TL;DR: A practical shift in AI security is at the center of C1.ai’s Transform 2026 agenda, which focuses on governing agents after the credential perimeter, testing whether Kubernetes is the right runtime for sandboxes, and deciding where AI agents actually create value in security operations, according to C1.ai. The conference points to a wider governance problem, because agent behaviour, privilege, and execution context now matter as much as model quality.
NHIMG editorial — here’s why we think this discussion matters
Questions worth separating out
Q: How should organisations govern external tools used by AI agents?
A: Organisations should review external tools as security inputs, not convenience features.
Q: Why do AI agents create more risk than traditional automation?
A: AI agents create more risk because they can interpret context, choose actions, and invoke tools autonomously.
Practitioner guidance
- Define agent identities explicitly Classify each agent, workflow bot, or AI assistant as a governed non-human identity with named ownership, scoped permissions, and review cadence.
- Separate sandboxes from production authority Use isolated runtimes for experimentation and limit what production agents can reach through network policy, secret boundaries, and tightly scoped service credentials.
- Tie agent actions to audit evidence Log the agent decision, the tool call, the credential used, and the resulting side effect so reviewers can reconstruct the chain of action.
What to expect at the briefing
C1.ai's full article covers the conference agenda and speaker lineup this post intentionally leaves at a higher level:
- The full agenda and session sequencing across AI strategy, security, governance, and infrastructure topics.
- Named speakers and the specific themes each session is intended to cover at Transform 2026.
- On-site event details, including venue context and the live conference experience for attendees.
👉 Read C1.ai's Transform 2026 agenda for AI agent governance and security →
AI agent governance and runtime control: what practitioners are missing?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Agent governance is now an identity problem disguised as an AI problem. Once agents can select tools, persist state, and act across systems, the meaningful question becomes who or what is authorised to do the work. That moves the control conversation into IAM, PAM, and NHI lifecycle management, not just model policy. Practitioners should treat agent identities as governed access subjects, not as incidental implementation detail.
A few things that frame the scale:
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to the Ultimate Guide to NHIs.
- 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation.
A question worth separating out:
Q: How do organisations decide whether AI governance is strong enough for autonomous agents?
A: Organisations should ask whether their controls can observe API calls, tool use, and policy decisions outside the browser. If an agent can act without passing through the organisation’s visible control points, the governance model is incomplete. Autonomous workflows need explicit visibility into machine-to-machine execution paths.
👉 Read our full editorial: AI agent governance and runtime control are the real conference agenda