“Start by doing what’s necessary; then do what’s possible; and suddenly you are doing the impossible.” – St. Francis of Assisi
In the 12th century, St. Francis wasn’t talking about digital systems, but his advice remains startlingly relevant for today’s AI governance challenges.
Enterprises are suddenly full of AI agents such as copilots embedded in SaaS platforms, LLM-powered automations in CI/CD pipelines, and countless scripts making API calls to model providers.
Every security team starts with the same mantra: “We need visibility first.” But with AI Agents, discovery has become a trap. The pursuit of perfect visibility can keep teams paralyzed while ungoverned agents run free. Discovery feels safe. Discovery is measurable and non-controversial. Discovery is an endless pursuit. However, discovery on its own doesn’t move you closer to the ultimate goal of security and governance. AI agents aren’t hiding behind obscure APIs. They’re in plain sight with excessive access! Waiting for perfect inventory before enforcing governance only extends your exposure window. The truth is you already have visibility. It’s imperfect and incomplete, but it’s there.
The question isn’t whether you can see your AI agents. It’s what you’re going to do about the ones you already know exist.
For those of us in the security business, the saying “Do not let perfect be the enemy of good,” or in this case “good enough” is not just good advice, it is the pragmatic foundation for making progress in an imperfect world. This pragmatic approach extends to improving visibility. The best way to improve your visibility isn’t to deploy another scanning tool, it’s to gain momentum by securing what you do know. This pragmatic approach lets you create a framework will then allow you to use that identity fabric to discover what you’re missing and get you to your ultimate goal.
Stop waiting for perfect discovery! You already know about AI agents in your environment:
Are you governing what you do know about AI in your environment? Most authenticate with static API keys, creating an exponential secrets sprawl problem that grants uncontrolled access to sensitive data and systems with long-lived credentials.
Even worse, these agents operate inside legacy environments that were designed for human users, not autonomous actors. These systems are overpermissioned and lack fine-grained access control, making them fertile ground for AI agents to overreach unintentionally as they pursue their assigned tasks. While the intention of your development teams is to enable the business, the unintended consequences could do more harm than good.
The risks compound quickly:
Here’s the path forward:
The misconception is that you need complete visibility before you can act. In practice, acting on partial visibility creates better visibility.
If yesterday you governed five AI agents and today you govern fifteen, that’s not imperfection, that’s momentum.
With Defakto, each step forward compounds:
Organizations using this approach deploy AI faster, reduce security review cycles from weeks to minutes, and cut the operational cost of credential management to near zero, all while maintaining provable control, compliance, and trust.
You don’t have to discover every AI agent before you can take control. Defakto gives you the framework to make it safe to deploy AI at scale by starting with what you can see today.
Defakto’s no-code/low-code deployment model, identity-based access control, and real-time audit trail, is the AI Identity Fabric that connects agents to your environment without requiring your engineers to become identity experts, slowing down delivery or sacrificing control.
With Defakto, your security team gains continuous oversight. Your AI projects keep their momentum. And your organization builds trust in AI, one visible, governable step at a time.
Schedule some time with our identity architect team.
*** This is a Security Bloggers Network syndicated blog from Defakto authored by Pieter Kasselman. Read the original post at: https://www.defakto.security/blog/your-ai-agents-arent-hidden-theyre-ungoverned-its-time-to-act/