Enterprise AI Agents Demand New Governance Framework as Business Units Race Ahead
As autonomous agents move from experimental projects to critical business operations, enterprises face a widening governance gap that traditional IT controls cannot easily bridge.

Autonomous agents are transitioning from pilot initiatives to essential business systems, forcing enterprises to establish governance protocols for a workforce that operates without the accountability mechanisms developed over decades for human staff. Organizations now oversee digital workers lacking employee identification, compensation structures, or ethical guardrails—and crucially, lacking auditable operational histories.
The absence of proper governance frameworks has become a pressing concern in private cloud environments, where agents access sensitive corporate information, interact with application programming interfaces, and execute tasks independently. Business divisions are moving faster than IT departments can establish safeguards, according to Clayton Donley, vice president and general manager of the Identity Management Security Division at Broadcom Inc.
We talk to companies every day that are doing mission-critical things very quickly with [AI]. It's not happening in an environment where we have 50 years of figuring out how to deal with employees and giving them their rights. It's happening in a brand new world.
Clayton Donley, Broadcom Inc.
Donley shared these insights during an exclusive interview at VMware Explore 2026, where he and theCUBE's John Furrier examined how organizations can implement identity management, governance structures, and controls for deploying autonomous systems reliably at enterprise scale.
Agent identity becomes the control point for AI infrastructure
Initial concerns about agents focused on external threats—attackers deploying them against organizations. The conversation has shifted toward an equally serious internal risk: agents operating within companies but outside established verification and audit frameworks. Regulated sectors face particular pressure to address this vulnerability, Donley noted.
With Sarbanes-Oxley, back in the day, you used to have to certify that your employees had [appropriate] access. Nobody certifies [that] my agents have this access. Nobody does any of that. The maturity's not there, but what we're seeing is a trend to try to pick up that maturity.
Clayton Donley, Broadcom Inc.
Resolving this governance challenge requires treating agents as distinct identities within infrastructure systems. Broadcom has been modernizing VMware's security capabilities for agent-driven environments by applying established distributed application monitoring techniques to agent prompts and tool interactions, creating visibility into agent actions and decision-making processes. Three core elements underpin this approach: identity, intervention, and inspection.
[You need] the identity of the agent, the control point to choke off bad things from happening and then being able to monitor what is actually happening. Being able to tie it together is really critical.
Clayton Donley, Broadcom Inc.
Organizations can implement these controls within their existing AI systems without requiring complete infrastructure overhauls, Donley explained. The implementation strategy begins with observation: monitor system traffic, recognize which agents are present, then establish a centralized enforcement mechanism for organizational policies.
https://www.youtube.com/embed/NfAXsFZhFYU?feature=oembed
Sometimes the starting thing we do is we just watch the traffic, because it's very easy, it's very cheap, it doesn't require you to change anything. You take away their Claude key, you take away their OpenAI key, and you give them a key to yours. Now you can make sure they can't circumvent you by using their keys through some other app.
Clayton Donley, Broadcom Inc.


