Slide 1 of 4

AI is already in the building.

Name the tools.

The approved tenant is only part of it. Engineers paste code into a consumer chatbot. Someone points a server at an internal database. You cannot secure a tool you have not named.

Why this is interesting now

Agents can already act.
The controls around them are still catching up.

Agentic systems can chat, browse, execute code, and act on someone's behalf. That is useful when permissions, data paths, and human checkpoints are in place, and a mess when they are not. Most of what gets written here is about that gap.