Agent Governance and Observability: Mitigating Risk and Eliminating Rogue AI Cost Centres
Scaling use cases means scaling agents: IDC research shows that organisations expect to double the number of distinct agent types in 2026 alone. The more agents you run in production, the wider the gap between what your governance frameworks were built for and what they are now being asked to cover. Unmonitored agents create compliance exposure and unaccountable costs, while unsanctioned workloads silently drain budgets. “The immediate threat from agents is self-inflicted harm due to poorly governed agentic deployments,” says recent IDC research.
This track addresses the governance infrastructure required to scale safely, covering identity and access controls, observability frameworks, and audit capabilities that keep agents within defined boundaries and leadership fully informed.
But governance is only half the equation. The same forces driving agentic adoption inside your organisation are arming the adversary outside it. Attackers are now using AI to probe, exploit, and move at machine speed — automating reconnaissance and scaling social engineering beyond what human teams could mount. “Threat actors, increasingly augmented by their own AI systems, are already compressing attack life cycles from days to hours and, soon, from hours to minutes,” says IDC.
Defending an expanding agent estate demands a posture that is equally automated, continuous, and intelligence-led. Organisations need to scale with confidence by treating governance and cyber resilience as two sides of the same strategic imperative.
Sponsored By:
Duncan Brown
Duncan Brown is associate vice president, European Security Practice, at IDC EMEA and leads the firm’s security research program in Europe. He specializes in providing strategic advice to his clients, informing and validating their corporate, product, and marketing plans. Brown is an expert in analyzing the security market globally, and his list of security-related clients includes enterprises, central banks, government organizations, and security product suppliers and services providers. Brown’s expertise spans the gamut of security topics including incident response, threat intelligence, and global privacy issues. He established and leads IDC’s coverage of the global impact of the GDPR, the RPEC (ePrivacy Directive update) and NIS Directive on technology companies and their customers. His analysis and opinions are widely sought by industry leaders and investors, while his comments on industry trends and developments frequently appear in the leading business and trade publications.
Rob O’Connor
Rob O’Connor is Insight’s EMEA CISO and is a business technology innovator focused on advancing cybersecurity across diverse industries. He leads regional security strategy, resilience planning, and risk alignment, helping organisations strengthen their security posture while enabling digital transformation. With expertise spanning cloud security, threat management, and modern security operations, Rob is known for translating complex risks into clear, actionable strategy and driving pragmatic innovation that accelerates business outcomes.