HomeSecurity, Governance, & Risk

Sequencing Is The Fix To Security's Agentic AI Complexity Problem

September 17, 2026

Jigar Shah, Chief Information Security Officer at healthcare firm Medusind, on why security teams manufacture their own agentic AI complexity, and how sequencing the problem, the data, and the identity keeps it from happening.

Sequencing Is The Fix To Security's Agentic AI Complexity Problem
Credit: CIOnews

Get the latest from CIOnews.

Enterprise AI, governance, risk, and leadership insights for CIOs, CTOs, CISOs, and technology leaders.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
While solving a little problem, you can create so much complexity around you. After solving that small problem, you created ten new problems that you now need to solve.

Jigar Shah

CISO
@
Medusind

Much of what slows an agentic AI project down tends to be self-inflicted. A security group takes on a narrow fix, goes deep on the technology, and loses sight of the business outcome it was chasing. Weeks later it resurfaces with shadow AI, redundant tools, and technical debt that costs more to unwind than the original problem ever did. The way out has less to do with better tooling than with the order of operations, settling what the problem actually is, and what data and identity foundations it rests on, before anyone deploys a thing.

Jigar Shah is Chief Information Security Officer at Medusind, a healthcare revenue-cycle company, where he leads enterprise security and stood up its governance, risk, and compliance function. He spent two decades in security and technology leadership across regulated industries, including a global cybersecurity and identity role at Tenet Healthcare, where he ran security functions covering 200,000 employees, and years at R1 RCM. He's also an engineer with an MBA and a law degree, a combination he uses to translate technical risk for the finance, legal, and HR leaders who have to act on it.

"While solving a little problem, you can create so much complexity around you," Shah said. "After solving that small problem, you created ten new problems that you now need to solve." He describes it as analysis paralysis, the tendency of technical teams to get so absorbed in a fix that they miss the forest for the trees and leave behind shadow AI and shadow tech nobody chose on purpose. The discipline he prescribes is a sequence, and it starts well before any tool gets picked.

  • Solve the problem before the tool: Shah's first move is to resist the reflex to build. "Most of the time, people jump into the solution without really understanding what the problem looks like, and then you waste so much time and resources," he said. His rule is lopsided on purpose: spend roughly 80% of the effort understanding the business problem and mapping it to a concrete outcome, and the remaining work gets easier. "Sometimes the complex problems have the simplest solutions." That framing pushes a team toward building the foundation first rather than reaching for the most sophisticated system available, which is usually where the self-inflicted complexity begins.

  • Settle data and identity before you deploy: The fundamentals, in his telling, are data and identity, and both have to be solid before an agent goes anywhere near production. Data needs to be organized, classified, and accurate; identity needs to answer who an agent is, what it can access, and whether that access is appropriate. He handles the second by treating agents the way a company treats a new hire. "Consider these digital identities, or agents, as an intern to your company," Shah said. "You don't give them all the access on day one. You monitor them, give them a chance, see how they're doing, and slowly add permissions." That is the discipline behind least-privilege agent access, and it leads him to a crisp operating principle for governing agent delegation: "Don't trust the agent. Control the agent's ability to act."

Foundations only hold if someone owns what happens on top of them, and this is where Shah gets most pointed about the difference between having a strategy and having a way to run it. A great deal of agentic AI work stalls not because the technology fails but because no one settled, in advance, who answers for a bad outcome. Governance, in his framing, is less about slowing anything down than about making that ownership explicit before the stakes get real. Without it, a team is automating decisions it can't account for.

  • Put accountability in place before you build: Before any implementation, Shah wants a cross-functional forum, a governance or AI council pulling in legal, HR, finance, operations, technology, and business, so the risk is shared rather than dumped on IT. He tests whether that accountability is real with a deliberately uncomfortable question. "If an AI agent makes a $50 million fraud tomorrow, who in your company would you hold accountable? If you don't have that answer, don't go with the transformation." The point is not to assign blame but to force the accountability structures into existence early, because, as he put it, cybersecurity and AI are not just a technology issue but a real business problem and opportunity.

  • Take one workflow, not the whole company: Shah's last rule is to resist scale. Rather than transforming everything at once, he picks one or two high-value use cases and maps the entire value stream before automating any of it. "Do not boil the ocean," he said. "Pick one or two use cases that are really high value, and understand the whole end-to-end value stream." He uses invoice approval as the example: a workflow that looks trivial hides queues, miscoded entries, and stalled approvals, exactly what a demo skips, and untangling those details is where the return actually lives. "Such a simple workflow, but it can create millions of dollars in benefit if you multiply it through scale," he said.

Run in that order, and Shah's argument is that security stops being the office that says no and becomes the reason the business can move fast. He reaches for a racing analogy to make the point. "Imagine if a Formula One car had no brakes. Would you sit in it?" he said. "They go very fast, but they have brakes, so when something goes wrong, they can use them." Guardrails, in that framing, are what let an organization accelerate safely rather than what holds it back, the same logic behind securing rather than blocking that a growing number of security leaders are adopting.

The people underneath all of it are the part he most wants understood, and he pushes back hard on the fear that AI is coming for everyone's job. The threat, as he frames it, isn't the technology but the colleague who learns to use it well. "You are not going to lose your job over AI. You're going to lose it to another person who knows AI better than you." His advice to anyone anxious about it is the same discipline he applies to the technology: stop treating it as a threat to react to, and start understanding it.

research report

From the Edge to the Core:
Bringing Agentic AI to the Heart of the Enterprise.