Gravitee Sets a Framework for AI Agent Governance
AI Agent Governance Needs Clear Accountability
AI agent governance is becoming urgent as enterprises move from experiments to production systems. In this Techstrong TV conversation, Mike Vizard talks with Rory Blundell, CEO of Gravitee, about a framework for securing AI agents before they create business risk. The discussion centers on a simple idea. Agents need identity, role, authority, oversight and recourse before organizations can trust them at scale.
Blundell explains that AI agents are not just another automation layer. They can act at machine speed, reach into systems and make decisions that affect data, operations and customers. That changes the security conversation. Teams need to know who owns each agent, what the agent is allowed to do and what happens if something goes wrong.
Trust Becomes the Foundation for AI Value
Gravitee’s view is that AI agent governance should enable adoption rather than slow it down. Blundell says many CIOs and CTOs are under pressure to put agents into production. Yet the transcript notes that only about 20% of those production agents are considered fully secured by the leaders deploying them.
That gap can limit the value of AI. One incident can wipe out months of expected return from an agent project. A trust layer gives teams a way to keep moving while reducing the attack surface. It also helps business leaders understand which agents exist, what services they touch and where human responsibility sits.
Old Security Lessons Still Apply
The conversation also makes the case for applying proven security thinking to new AI systems. Blundell argues that organizations should not forget the governance, security and control models they built during the internet era. APIs, MCP services, event streams, LLMs and AI agents all need abstracted control layers.
That approach does not require a single silver bullet. It requires defense in depth. Guardian agents, identity controls, service boundaries and human oversight can all help reduce risk. The goal is not to stop AI adoption. The goal is to make adoption safer and more sustainable.
InfoSec Has a New Role in Human-Agent Collaboration
For security leaders, the episode offers a practical message. They do not need to become the people who simply say no to AI. Instead, they can help build the conditions for human-agent harmony. Blundell argues that people and agents working together can create more value than either side alone.
That value depends on trust. If employees do not trust agents, they will resist using them or avoid giving them meaningful work. Strong AI agent governance gives organizations a path to productivity without giving up control. It also gives security teams a central role in turning agentic AI from a risky experiment into an operating model.
Transcript
Hey guys, thanks for the throw. We're here with Rory Blundell, who's the CEO of Gravity, and they have a new framework for securing AI agents, and we're going to dive into, well, why do we need this new framework? Rory, welcome to the show.
Hello, Mike. Lovely to be here. We have seen everybody and his brother is building something that looks like an AI agent, and some of these things go rogue, and some of them are doing things they're not supposed to be doing.
But it's not clear to me or probably anybody else at this point exactly what needs to be done to kind of isolate and contain these things in a way that allows them to do their job without maybe wreaking a whole lot of havoc. So what's going on here, my friend, and what are the challenges, and what are we going to solve with a framework? That's a great question.
Look, I think what's going on at the moment is we've seen over the course of the last, let's say three weeks, a number of situations where AI agents, people have called it going rogue and stuff like this, as you just referenced. But ultimately, what we're really seeing is the power of AI and agents and what they can actually do. And so our belief is what we have to do is we have to introduce this framework to provide governance, security, and control.
And so our belief is there are some fundamental points that are missing at this particular moment in time from an AI perspective. Simple things like what sort of authority does an agent have? Does it have a clear owner, a human who's responsible for it?
Is it very clear that it has its own unique identity and that it's not conflated with that of the human who has the sort of named responsibility? There's a number of these things, and in our view, it really comes down to five key points, right? Identity, role, authority, oversight, and recourse.
Those are the five points that we believe need to be addressed to be able to get the real economic benefits that AI can bring. What is the challenge in addressing that? I mean, is a framework a set of best practices here, or is it some idea of maybe something we're supposed to add to our runtimes and it's a hard piece of code?
But what exactly needs to be done to achieve those five points? It's a great question. It's definitely not the latter, in terms of some code that's hard-coded into a particular runtime or something like that.
It's much more of the former. Look, if you think about all of those five points that I just mentioned there, like identity, role, authority, oversight, and recourse, it's a combination of different things that are required. So it's our view that in order to get the economic benefits from AI, you do need things like a named human who is responsible.
That's not something that's hard-coded into a particular application or a back end or anything like that. This is a set of guidelines that we recommend that people utilize to be able to get the most from their agents. And that's the point I really want to emphasize, though, Mike, is because a lot of people will look at this and think, "Hmm, he's just talking about security.
" And all that sort of stuff. Is it more sort of oversight than is required? And I would say what's become apparent, research that we have done at Gravity, has shown that at the moment, CIOs and CTOs are putting more and more agents in production.
They're feeling more pressure to do this. But only about 20% of those agents that are going into production, according to the CIOs and CTOs, are fully secured according to them. And so our view is that when you don't have the foundation of trust in a new phase of the economy, which is what AI really is, you're never going to get the economic benefits from it, because people won't be able to trust what their agents are doing, who's doing it, when's it doing it?
Does it have the authority to do it? Who's going to be the one that picks up the bill if something goes wrong? All these sorts of things are absolutely critical and fundamental to ensuring that we can generate the economic benefits out of AI.
I think a lot of people are at least are instinctively aware that it probably only takes one incident to wipe out months of ROI from an AI agent project. But at the same time, we seem to be struggling with the whole idea of, well, how to do the right thing here and put these best practices into place. So what's your advice to folks about how to kind of operationalize what's in the framework?
For me, I think the framing of your point there is exactly right, and I feel what's happening in the market. And I will answer your point directly, Mike, which is that my point that I would say to CIOs, CTOs, and technologists more generally is don't forget everything that you built and all of the key frameworks and all of the key thoughts that you had over the last 25 to 30 years in the internet age. Don't forget that stuff.
You would never have dreamt as a CIO or a CTO of allowing... " And this is the year 2010, for example. You would have probably fallen off your chair, Mike.
But today, because CIOs and CTOs are feeling the pressure, because we're in a new paradigm, they aren't applying the same principles of these abstracted layers of governance, security, and control on top of their services. So whether those services are AI agents, whether they're LLMs, whether they're MCP services, whether they're APIs, whether they're Kafka services, whatever it may be, put an abstracted layer in place And that's where you get governance, security, and control, and that would be my advice at this particular point in time. Some people say that the AI agents are just exposing weaknesses in our policies and controls as they are, and trying to apply guardrails to the AI agents themselves is kind of a fool's errand because, well, they're just too smart, and they'll end-run our way around various policies and controls, and they'll find some backdoor into something, and it is what it is.
So how do we strike a balance between those two thoughts? This is something I've given a lot of thought to, and I believe that what we've come up with at Gravity is something we call Guardian agents. Because the way that you framed it there, which I think is how a lot of people think about it, Mike, is that there's a silver bullet answer.
There isn't. Let's not kid each other that there aren't vulnerabilities in the world and all these sorts of things. There are.
But my point is that it's about strength in depth, and you have to reduce your attack surface. That's, again, just learn from previous generations. Even though that we're now operating, all these agents can operate at machine speed, whereas in the past, we operated at human speed, and we still identified these vulnerabilities.
What InfoSec teams, et cetera, would always do is try to reduce the attack surface and really try to contain the depth that the attack could go. There's nothing different here. But how do you reduce the attack surface, and how do you reduce how deep it can go?
That's the question in the agentic world. And my view is the answer is Guardian agents. And what these Guardian agents are is almost like, think of AI checking AI's homework, if that makes sense.
So you've got an LLM that's given you a response. What we've implemented at Gravity with the Guardian agents is that every single response from an MCP server or from an LLM or anything in your AI ecosystem, let's say from another agent, must go through the layer of Guardian agents. And these Guardian agents can be strength in depth.
" And it will just block all of those sorts of things. And you then might have a second agent, which is using a very specific model, let's say a classifier model, that's specifically determining should a human be engaged or should a human not be engaged. But these are two separate agents, so you have this layering where you're not expecting a silver bullet, but you're adding all of these layers of different Guardian agents to add that layer of guardianship and governance to the agentic world.
Do we need something that feels like a zero trust approach to this? Because a lot of the AI agents, well, they're aggressive, and sometimes they will say they did something that they didn't do, or they did do, and then they'll say they didn't do it. And you can't help but wonder if there's just some sort of approach here, because, I don't know, do we need AI agents, to your point, to manage and keep track of what other AI agents are doing?
Otherwise, if I ask the AI agent about it, it's essentially asking the fox what just happened in the henhouse. I think everything you said there, I would agree with, the exception of the asking the fox about the henhouse type analogy, because these would be two separate agents with very specific scoped, not just permissions, but, rules, I would say, of what they're doing. Now, coming back to your point, though, pardon me.
How do we really bring this to bear? How do we actually do all this sort of stuff? Look, it's complex, but the framework that we've implemented is a set of guidelines.
But actually, the platform that we have built at Gravity really does enable this sort of stuff. It's not wishful thinking. This is stuff we're doing right now.
So everything that CIOs and CTOs are struggling with at this particular point in time, I believe there are answers to it, and that's what we can address at Gravity. Is it your sense that despite these concerns, people are deploying these AI agents, and at this point, is it going to be a matter of a couple of very well-publicized incidents before we all kind of wake up and understand what their issues are? Or conversely, are we about to suffer death by a thousand cuts before we finally get around to figuring out what needs to be done here?
That is a good question. Being brutally honest about it, I don't know which of those two is more likely. My sense is that, as I mentioned, over the course of the last few weeks, we have seen, I think, about four to five, let's say, major newsworthy events with agents going rogue or whatever we want to call it, okay?
" sort of thing? Maybe. But I think what was helpful over the course of the last couple of weeks is that there was a crescendo of noise, I would say, in relation to these items, because a lot happened at the same time.
And I think it's just vitally important that people wake up to the governance crisis that they have in their organizations, and they're not going to get the economic benefits if they don't start implementing this sort of stuff. So is it a death by a thousand cuts or is it big bang? I'm not 100% sure.
I hope that people wake up to it sooner rather than later, though. If we don't wake up, it seems probable, and I think we've already seen some moves in this direction, where bureaucrats and regulators who don't understand the technology are just going to start writing rules anyway. Yeah.
And so is this incumbent upon us in this industry to go fix this problem before the, quote-unquote, "end users wake up and start creating policies that are going to be, shall we say, difficult to maintain and implement"? Yeah, I think you're right in your characterization of legislation that's been thought about. The most prominent one probably is the European Union's piece of legislation, I would say.
But I think in research that I've done, because I'm writing a paper actually about this particular subject, about the role of regulation in AI, what you've noticed is there's a lot of states, in actual fact, who've tried to enact their own pieces of legislation that aren't a million miles away in terms of their raison d'être, if you will. What they're trying to achieve with the legislation. Now, do I think the legislation is the entire answer?
No. And I do think you're right, because when you read the pieces of legislation, I guess the best way that I can characterize the legislation is it almost treats the AI as like a tin of baked beans or... That's actually a very British thing to say.
Let's say a tin of sweetcorn or something like that, something that's immutable, it doesn't really change. Okay, it might go off in time, but a tin of sweetcorn is going to be a tin of sweetcorn in 10 years' time, right? But the thing with an AI agent is that every time you're prompting it and it's getting responses and it's doing stuff, it's non-deterministic.
And so they've got this sort of concept of risk tiers and all this sort of stuff that they'll put into it, that to my mind, is complete nonsense. Because something that can start the week as low risk can end the week as very high risk. And this is why we think guardian agents are needed, this strength in depth, that actually our belief at Gravyty is there is an illusion of low risk.
There is no low risk in this world of AI. Actually, everything should be treated, generally speaking, as high risk, because you need to make sure that you have the oversight, the governance, the control, the human in the lead, all these sorts of things to give it that purpose. But I do think you're right, that you have to be incredibly careful if you don't actually enact these sorts of legislations, and leaders like me don't speak more about this sort of subject, because otherwise you will get pieces of legislation that probably aren't fit for purpose.
What is your best advice therefore to the information security people that are kind of at the heart of this? Because many of them have been told to basically stand down in the name of productivity. We're going to roll out these AI agents because, well, we're afraid of being left behind.
And a lot of those people don't want to show up and be the person at the party telling everybody not to drink so much AI punch, right? It's a great question. Look, my belief is that those professionals need to push back on that, but they need to push back on it in a different way, because I think the way the AI...
Look, let's be brutally honest with each other. The information security teams in many large organizations are characterized as the "no" people and all this sort of stuff, right? My personal belief is that actually this point in time gives them a massive opportunity to reframe their position.
Because I genuinely believe that unless you build this trust layer through these agentic interfaces, you're not going to be able to get the economic benefits. And there's a ton of research actually, in relation to this. Both Stanford and MIT have done research papers that actually talk to very clearly that humans and agents working together, they have a productivity benefit of in the region of about 60, 65 to 70% over humans alone or agents alone.
So the answer is human agents together. So then you have to ask the question, if that is the benefit, is 65 to 70%, then how do you achieve what I call human agent harmony? How do you achieve that?
And that is where InfoSec is required, because you cannot achieve human agent harmony if the humans don't trust the agents. So you have to build the layer of trust in order to be able to get the economic benefits. All right, folks, you heard it here.
Hey, there's a consensus building, and it's kind of simple. The one thing everybody seems to agree on is that we can't really trust those AI agents, and that gives us a starting point to have the next conversation. Rory, thanks for being on the show.
Cheers, Mike. And back to you guys in the studio.