Tech Talks Daily podcast

Building Infrastructure That Can Govern AI Agents With Broadcom

0:00
25:57
15 Sekunden vorwärts
15 Sekunden vorwärts

What happens when an organization writes careful AI governance policies but its infrastructure cannot enforce any of them?

In this episode of Tech Talks Daily, I speak with Sabina Anja, Chief Technologist at Broadcom within the VMware Cloud Foundation division, about the infrastructure controls required as AI agents move from generating answers to accessing data, calling APIs, modifying systems, and triggering work.

Sabina brings experience from both sides of enterprise technology. She remembers cabling networks, dealing with unstable infrastructure, and receiving those weekend calls when downtime had already upset the business. That background informs her belief that ambitious AI programs cannot succeed without stable, observable, and enforceable infrastructure beneath them.

Many organizations are repeating a familiar pattern. Business teams adopt AI services before IT has established visibility, ownership, or control. The terminology may have changed from shadow IT to shadow AI, but the management problem remains. Sabina argues that CIOs first need an inventory of agents, nonhuman identities, data access, processes, and accountable owners.

The risk becomes greater because agents behave differently from people. They operate across multiple systems at machine speed and can perform repeated actions without appreciating the wider business outcome. An agent does not need malicious intent to cause disruption. Excessive permissions, flat networks, inconsistent access rules, and years of deferred infrastructure work can give it plenty of opportunities.

Sabina recommends brokered access rather than direct access, alongside dedicated virtual machines or namespaces, microsegmentation, lateral security, east-west policy controls, and tamper-evident logging. Organizations also need to define which data an agent can view, modify, or move, especially when sovereignty and regulatory requirements apply.

One of Sabina's most memorable ideas is to treat an AI agent like a superhuman contractor. It should have a defined purpose, a named manager, a clear access specification, an activity record, and an end date. Additional permissions should be earned through evidence of reliable behavior rather than granted on the first day.

She also warns about agent debt. AI systems are developing rapidly, so an agent created today may become outdated within months. Sabina recommends assuming that many agents will expire after six to nine months rather than allowing forgotten systems and permissions to accumulate indefinitely.

For CIOs wanting an immediate test, her advice is straightforward. Create an inventory of nonhuman identities with production access. Then select one agent and examine every part of the infrastructure it attempted to reach. The question is not simply whether the application produced the expected result. Leaders should ask whether the agent entered systems, networks, or data stores that nobody expected it to access.

We also challenge the familiar claim that AI agents will take everybody's jobs. Sabina sees an opportunity to remove repetitive tasks and give technology professionals new skills, although she warns that agents may behave like teenagers armed with infrastructure permissions. They may not take your job, but they could become remarkably good at testing your patience.

I'd love to hear your thoughts. Does your organization know how many AI agents have production access and who is accountable for each one?

 

Weitere Episoden von „Tech Talks Daily“