Controlling Agentic AI and Supporting AI Governance

An executive guide to understanding how your AI agents operate

Thursday, September 24, 2026  |   1:00pm New York
What will I learn?
  • How to govern AI agents alongside human and machine identities without slowing adoption.
  • How to scope agent access to the task rather than the person who deployed it, granted just-in-time and revoked when the task completes. 
  • How boards are now evaluating AI risk and balancing adoption speed against defensibility and compliance. 
  • What to put on your next risk committee agenda, and the one-hour exercise that reveals your real agent maturity regardless of what your policy says.

Every AI agent in your environment is built to achieve a goal, making them remarkably fast and effective, no matter what it takes, and that is a benefit. But the risk doesn't wait for something to go wrong; it goes live the moment the agent does. 


That might be manageable if adoption were slowing down. It is not. CEOs and boards are prioritizing AI adoption across the organization; some leaders are measured on how quickly it lands and CISOs bear accountability if something goes wrong. So, the question from the top has changed. It is no longer "Is it safe?" but "Can you prove what it did?"  

Most companies can provide a policy granting an agent access. Almost none can produce a record of how that access was used. 

Join Myrna Soto and Frank Vukovits for a candid, executive-level discussion on why AI agents belong under the same discipline as every other privileged identity 

You will hear what your board and auditors will ask for, and how to show them that AI is moving fast because it's under control, not in spite of it.

Get answers to these important questions:  

  • Is there a practical framework for governing AI agents alongside human and machine identities without slowing adoption? 

  • How do I scope agent access to the task rather than the person who deployed it, granted just-in-time  and revoked when the task completes?  

  • How do I evaluate each agent action against policy before it executes: allow it, block it, or bring in a human? 

  • How can I attribute every agent action to a named human identity so teams can investigate, respond and stand behind every access decision? 

Who should attend this webinar?

  • CISOs, CTOs, CIOs, Chief AI Officers (CAIOs) and Executive Leadership 

  • IT and Security Leadership

  • VPs of Engineering/Developers

  • Compliance Officers

  • Innovation Teams  

Featured Speakers

Myrna Soto
Myrna Soto
Myrna Soto serves as Chief Trust Officer (CTO) at HITRUST and is the Founder and CEO of Apogee Executive Advisors. She brings extensive executive leadership experience, having previously served as CISO of Comcast and MGM Resorts International. Through her boutique advisory and consulting firm, she specializes in executive advisory services spanning corporate governance, technology risk management, cybersecurity, mergers and acquisitions, corporate development, public and private board service and capital investments.
cropped_frank_circle
Frank Vukovits

Frank is Chief Security Scientist at Delinea. He has over three decades of experience as an auditor and security professional, along with corporate IT executive management. Frank holds Certified Internal Auditor (CIA) and Certified Information System Auditor (CISA) designations. He is a frequent speaker at audit (IIA), IT audit (ISACA), software publishers, security, and user group events. Frank's recent work focuses on AI governance and securing AI agents as a new class of privileged identity, including runtime authorization of agent actions and the audit-ready accountability enterprises need as AI adoption accelerates. He writes and speaks frequently on these topics, including at Identiverse, Black Hat industry briefings, and for GRC organizations such as OCEG.