributed systems could not scale without them. Similarly, I think agentic systems are reaching the same point.

The next challenge is not just building agents that can do more. It is building the control plane that allows us to safely give them more to do.