The Three Questions Everyone Is Asking About Agentic AI

Enterprise AI agent deployment has outrun governance by a wide margin. Ninety-one percent of organizations are deploying agentic AI. Ten percent have any form of agent governance in place. The three questions that the Okta CEO derived from 40 enterprise customer meetings — where are my agents, what can they connect to, and what can they do — are now being posed in boardrooms and investment committees with no clear answer in sight. The IRM Navigator™ Model provides the analytical structure to answer them: each question maps to a distinct risk domain, each domain requires a distinct governance response, and the full loop closes at ERM where the aggregate risk state is measured against enterprise risk appetite. The question this note answers is whether any platform architecture currently running in production can close that loop continuously — and what happens to the organizations and vendors that cannot.

The cybersecurity industry has built a rigorous answer to the second question. Access governance, privilege management, and identity threat detection are mature capabilities, and the Okta blueprint represents the most structured articulation of their extension to agent identities. But the identity security layer enforces the rules that the governance layer establishes. When those rules are absent, outdated, or misaligned with the organization's actual risk posture, identity security enforces the wrong rules with precision. The IRM50 AI Disruption Risk Index Compression Boundary describes exactly where the structural gap opens: vendors above it have platform architectures capable of accelerating toward continuous risk governance; vendors below it are structurally dependent on human-paced workflows that agents will simply outrun. This RTJ Bridge research note examines what it takes to answer the three questions at enterprise risk level — and which vendors and organizations are architecturally positioned to do it.

John A. Wheeler

John A. Wheeler is the founder and CEO of Wheelhouse Advisors, a global risk management strategy and technology advisory firm. With over three decades of experience spanning executive management, finance, risk management, audit, and IT, John is a world-renowned expert in integrated risk management technology, executive leadership, and corporate governance.

https://www.linkedin.com/in/johnawheeler/
Sign up to read this post
Join Now
Next
Next

NemoClaw and the Trillion-Dollar Tailwind for Autonomous IRM