Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Agentic AI systems: are your observability controls ready yet?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19382
Topic starter  

TL;DR: Agentic AI breaks the deterministic testing assumptions enterprise teams used for traditional software, and Fiddler argues that observability, auditability, hybrid architectures and ROI-first use case selection are now the practical foundation for safe deployment. The real governance shift is that agent behaviour must be treated as a managed system property, not a post-launch surprise.

NHIMG editorial — based on content published by Fiddler: Beyond Predictability: Lessons Learned from Building Agentic Systems

By the numbers:

Questions worth separating out

Q: How should security teams govern AI models that can call tools and access data?

A: Security teams should govern AI models as non-human identities with named owners, limited scope, short-lived credentials, and continuous authorization.

Q: Why do agentic AI systems complicate access control and auditability?

A: They complicate access control because behaviour is probabilistic, not fixed, so the same inputs can lead to different actions.

Q: What breaks when observability is used instead of access control for AI agents?

A: What breaks is the security boundary itself.

Practitioner guidance

What's in the full article

Fiddler's full blog covers the operational detail this post intentionally leaves for the source:

  • Examples of how the team structures agent observability across tool calls, token usage and workflow traces
  • Discussion of ROI-led prioritisation for agentic use cases, including which workloads to pilot first
  • Practical guidance on hybrid architectures that combine LLMs with predictive and causal validation
  • The article's framing on how collaboration between business and technical stakeholders changes adoption decisions

👉 Read Fiddler's analysis of lessons learned from building agentic systems →

Agentic AI systems: are your observability controls ready yet?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 18973
 

Non-determinism is now a governance problem, not just a model property. Once an agent can vary its behaviour at runtime, traditional assurance based on fixed outputs becomes incomplete. The control question changes from whether the model works in testing to whether the system can prove what it did in production. Practitioners should treat variability as a governed risk boundary, not a tuning nuisance.

A few things that frame the scale:

  • Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation, according to AI Agents: The New Attack Surface report.
  • Another finding from our research: 80% of organisations report their AI agents have already performed actions beyond their intended scope, according to AI Agents: The New Attack Surface report.

A question worth separating out:

Q: Should organisations prioritise hybrid AI architectures over pure LLM workflows?

A: Yes, where correctness, governance or sensitive data handling matter. Hybrid architectures add validation layers such as rules, knowledge graphs or predictive checks that can constrain unsafe model output before it becomes action. That does not remove risk, but it makes the system easier to govern and less dependent on one model's judgement.

👉 Read our full editorial: Agentic AI systems need observability, auditability and ROI discipline



   
ReplyQuote
Share: