Rogue agents are forcing a governance reckoning as enterprises hand over the keys
Governance is moving into the foundations of enterprise AI infrastructure as autonomous agents graduate from experiments to mission-critical work. Companies that spent decades refining controls for human employees now manage a second workforce that has no badge number, no paycheck and no moral compass — and no track record to audit.
That governance gap is dominating security conversations across the private cloud market, where agents are being handed corporate data, application programming interfaces and the ability to act without supervision. But business units are not waiting for information technology teams to catch up, according to Clayton Donley (pictured), vice president and general manager of the Identity Management Security Division at Broadcom Inc.
“We talk to companies every day that are doing mission-critical things very quickly with [AI],” Donley said. “It’s not happening in an environment where we have 50 years of figuring out how to deal with employees and giving them their rights. It’s happening in a brand new world.”
Donley spoke with theCUBE’s John Furrier at VMware Explore 2026, during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. They discussed agent identity, governance and the controls needed to run autonomous systems safely at scale. (* Disclosure below.)
Agent identity becomes the control point for AI infrastructure
Early anxiety around agents centered on attackers wielding them against the enterprise. Attention has since turned to the opposite risk — an organization’s own agents operating outside any certification or audit regime, a gap that regulated industries cannot carry for long, Donley explained.
“With Sarbanes-Oxley, back in the day, you used to have to certify that your employees had [appropriate] access. Nobody certifies [that] my agents have this access. Nobody does any of that,” he said. “The maturity’s not there, but what we’re seeing is a trend to try to pick up that maturity.”
Closing that gap means treating agents as identities first. Broadcom, which has been reworking VMware security for the agentic era, is applying decades of distributed application tracing to prompts and tool calls, extending observability into what an agent actually did and why, Donley noted. Three principles are fundamental: identity, intervention and inspection.
“[You need] the identity of the agent, the control point to choke off bad things from happening and then being able to monitor what is actually happening,” Donley said. “Being able to tie it together is really critical.”
Enterprises can layer that control onto existing AI infrastructure rather than rebuilding it, he added. The starting point is passive: Watch the traffic, identify the agents and then introduce a central control point where policy can be enforced.
“Sometimes the starting thing we do is we just watch the traffic, because it’s very easy, it’s very cheap, it doesn’t require you to change anything,” Donley said. “You take away their Claude key, you take away their OpenAI key, and you give them a key to yours. Now you can make sure they can’t circumvent you by using their keys through some other app.”
Here’s the complete video interview, part of SiliconANGLE’s and theCUBE’s coverage of VMware Explore 2026:
(* Disclosure: TheCUBE is a paid media partner for the VMware Explore 2026 event. Neither Broadcom, the sponsor of theCUBE’s event coverage, nor other sponsors have editorial control over content on theCUBE or SiliconANGLE.)
Photo: SiliconANGLE
A message from John Furrier, co-founder of SiliconANGLE:
Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.
- 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
- 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network
Are you an AWS customer? Support SiliconANGLE financially by buying your AWS services from our Marketplace portal page and links: https://siliconangle.com/aws-marketplace/
About SiliconANGLE Media
Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.