Skip to content
Breaking:

Enterprises Face Governance Gap as Autonomous AI Agents Move to Core Workflows

Broadcom's Clayton Donley outlines infrastructure-level strategies for managing agent identity, intervention, and inspection at VMware Explore 2026.

By The Company Wire4 min read
Share
Broadcom — Enterprises Face Governance Gap as Autonomous AI Agents Move to Core Workflows
Broadcom — Enterprises Face Governance Gap as Autonomous AI Agents Move to Core Workflows. Photo: SiliconANGLE.

As autonomous software agents transition from isolated experimental projects to mission-critical operations, enterprise information technology teams are confronting a fundamental gap in corporate governance. Organizations that spent decades building regulatory frameworks and identity controls for human workers are now granting digital agents direct access to sensitive databases, enterprise application programming interfaces, and operational systems without oversight mechanisms or established auditing standards.

The challenge of managing these autonomous digital entities has become a central focus across the private cloud sector, where business units are deploying agentic software at a faster pace than central security departments can institute compliance protocols. Speaking in an interview with theCUBE at the VMware Explore 2026 conference, first reported by SiliconANGLE, Clayton Donley, vice president and general manager of the Identity Management Security Division at Broadcom Inc., highlighted the urgency of building governance directly into core cloud infrastructure.

According to Donley, enterprise business units are rapidly integrating artificial intelligence systems into production environments without waiting for legacy governance structures to adapt. He noted that while corporations have spent half a century refining protocols for onboarding, managing, and revoking rights for human personnel, autonomous agents represent an entirely unfamiliar operating environment that lacks standardized identity verification or access history.

While early cybersecurity discussions regarding autonomous agents focused on external threats using artificial intelligence tools against corporate targets, attention has increasingly shifted toward internal compliance vulnerabilities. Regulated sectors face mounting risks from internal agents executing transactions or accessing data without auditable paper trails. Donley drew a comparison to historical regulatory compliance standards such as the Sarbanes-Oxley Act, pointing out that while organizations must formally certify employee system permissions, equivalent compliance requirements for autonomous digital agents do not yet exist in the market.

To address these regulatory and security exposures, infrastructure providers are attempting to establish formal agent identity controls. Broadcom has been updating security tools across its VMware portfolio for agentic workloads by repurposing distributed application tracing techniques previously designed for traditional cloud applications. By adapting these tracing methods, system administrators can gain visibility into the exact series of prompts, inputs, and API tool calls executed by an agent during any given workflow.

Donley outlined a three-part framework necessary for establishing scalable agent management in enterprise settings: identity, intervention, and inspection. Under this model, security platforms must first verify the distinct identity of every deployed agent, maintain centralized enforcement points capable of blocking unauthorized or dangerous actions in real time, and continuously monitor operational activities across the corporate network to reconstruct decision paths.

Rather than requiring enterprises to dismantle and rebuild existing cloud architecture, Donley emphasized that security teams can implement agent controls incrementally. The initial phase typically involves passive monitoring of network traffic to identify active agents and map their data connections. Organizations can then consolidate control by revoking direct enterprise keys for external models—such as credentials for OpenAI LLC or Anthropic PBC's Claude—and routing all agent interactions through internal management gateways where corporate policies can be consistently enforced.

Sources

  1. SiliconANGLE

Company: Broadcom

Written by

The Company Wire

Newsroom · San Francisco

Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.