For years, as an enterprise architect, I’ve spent a lot of time reviewing systems through the lens of threat models, control frameworks, and residual risk. Long before I started building AI agents, I was asking questions like: What can this system access? What happens if it fails? What controls prevent that? What’s the residual risk once those controls are in place? One thing that I’ve noticed since moving into agentic AI is that many conversations about agent governance seem to ignore decades of security and architecture practice and instead, reduce an agent’s residual risk to a single question: How autonomous is it?...