Every AI Agent Needs a Baby Gate

AI agents act with curiosity but no judgment. Learn the 6 pillars of AI governance and why access control must come first, backed by new CISO survey data.

Last updated:

Picture an infant standing at the top of a long, steep staircase. She’s curious, mobile, and has absolutely no concept of what happens if she takes one more step forward. She isn’t malicious. She isn’t even careless, really — she just doesn’t yet have the judgment to know where the danger is. So we install a gate.

That image is a pretty good stand-in for where we are with agentic AI today. We’ve built agents that are curious, mobile, and capable of taking action on their own: booking things, editing things, calling other systems, moving data around. They’re remarkably capable…and remarkably short on judgment about where the danger actually is. 

Like a toddler, an AI agent will walk straight toward the thing that hurts it (or us) unless something is in place to stop it. That “something” is AI governance: the set of controls that determine what an autonomous agent can see, touch, say, and be held accountable for.

Governing an Agent Is a Lot Like Protecting a Child

When babyproofing a house, parents don’t rely on a single safeguard. Instead, they layer several, each addressing a different kind of risk.

  • Data governance: what the child is exposed to, and what’s appropriate for their age. For an agent, it’s what data it can see, use, and retain.
  • Access governance: which rooms, cabinets, and streets are off-limits. For an agent, it’s which tools, systems, APIs, and resources it’s allowed to touch.
  • Behavioral governance: the rules of the house: manners, boundaries, what’s acceptable. For an agent, it’s the guardrails on what it’s allowed to say or do.
  • Identity governance: knowing exactly who this child is, and who’s responsible for them. For an agent, it’s a verifiable identity distinct from the human or service that deployed it.
  • Model governance: the child’s ongoing development. Are they growing and learning the way we expect? For an agent, it’s tracking the underlying model’s version, performance, and drift over time.
  • Audit governance: the running memory of what happened and when, so you can reconstruct events after the fact. For an agent, it’s the log of every action taken and why.

All six matter. None of them is optional. But they’re not equally urgent.

The Gate at the Top of the Stairs Comes First

Ask any parent which safeguard goes in on day one, before the child even starts crawling, and the answer is almost universal: the stair gate. You don’t wait to see if your child develops good behavioral habits, or wait to audit which rooms they’ve wandered into after the fact. You control physical access before anything else, because that’s where the irreversible harm lives. Everything else — teaching manners, tracking development, keeping a journal of the day’s events — matters, but it doesn’t matter if the child is already at the bottom of the stairs.

Access governance plays the same role for AI agents. An agent with unrestricted reach into your systems, tools, and data is one bad prompt, one hallucinated instruction, or one compromised credential away from real damage. Behavioral rules and audit logs help you understand and refine an agent after the fact, but controlling what it can actually reach in the first place is what keeps “after the fact” from being a disaster in the first place.

 If you get one governance area right before all the others, it should be access. Since you can’t fully control the agent, you must control what it can access first.

Where NetFoundry Fits In

This is the problem NetFoundry was built to solve. Our Zero Trust, Identity-First Reachability™ approach means an AI agent only gets access to the exact tools, resources, and data it’s explicitly entitled to: nothing discoverable, nothing implicit, nothing left to chance. That’s access governance done right.

But we don’t stop at the gate. We help enforce data governance at the point of access, give every agent a strong, verifiable identity, extend model governance through our LLM gateway, and generate the audit trail that shows exactly what your agents did and why. Six areas of governance, one platform that starts with the one that matters most.

The data backs this up. In our newly released 2026 State of Secure AI Access report, we surveyed 200 CISOs and CTOs on how they’re handling the security risks of AI deployment, and insufficient access controls came out on top as the single most-cited concern. In other words, the industry already knows where the gate needs to go. 

If you want to see how your organization’s approach to AI governance compares to your peers, the full report is worth a read.

Download the 2026 State of Secure AI Access Report

Related Reading