AI Agent Governance for Risk Leaders: Lessons from the Frontlines
About This Session
As enterprises rapidly transition from passive LLM chatbots to autonomous AI agents capable of executing multi-step business tasks, risk leaders face an entirely new paradigm of operational danger. Unlike static models, autonomous agents have the authority to act—calling APIs, querying databases, and modifying corporate environments. Knowing how to establish guardrails without halting business innovation has left many security leaders paralyzed. This session cuts through the hype, delivering hard-learned lessons and actionable insights gathered directly from the frontlines of enterprise AI deployment and incident response.
Moving past theoretical frameworks, this talk addresses the real-world friction points keeping leadership up at night: privilege creep, "black box" execution pathways, and the rise of shadow agent deployments by business units. Attendees will learn how organizations are successfully balancing innovation and risk, exploring practical strategies to safely enable these high-productivity tools without inadvertently opening a backdoor to enterprise data assets.
Key areas covered include:
- The Agentic Risk Landscape: A frontline analysis of the unique security, compliance, and operational risks introduced when autonomous agents are granted execution capabilities.
- The Governance Blueprint: Core pillars for establishing operational guardrails, creating cross-functional oversight, and integrating agentic threat modeling into existing enterprise risk management frameworks.
- Real-World Case Studies: Lessons learned from early enterprise deployments, highlighting both rapid business wins and overlooked security gaps that led to live incidents.
- Securing the Ecosystem: High-priority technical and procedural controls to secure the AI agent lifecycle without degrading model performance.
Moving past theoretical frameworks, this talk addresses the real-world friction points keeping leadership up at night: privilege creep, "black box" execution pathways, and the rise of shadow agent deployments by business units. Attendees will learn how organizations are successfully balancing innovation and risk, exploring practical strategies to safely enable these high-productivity tools without inadvertently opening a backdoor to enterprise data assets.
Key areas covered include:
- The Agentic Risk Landscape: A frontline analysis of the unique security, compliance, and operational risks introduced when autonomous agents are granted execution capabilities.
- The Governance Blueprint: Core pillars for establishing operational guardrails, creating cross-functional oversight, and integrating agentic threat modeling into existing enterprise risk management frameworks.
- Real-World Case Studies: Lessons learned from early enterprise deployments, highlighting both rapid business wins and overlooked security gaps that led to live incidents.
- Securing the Ecosystem: High-priority technical and procedural controls to secure the AI agent lifecycle without degrading model performance.
Speakers
Jose Toledo
Principal Consultant - Google
José is a strategic cybersecurity advisor at Mandiant, part of Google Cloud, specializing in securing AI deployments and aligning technical risk with business objectives. With over a decade of experience across IT, OT, and AI landscapes, he moves security from abstract theory to frontline execution. His background spans network administration, cloud threat assessments, and executive tabletop simulations, focusing on translating complex threats into high-impact governance strategies. José’s work spans the entire risk lifecycle, helping global organizations safely adopt autonomous technologies and implement resilient guardrails. Beyond Google, he serves on corporate advisory boards, guiding organizations through the rapid evolution of emerging tech.
Ryan Fried
Principal Security Consultant - Google
Ryan is a seasoned cybersecurity leader with over a decade of experience spanning the entire security lifecycle—from the front lines as a SOC Analyst to strategic leadership as a CISO. A dedicated educator, he has spent the last eight years shaping the next generation of defenders as a cybersecurity instructor at the community college level.
Currently, Ryan specializes in high-impact initiatives, including cyber defense assessments, threat hunting program development, and cloud security posture (CSPM). His unique perspective blends technical rigor with a consultant’s eye for program maturity, making him a sought-after voice on building resilient security cultures.
Currently, Ryan specializes in high-impact initiatives, including cyber defense assessments, threat hunting program development, and cloud security posture (CSPM). His unique perspective blends technical rigor with a consultant’s eye for program maturity, making him a sought-after voice on building resilient security cultures.