Gartner warns traditional IT controls won't keep up with AI
Autonomous AI agents have outpaced traditional IT controls. CIOs must strengthen access and accountability and build controls to stop agents before they cause damage.
GRAPEVINE, Texas -- Reining in the risks posed by autonomous agents was a key theme at Gartner's 2026 Enterprise Risk, Audit & Compliance Conference.
Unlike assisted agents, which let humans review most outputs, autonomous agents make plans, access systems and take actions with little to no human approval. This autonomy makes them attractive to businesses, but it also makes them risky.
CIOs and other leaders who manage IT risk have relied on traditional identity and access management (IAM) and accountability controls to govern these agents. But those controls were designed for humans, not machines.
"Traditional controls assume human limits," said Devanshu Mehrotra, senior director and analyst at Gartner, during a session on "Hot Spots Deep Dive: Autonomous AI Systems."
Instead, CIOs and other IT risk leaders must update their controls for AI systems. They need better visibility into what agents can access and do, clear accountability for their actions and mechanisms to quickly stop them when they behave unexpectedly.
Autonomous AI is breaking traditional IT controls
Autonomous agents lack common sense, so they sometimes take bizarre paths to reach a goal. Mehrotra referred to a case in April involving the software company PocketOS, where an agent was asked to improve code in a staging environment. When the agent encountered a credential problem, it searched unrelated documents it had access to, found an API key with access to production systems and backups, and used it to rewrite the company's production code and backups.
We built IT controls around what a human could reasonably do. AI agents change the equation by making the unreasonable possible at machine speed.
Manish JainFounder and CEO of Strategic Horizon Research
The entire sequence unfolded in nine seconds, and no attacker exploited a vulnerability or gained unauthorized access. The agent already had access to the systems and used that access to pursue its assigned goal, Mehrotra said.
The incident illustrates a problem with traditional IT controls, which were largely designed around human behavior and limitations. Manish Jain, founder and CEO of Strategic Horizon Research, said in an interview with TechTarget that role-based access control assumes a human has a defined role, as well as predictable intent, and limited speed and attention.
"We built IT controls around what a human could reasonably do. AI agents change the equation by making the unreasonable possible at machine speed," Jain said.
An agent can have legitimate access to multiple systems and still combine those permissions in a way no one explicitly authorized. Traditional controls might evaluate each permission separately without accounting for the outcome that emerges when an agent connects them, Jain said.
Mehrotra described these potentially dangerous combinations as "toxic combinations." An agent's individual permissions may look reasonable, he said, while the full sequence of actions can create a problem that only becomes visible after something goes wrong.
Where traditional IT controls fall short
Mehrotra explained where traditional controls fall short when managing autonomous agents. With IAM, for instance, he said autonomous agents expose gaps in how organizations track their identities, understand their capabilities and review their access. Those gaps fall into the following three areas, he explained:
Lifecycle. Traditional access processes typically record an account and its owner without documenting the agent's purpose, expected behavior or changes in its capabilities. Human users usually go through an approval process before receiving access, but when applied to an agent, that process doesn't capture enough information about what the agent is supposed to do.
Visibility. An agent built by a business team or enabled by an existing application might not appear in a company's inventory. And even when an organization knows how many agents it has, that doesn't indicate how much authority they have or what actions they can take, Mehrotra said.
Access reviews. A review can confirm that each individual permission was approved without considering what could happen when an agent combines permissions across multiple systems.
Mehrotra's solution is to better understand autonomous agents, similar to how banks use "know your customer" processes to understand who they're dealing with and their risk profiles. Companies need to know what each significant agent is, who deployed it, its business purpose, what systems and data it can access, what decisions it can make and who's accountable for it, he said.
Each significant autonomous agent should have its own identity and a clearly named owner, Mehrotra added. The owner should understand the agent's purpose, approve its access and remain accountable if its capabilities change, he said, and monitoring must go beyond login activity to track the tools an agent uses, paths it takes and actions it completes.
Autonomous agents also expose gaps in traditional accountability controls. Mehrotra identified the following three assumptions that become harder to manage when agents act on their own:
Human approval. Traditional controls often rely on a person reviewing or approving an action before it happens. Autonomous agents, by design, can act without seeking approval at each step, reducing the time available for a human to intervene.
Overrides. A person can tell an employee to stop, but an agent needs a mechanism that can actually halt it while it's running. Without one, an agent could complete an action before someone can intervene, Mehrotra said.
Decision rights. Organizations also need to know how an agent's decisions are being made and preserve evidence of the actions that follow. Traditional accountability frameworks might not provide an immutable audit trail for autonomous systems, making it harder to establish what happened and who was responsible.
To overcome these shortcomings, organizations must build stronger intervention and evidence mechanisms into autonomous agents, Mehrotra said. He compared this to the Federal Aviation Administration's ground stops, which require aircraft to stop rather than simply advising them to do so.
"We need to build that kill trigger into autonomous agents," Mehrotra said. "When we want it to stop, the agent stops."
Human review still has a role, but it needs to happen early enough for someone to intervene before the consequences become unavoidable. Companies also need immutable audit trails that preserve evidence of what an agent did, similar to an aircraft flight recorder.
Approvals, technical overrides and immutable audit trails let organizations maintain accountability even when an agent makes and carries out decisions on its own.
Steps to take now
CIOs don't need to redesign every control at once. Mehrotra recommended starting with one significant autonomous agent and testing whether its behavior aligns with the authority the organization intended to give it.
For organizations beginning an autonomous AI governance effort, Mehrotra recommended using the first 30 days to select an autonomous agent with significant activity or potential impact and compare its stated purpose with its actual behavior in the logs. The goal is to see whether the agent is accessing systems, using tools and taking actions in ways that match its intended role.
Within 60 days of starting that effort, organizations should use a kill switch to test the agent's ability to stop.
"The goal here isn't to remove autonomy or require human approval for every action. It's to make sure autonomy is deliberate, bounded [and] visible," Mehrotra said.
Tim Murphy is a reporter covering IT strategy for Informa TechTarget, with a focus on IT leadership, governance, workforce skills and AI strategy. His enterprise technology coverage has earned multiple Azbee Awards.