Controlling Agentic AI and Supporting AI Governance - EMEA

An executive playbook to understanding how your AI agents operate

Thursday, October 01, 2026  |   11:00am BST

 

What will I learn?
  • AI agents as a new class of privileged identity and why access must be enforced continuously instead of granted once and left standing.
  • Why "blast radius" is really an accountability term: how far an agent's consequences travel past anyone who agreed to accept them. 
  • Why most AI governance programs stop at policy documents and never reach runtime enforcement. 
  • Why authorizing access at login was never enough and why AI agents have made the gap between authentication and execution impossible to ignore.
  • How to distinguish agent-driven connections from human-driven connections and why treating every connection as a human session breaks accountability. 

Every AI agent in your environment is built to achieve a goal, making them remarkably fast and effective, no matter what it takes, and that is a benefit. But the risk doesn't wait for something to go wrong; it goes live the moment the agent does. 


That might be manageable if adoption were slowing down. It is not. CEOs and boards are prioritizing AI adoption across the organization; some leaders are measured on how quickly it lands and CISOs bear accountability if something goes wrong. So, the question from the top has changed. It is no longer "Is it safe?" but "Can you prove what it did?"  

Most companies can provide a policy granting an agent access. Almost none can produce a record of how that access was used. 

Join Myrna Soto and Frank Vukovits for a candid, executive-level discussion on why AI agents belong under the same discipline as every other privileged identity 

You will hear what your board and auditors will ask for, and how to show them that AI is moving fast because it's under control, not in spite of it.

Get answers to these important questions:  

  • Is there a practical framework for governing AI agents alongside human and machine identities without slowing adoption? 

  • How do I scope agent access to the task rather than the person who deployed it, granted just-in-time  and revoked when the task completes?  

  • How do I evaluate each agent action against policy before it executes: allow it, block it, or bring in a human? 

  • How can I attribute every agent action to a named human identity so teams can investigate, respond and stand behind every access decision? 

Who should attend this webinar?

  • CISOs, CTOs, CIOs, Chief AI Officers (CAIOs) and Executive Leadership 

  • IT and Security Leadership

  • VPs of Engineering

  • Developer Compliance Officers

  • Innovation Teams  

Featured Speakers

Myrna Soto
Myrna Soto
Myrna Soto serves as Chief Trust Officer (CTO) at HITRUST and is the Founder and CEO of Apogee Executive Advisors. She brings extensive executive leadership experience, having previously served as CISO of Comcast and MGM Resorts International. Through her boutique advisory and consulting firm, she specializes in executive advisory services spanning corporate governance, technology risk management, cybersecurity, mergers and acquisitions, corporate development, public and private board service and capital investments.
cropped_frank_circle
Frank Vukovits

Frank is Chief Security Scientist at Delinea. He has over three decades of experience as an auditor and security professional, along with corporate IT executive management. Frank holds Certified Internal Auditor (CIA) and Certified Information System Auditor (CISA) designations. He is a frequent speaker at audit (IIA), IT audit (ISACA), software publishers, security, and user group events. Frank's recent work focuses on AI governance and securing AI agents as a new class of privileged identity, including runtime authorization of agent actions and the audit-ready accountability enterprises need as AI adoption accelerates. He writes and speaks frequently on these topics, including at Identiverse, Black Hat industry briefings, and for GRC organizations such as OCEG.