Vanderbilt Extends Identity Governance to AI Agents While Weighing Liability Risks
CIO Shane Callahan argues existing technology-intake frameworks can manage autonomous software, even as legal accountability remains unresolved.

Higher education IT environments face distinct access-control challenges, and the introduction of autonomous artificial intelligence agents is compounding that complexity. Speaking at Okta's Oktane event in an interview with SiliconANGLE Media's livestreaming studio, theCUBE, Vanderbilt University Chief Information Officer Shane Callahan outlined how institutions must navigate identity management and accountability as AI tools integrate into operations.
Vanderbilt manages access through OneVU, a single sign-on platform powered by Okta. The university's operational surface spans residential life, athletics, an internal police department, and an annual research portfolio exceeding $1 billion. Managing access permissions across that footprint requires tracking individuals who regularly occupy multiple institutional roles simultaneously.
“When it comes to [a] university, you could have multiple identities and sometimes at the same time,” Callahan told theCUBE hosts Krista Case and Rebecca Knight. “For me, I’m a student, I’m a staff member, [I] could be a donor — all these different things — and they all have different profiles of how you work at a university. Keeping track of that security profile is very, very difficult.”
The rollout of autonomous agents adds an additional tier to identity security. While IT administrators can assign distinct identities and scoped access parameters to restrict an agent's operational envelope, technical safeguards do not resolve legal and organizational liability when an automated system exceeds defined boundaries.
“If you have an agent that does something and it goes outside of your guardrails, are you accountable for that or is the tool accountable for that?” Callahan said. “What happens if that tool gets out of guardrails and impacts another group or another company? Does cyber insurance help us with that? We don’t understand where liability or responsibility falls at this point.”
Despite unresolved legal and insurance questions, Callahan cautioned enterprise leaders against abandoning established intake and oversight mechanisms. He maintained that existing cross-functional governance structures can be applied directly to autonomous systems.
“We’re treating AI like it’s a brand-new thing. But really, you’re still talking about identity data in another technology tool,” Callahan said. “You don’t have to recreate everything. If you have a governance process and a technology intake program, do that, use that.”
As reported by SiliconANGLE (https://siliconangle.com/2026/09/25/vanderbilt-university-extends-identity-governance-ai-agents-oktane/), the deployment underscores a growing enterprise consensus: managing AI risk requires applying rigorous identity lifecycles and established governance workflows rather than treating autonomous agents as outside standard enterprise controls.
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.


