TL;DR: As generative AI and agentic architectures push into API and data-path design, Kong’s workshop frames the operational question as how to govern models, agents, and flows at scale without sacrificing performance or security. The strategic issue is that connectivity now carries identity and authorisation risk, not just traffic management.
Editorial analysis by NHI Mgmt Group, based on content published by Kong: “# Strategy & Connectivity in the Age of AI - An evening among peers, in Italy”.
Key questions
A: Organisations should unify governance across data, AI, and operational workflows instead of managing each use case in a separate silo.
Q: Why do agentic AI systems increase risk for API security and governance?
A: Agentic AI increases risk because it can interpret context, make decisions, and execute multi-step actions without waiting for direct human approval.
Practitioner guidance
- Map AI data-path ownership Document which teams own the routes, APIs, and policies that move data between agents, models, and downstream systems.
- Inventory agent-facing APIs Create a separate inventory for APIs used by AI agents, including deprecated endpoints, hidden service calls, and tool-specific routes.
- Define runtime policy for MCP tools Set explicit approval, logging, and scope rules for every tool exposed through MCP-connected workflows.
Bottom line: AI data paths are becoming governance boundaries because agents and APIs now carry authorisation risk as well as traffic.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
AI connectivity is becoming an identity problem, not just an architecture problem. The workshop topic reflects a broader shift: once agents and models participate in live data flows, the main risk is no longer only latency or throughput, but who can act through those flows. That is why API design, access control, and NHI governance now need to be treated as one operational plane. Practitioners should plan for identity enforcement at the point of interaction, not after the fact.
A few things that frame the scale:
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%), according to AI Agents: The New Attack Surface report.
- Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.
A question worth separating out:
Q: What should organisations check before scaling agentic AI in production?
A: Organisations should check whether their current controls can enforce least privilege across models, agents, APIs, and data flows at runtime. If ownership, logging, and revocation are unclear, scaling will expand the blast radius of every mistake. The key question is whether the control model still matches the access path.
👉 Read our full editorial: AI data path governance for agents and APIs in 2026
AI connectivity is becoming an identity problem, not just an architecture problem. The workshop topic reflects a broader shift: once agents and models participate in live data flows, the main risk is no longer only latency or throughput, but who can act through those flows. That is why API design, access control, and NHI governance now need to be treated as one operational plane. Practitioners should plan for identity enforcement at the point of interaction, not after the fact.
A few things that frame the scale:
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%), according to AI Agents: The New Attack Surface report.
- Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.
A question worth separating out:
Q: What should organisations check before scaling agentic AI in production?
A: Organisations should check whether their current controls can enforce least privilege across models, agents, APIs, and data flows at runtime. If ownership, logging, and revocation are unclear, scaling will expand the blast radius of every mistake. The key question is whether the control model still matches the access path.
👉 Read our full editorial: AI data path governance for agents and APIs in 2026
AI connectivity is now an identity governance problem, not just an architecture problem. Once models and agents sit on the data path, the organisation is no longer only designing for latency and resilience. It is also deciding who can invoke what, which contexts are trusted, and where authorisation is enforced. That makes data-path governance a control-plane issue for IAM and NHI teams, not a side effect of application design. Practitioners should therefore evaluate AI traffic with the same discipline they apply to privileged connectivity.
A question worth separating out:
Q: What should security teams prioritise when AI connectivity expands?
A: Security teams should prioritise ownership, inventory, and enforcement together. Without clear ownership, no one fixes drift. Without inventory, no one sees stale APIs or tool paths. Without runtime enforcement, inventory is only documentation. The effective programme is the one that connects all three at the point of access.
👉 Read our full editorial: AI data path governance for agents and APIs in 2026