Every AI agent an enterprise builds or adopts needs a path to reach real systems — data, APIs, applications, OT and IoT assets. The problem isn’t giving agents access. It’s that the tools used to grant that access (VPNs, firewall rules, vendor connectors, API keys) were built for a pre-AI world, and each one adds its own separate trust relationship that nobody can see or govern as a whole.

Download the PDF here.

Three Key Takeaways

1. Every new agent or vendor adds another ungoverned “door” — and the doors add up fast. Whether it’s a first-party agent built in-house or a third-party AI vendor requesting access to enterprise systems, the default pattern is the same: a new VPN profile, firewall exception, connector, or API key. Multiply that by every agent, every vendor, and every environment, and you get (n) tunnels for (n) AIs — each with its own credentials, policy model, and logs. The result isn’t just complexity; it’s a genuine blind spot. Enterprises can’t consistently answer which agents can reach which systems, right now.

2. The fix isn’t more network engineering — it’s replacing network borders with identity. Instead of a new border crossing for every agent-to-system connection, identity-defined governance makes connectivity a policy the team declares rather than a queue of firewall tickets. An agent (or a vendor’s connector, or a developer’s laptop) gets an identity, and that identity is authorized for specific services — nothing else is visible or reachable. Sites and devices dial out only, so nothing is ever listening for inbound connections in the first place.

3. This applies well beyond one team’s AI project — it spans six distinct patterns enterprises are already running into. From first-party agents reaching enterprise data (A2A/server-to-server), to developers and CI/CD pipelines accessing AI dev environments, to OT and IoT deployments where agentic ROI is highest and adoption slowest, to three flavors of third-party vendor access (customer-hosted connectors, vendor private paths like PrivateLink, and vendor agents calling enterprise MCP servers) — the same governance gap shows up everywhere an agent needs to reach something it doesn’t own.

The Bigger Picture

The underlying tension is a real one: enterprises are stuck choosing between slow AI adoption or sacrificed governance, because agents break access patterns designed for people, not software. Unifying governance, private connectivity, and observability into a single layer — one that extends as close to the AI as possible while covering every use case — is what lets organizations move at AI speed without losing visibility into what their AI can actually touch.