As autonomous AI agents evolve from passive prompt responders into multi-step execution partners, the threat landscape is undergoing a structural shift.

In its September 2026 State of the Internet security report, Speed, Scale, and Nonhuman Identity: The Agentic Threat Landscape, Akamai argues that enterprise security must expand beyond identity and access management to govern what autonomous, nonhuman entities do across APIs and workflows.

Static permissions and periodic reviews were designed around human roles and comparatively predictable software. They are not sufficient on their own when agents can chain actions across systems, modify code and make operational decisions during execution.

For software delivery, this points to two practical principles: match autonomy to verifiability and preserve the human intent behind agent activity.

1. Match autonomy to verifiability

One of Akamai’s strategic recommendations is to “match autonomy to verifiability”. In practice, an agent should receive more operational freedom when its actions are easy to verify and reverse. High-impact or difficult-to-reverse actions should retain human oversight.

                       High verifiability
                       High reversibility
                               │
                               ▼
                  High operational autonomy
          Drafting PRs · Local linting · Documentation
                               │
                               │  Rising impact or lower reversibility
                               ▼
                   Restricted agent autonomy
        Authentication · Database schema · Production deploy
                               │
                               ▼
                     Human-in-the-loop gate
  • Low-risk, highly reversible actions: Formatting code, running unit tests or drafting a focused pull request. Agents can operate with greater autonomy because teams can inspect the output and revert failures with limited impact.
  • High-risk, low-reversibility actions: Changing authentication logic, payment configuration, infrastructure policy or production data. These actions call for explicit boundaries, deterministic checks and human approval appropriate to the risk.

This model raises a deeper question: How can a reviewer verify an agent’s output without knowing the human decisions and instructions that shaped it?

2. The missing layer: human intent

If behavioral governance requires teams to evaluate agent actions, human intent provides an essential reference point.

When a developer works with a coding agent, the session creates a decision trail. Version control records the resulting code change, but usually not the request that initiated it, the context supplied to the model, the tools the agent invoked, or which suggestions the developer accepted or declined.

Without that context, security and governance teams must assess agent behavior with only part of the record.

+------------------------------------------------------------------+
|                     SECUARDEN CONTEXT BOM                         |
+------------------------------------------------------------------+
| Human intent      → Instruction, decision context and purpose     |
| Agent activity    → Model, tool and execution events captured     |
| Policy decisions  → Applicable gates, approvals and exceptions    |
| Code lineage      → Files, diff, commit and pull-request links     |
+------------------------------------------------------------------+

From blind approval to reviewable provenance

Secuarden’s Context BOM applies this idea to AI-assisted software development. For supported coding-agent workflows and configured integrations, it connects four parts of the change record:

  1. Capture intent at the source. Record the human instruction and relevant decision context alongside supported agent-session activity.
  2. Apply policy and approval controls. Evaluate contextual signals—such as sensitive paths touched—and retain the policy decisions or approvals associated with the change.
  3. Create a verifiable decision trail. Link the captured evidence from human intent → agent activity → policy outcome → code change so reviewers can inspect how the change was produced and governed.

The resulting record is designed to support review, investigation and audit evidence. It does not, by itself, certify that a change is secure or that an organisation is compliant.

Behavioral governance in action

Combining risk-based agent autonomy with change provenance produces an operational governance matrix:

Workstage risk Reversibility Governance approach Secuarden mechanism
Low — refactoring a local helper High — easily reverted Agent execution with passive session capture Record supported session lineage and intent in the Context BOM
Medium — modifying a public API endpoint Moderate — requires review and integration testing Agent proposal with contextual automated review Combine code analysis with CCR™ evidence and control signals before merge
High — changing authentication or payment routes Low or critical — significant outage or vulnerability risk Human-in-the-loop approval and deterministic policy checks Bind the approval and policy outcome to documented intent and the exact change

The precise evidence and controls available depend on the coding-agent integrations, repository configuration and deployment model in use.

Moving beyond static identity

Agentic AI can accelerate software delivery, but speed without verifiable context creates enterprise risk.

Behavioral governance extends security beyond confirming an agent’s identity or permissions. It asks whether the agent’s actions were appropriate, observable and reviewable in context. For AI-assisted development, that context should include the human request, the agent’s activity, applicable policy decisions and the resulting code change.

Matching autonomy to reversibility—and anchoring agent activity to human intent—gives engineering and security teams a stronger basis for deciding when agents can act independently and when a person must remain in the loop.

Further reading: Akamai’s report announcement and analysis of behavioral governance for the agentic enterprise.