HomeSecurity, Governance, & Risk

A Credential Gets An AI Agent Through The Door. Security Still Has To Govern What It Does Next.

October 6, 2026

Subba Raju Vathsavai, Chief Information Security Officer at iBASIS, on why AI agents now act as non-human identities inside the network, and why trust in them has to be shown in production, not certified on paper.

A Credential Gets An AI Agent Through The Door. Security Still Has To Govern What It Does Next.
Credit: CIOnews

Get the latest from CIOnews.

Enterprise AI, governance, risk, and leadership insights for CIOs, CTOs, CISOs, and technology leaders.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
"Authentication tells me who you are. It doesn't tell me whether what you're about to do is appropriate."

Subba Raju Vathsavai

CISO
iBASIS

An AI agent with valid credentials and the right permissions can still take an action no one sanctioned. What an agent is permitted to do, and what it actually does next, have become two separate things to watch. The approach taking shape inside security teams treats each agent as an identity with an owner, a declared intent, and a set of actions that can be watched and pulled back the moment they drift. In a connected network, where one component's mistake travels through every dependency it touches, that kind of provable control is becoming the condition for putting agents into production at all.

Subba Raju Vathsavai is the Chief Information Security Officer at iBASIS, the international communications carrier that moves voice, messaging, and connectivity between operators worldwide. Before iBASIS, he led security as CISO and Data Protection Officer across APAC and India at NTT DATA Business Solutions, and earlier spent 16 years running mission-critical IT systems for the Indian Air Force. That span, from military operations where continuity isn't optional to global carrier networks, shapes how he reads the arrival of autonomous agents: as identities that have to earn trust the way people do.

"Authentication tells me who you are. It doesn't tell me whether what you're about to do is appropriate," Vathsavai said. That second question is the one agentic systems force into the open. A credential confirms identity at the door, but an agent keeps acting long after it's been let in, chaining decisions that each look legitimate on their own. Governing that behavior, rather than just the login, is the work he says security leaders have to show they can do before the business trusts an agent with anything that matters.

  • An ID and an owner: "When we prepare an agent, we assign it accountability the way you'd give an ID to a person," Vathsavai said. "You give that agent an ID, you understand its intent, what it's expected to perform, and who answers for it." Treating an agent as a named identity rather than a feature changes what's possible later. An owner gives every action a person to trace it back to, and a declared intent gives monitoring something to measure each action against, so the question becomes whether what the agent actually did still matches what it was built for.

  • Proof over paperwork: "Having a policy doesn't mean we have AI governance. AI governance can't stop at the policy document. It has to pass into the runtime environment. That's where it has a real impact," said Vathsavai. What has to travel into production is the part an audit rarely captures: visibility into what data the agent reaches, controls built into the architecture rather than a binder, and outcomes precise enough to measure. An ISO certificate predates all of it.

  • The network raises the bar: iBASIS sits in the middle of a web of operators, messaging platforms, IPX routes, and partner APIs, which means an agent's bad decision rarely stops where it started. "A cyber incident doesn't stay inside one system," Vathsavai said. "You've got the networks, the messaging platforms, the IPX solutions, the APIs, the partners, the whole supply chain. It propagates through the dependencies." The way he frames resilience has moved with the threat. "The focus has shifted from hardware to software, from software to the database, from the database to the data. Now it's shifting to the agents. All of a sudden your agent doesn't function, and the question is how fast you can bring it back before the customer feels it." Resilience, in that reading, now includes how fast you can cut a misbehaving agent off, not only how fast a server comes back.

Raising the stakes is one thing. Operating inside them every day, with agents making calls faster than anyone can watch, is another. Teams that are further along have stopped trying to supervise every action, and instead decide in advance where human judgment is mandatory and where it isn't. That calibration, and the structure that enforces it, is where the real work of governing agents happens.

  • A tolerance for failure: Not every agent decision deserves the same scrutiny, and treating them as if they do is how governance stalls. "Is it low risk, medium risk, or high risk? For low risk, within limits, it's permissible, depending on the organization's risk tolerance. For medium risk, you need a human in the loop to verify and validate. For high risk, anything regulatory, someone has to go through what the AI produced and check it fact by fact." The checkpoint that earns its keep is the one on a confident answer no one examined, the kind that reads as authoritative and ships straight into a decision. Guardrails that catch it before it lands are what let a leader widen the agent's autonomy everywhere else.

  • Agents to watch agents: "With two agents or five agents, you can keep a human in the loop. With thousands, you can't," Vathsavai said. "So you create an agent to govern your agents. For every five agents, you build one as a governing body, a team leader that watches what they do and reports back the moment it sees an anomaly." The structure mirrors the one every company already runs, supervisors over workers, managers over supervisors, with accountability climbing the same way. "An agent organization chart is going to arrive soon, maybe in the next year or two. But wherever there's a regulatory requirement, that decision still has to be reviewed by a human, whichever agent made it." What changes is the speed it all runs at, and the fact that the humans move up the chart, concentrating where the law or the risk demands a person's signature.

  • Proving it upward: None of this earns budget until it's spoken in the board's language. "When you can convert risk language into business language, 50% of your work is done. Instead of saying 'I want you to buy an antivirus solution,' you tell the board the systems are exposed to the internet, that could mean a penetration attack and a $100,000 penalty, and $20,000 of spend protects against it." The sharper move turns the register itself into a growth plan, ordered by what would actually cost the business most, so the spend that cuts the biggest exposure rises to the top. "I convert risk into opportunity. Every risk carries its own opportunity to grow the business and contribute to revenue."

Asked what leaders should be auditing over the next 18 months, Vathsavai pointed where most agentic-AI roadmaps don't: at the cryptography underneath all of it. "People are forgetting quantum-readiness cryptography. It's coming in the next year or 18 months, and this isn't an easy process," he said. "Everyone has an asset inventory. Ask any organization whether they have a cryptographic inventory, a record of where their crypto is actually used. You need to start building that now."

The timing isn't hypothetical. Federal rules already put a clock on it: new national-security systems have to be quantum-resistant from 2027, and vulnerable public-key encryption is set for deprecation by 2030 and off-limits after 2035. It's the same discipline the rest of his argument runs on: trust you can show on demand, built before anyone asks to see it.

research report

From the Edge to the Core:
Bringing Agentic AI to the Heart of the Enterprise.