When I was tasked to formulate an AI strategy, I said, “there’s risk to doing something and risk to doing nothing.” I appreciated this article by Anthropic’s deputy CISO. Ready or not, connections are happening — the risk is not the connection, but rather the connection without any deliberate design.

This week Anthropic’s deputy CISO, Jason Clinton, published a guide for security leaders on agentic AI. It is written for CISOs, but it generalizes to every leadership team I have worked with.

When the governed thing moves faster than the governing process, the control does not disappear. It becomes ceremony, while the world around marches forward.

Somewhere in your organization, an employee has already connected an agent to something without telling you.Jason Clinton, “Zero risk isn’t the job”

While everything has a clock speed, the thing is, the clocks do not need to match. They need to remain connected — they need to be understood.

As someone who wants to move forward in safe and secure ways, I took notes on Clinton’s framework — a set of steps toward good governance. When an agentic use case reaches review, he asks four questions.

The four boundary questions

  • 01What untrusted content does it ingest? Untrusted means anything an attacker could plausibly write or alter — outside email, the open web, third-party documents. If the answer is nothing, the agent-specific risk is near zero. Move quickly.
  • 02What actions can it take, and on whose behalf? Read-only is a different conversation from read-write. Every action happens under some identity, and you need to know whose.
  • 03What is the blast radius if it goes wrong? One file or the whole organization. An anomaly, an annoyance, or a true incident.
  • 04What observability do I have? Can you tell the agent’s actions from the user’s?

“No” does not stop time. The technology keeps advancing. Employees keep experimenting. Vendors keep adding capabilities. Data finds new paths. A blanket no may slow visible adoption — it can also push activity outside the systems designed to govern it. The clocks keep moving. They just move out of sync. And risk builds in the gaps.

An agent that drifts out of alignment with your intent is indistinguishable from an insider attack.Jason Clinton, “Zero risk isn’t the job”

The lines in the drawing aren’t decoration. They are the design.

Identity, permissions, boundaries, telemetry, ownership. Cut them and the activity does not stop — it just comes loose from the people responsible for it. Inside becomes, functionally, outside.

Clinton’s closing argument is one I have carried for years in a different form: there is risk to doing something, and there is risk to doing nothing.

Waiting for zero risk means waiting forever. The web is adversarial, the models are evolving fast, and the organizations that learn to size and accept this risk now are the ones that get the advantage.Jason Clinton, “Zero risk isn’t the job”

The modern opportunity comes from connection: across systems, data, and decisions. The risk comes from connection without deliberate design — an architecture aligned with the organization’s innovation and risk appetite. Good governance does not force everything to move at the same speed. It keeps the clocks connected and the boundaries visible, and it moves the evidence by experiment, not ceremony.