Your AI Agent Is Not the Risk. Its Authority Is.

Autonomous agents are already making operational decisions, and most governance programs are still pointed at the model. Yogita Parulekar argues the real exposure is delegated authority: what an agent is permitted to do, under whose identity, with which credentials, and who is accountable when it acts. She explains why identity and permissions belong at the center of agent governance, and what secure-by-design architecture looks like for enterprises deploying agents at scale.

Key takeaways

•    Agents inherit the probabilistic nature of the LLMs they run on, so oversight has to scale with context rather than apply uniformly

•    Accountability cannot be delegated to an AI. It stays with the person or company the agent acts for

•    Human-in-the-loop oversight fails when reviewers lack authority, time, or expertise. One report found reviewers given 1.2 seconds to approve an output

•    Agent identity and permissions are the control surface, not the model

•    The blast radius sits at the agent level, so containment has to be architectural rather than retrofitted

•    Boards should work a four-part loop: goals, strategy, risks, oversight

About Yogita Parulekar

Yogita Parulekar is the founder and CEO of Invi Grid, a patented platform for secure-by-design cloud and AI infrastructure. She has built security and governance programs for nearly three decades, including as one of the first five people in EY India’s cybersecurity practice and as Oracle’s first technology auditor. She helps enterprises deploy AI with built-in governance, security, and compliance from day zero. She was recently named to the Silicon Valley Business Journal’s Power 100 and advises private company boards on AI governance through the Private Directors Association.

Yogita joined us previously to discuss AI governance fundamentals — start there if you are new to the topic.

 

In this episode

00:00 Welcome and guest intro
01:47 Why govern agents
02:19 What makes agents different
06:03 Context and risk tolerance
08:51 Guardrails and policy controls
09:56 Human-in-the-loop reality
10:56 Accountability and risk layers
23:09 Agent identity governance
25:53 Designing blast radius
29:57 Board-level governance model
35:27 Two starting points for production
39:03 Resources and leadership takeaways
42:58 Final message and wrap-up

In Yogita’s Words

“Agents are inheriting the probabilistic nature of the LLMs.”

“Accountability cannot be transferred to AI. It is on whose behalf AI is acting is finally responsible for the action.”

“Whether you are giving the agent the authority to change infrastructure or in healthcare settings to suggest a diagnosis — these are all very different.”

“If you haven’t used AI, use it. Your expertise and your wisdom doesn’t go away because of AI. It actually increases the need for your expertise.”

 

Resources

•    Yogita Parulekar on LinkedIn

•    Invi Grid — articles on secure-by-design cloud and AI infrastructure

•    MIT AI Risk Navigator — tracks AI-related attacks and incidents

•    MIT AI Incident Tracker

•    AI GovOps Foundation — co-hosted the executive roundtable this episode builds on

•    Private Directors Association

Cases discussed

•    Moffatt v. Air Canada (2024) — the BC Civil Resolution Tribunal held Air Canada liable for misinformation given by its chatbot

•    Replit AI agent database deletion (July 2025) — an agent deleted a production database and its backup during a code freeze

Related AI Realized episodes and events

 

Frequently Asked Questions

 
 
 
 
 
 
 
 
 
 
 
Next
Next

AI Governance as Code: From PDF Policies to Pipelines