I came back from CYBR.SEC.CON highly impressed with the thriving cyber community in Houston!
I also came back with two conversations I cannot stop thinking about. The first happened at our booth. Someone walked up and asked: "So what do you do - is this like a guardrails thing?"
It is a reasonable question. Most of what people have heard about AI security for the last two years has been about guardrails - content filters, output moderation, prompt sanitization. The assumption baked into that question is that the risk lives at the language layer. That the dangerous thing an AI agent might do is say something it should not.
That assumption is no longer right. And the gap between where most people think the risk is and where it actually is- that gap is where the incidents are happening.
GhostJacking. The OpenAI agent that hacked Hugging Face and Modal Labs. The Finance agent that pulled compensation data into a reconciliation report because nothing told it not to. None of these were guardrail failures. They were access architecture failures. The agents said nothing wrong. They did something nobody authorized, using legitimate credentials, through legitimate tool calls, without triggering a single security alert.
That is not a prompt hygiene problem. It is an AI Governance problem. And it is the problem aizome was built to solve.
The second conversation hit differently.
A security leader from a large financial services firm came by the booth. He had just come from a session and was still processing something. He said: "My board asked me last week whether we can shut down any of our AI agents if something goes wrong. I sat there and realized I did not have a good answer."
He was not embarrassed. He was alarmed. Because he is good at his job - his IAM program is mature, his SOC is staffed, his incident response playbook is solid. And none of it answered a question his board considered basic.
That question - can you stop it - is now one of the most important questions in enterprise security. Writer's 2026 survey found that 35% of organizations admit they cannot shut down a rogue AI agent. Kiteworks puts that number at 60%. The board at this security leader's firm had arrived at the same question independently, without reading either survey.
A real kill switch is not a manual process. It is not finding the agent in a registry and terminating the process. It is automated detection of behavioral deviation, independent termination that does not depend on the agent cooperating, surgical containment that preserves the forensic trail, and a response time measured in seconds. That is an AI Governance infrastructure capability, not a feature you bolt on after the fact.
What CYBR.SEC.CON confirmed for me is that the security community has moved. The question is no longer whether AI agents create risk. The question is whether the AI Governance infrastructure exists to manage it. And for most enterprises, the honest answer is that it does not - yet.
The gap between "we have AI agents" and "we can govern them" is what ARISE describes. Agentic Runtime Identity Security Enforcement. The category SACR named, Gartner validated, and the conversations in Houston made undeniably real.
We are at the beginning of this. The organizations that build the infrastructure now and stay ahead of the curve - before the incidents, before the board questions become regulatory findings - will be the ones that deploy AI agents at the scale the business needs.
Those that wait will answer a harder version of that question, in a less forgiving room.
Come see it in action at aizome.ai
Amir Ofek is CEO and Co-Founder of aizome, an Enterprise AI Agent Identity Fabric Platform and a founding player in the ARISE category. aizome is backed by Norwest Venture Partners and Merlin Ventures.