All articles

Aug 25, 2026

AI Weekly: Nobody Onboarded the Agent

The agent got hired without an identity, a manager, or a dictionary

Nobody Onboarded the Agent

A security team was asked how many AI tools its company had approved. Eight, it said. Then somebody actually looked, and the browsers turned up 243.

That is Michael Leland, field CTO at Island, describing his own customer assessment: "I had a customer insists that they only had 8 sanctioned AI tools in use. We did an assessment with just our browser extension. We found 243 tools." Two orders of magnitude of software walked in without anyone processing the paperwork.

His framing is the useful part, because it is not a security framing. It is an HR one. "You never onboarded your agents. Your agents didn't go through HR training. They didn't go through acceptable use training. They don't understand your data governance policy." What arrived, in his words: "They are the new virtual knowledge worker." Bans do not work on it either, because "If you tell a user no, he will find a way around your no to get a yes."

Clare Liguori, a senior principal engineer at AWS who maintains MCP, hit the same staffing problem one layer up. How many agents a company runs turns out to be a function of its org chart, not its product. "Conway's law has been applied to agents very much." Every team takes an annual goal to build one: "I'm starting to hear from AWS customers that, hey, I have 500 agents across all of these teams internally, and that just seems like too much these days." Her prescription is subtraction. Most of those teams needed a skill or an MCP server, not a hire. And nobody built the boring part that would let them share one: "for the last 25 years, we have been, you know, fed the gospel of service oriented architecture. And now we're just shoving markdown files around."

Microsoft Gaming's deputy CISO Aaron Zollman is working the credential half, which is what breaks when a worker has no employee record of its own. "If you just start with, oh, well, it's just gonna run as me. It's going to take my token directly from my browser cache and do whatever it wants to do with that token, that's going to end poorly."

Vanguard's Raman Tallamraju has the part nobody can buy their way out of. Enterprises never wrote down what their own words mean, because staff papered over it by asking a colleague what a column meant. Take the colleague out of the loop and the deferred bill lands at once: "But an agent in AI could just take the wrong context and take an action on it." No vendor sells the fix, because "most of the institutional knowledge still sits within people's heads."

Last week the skill got a gatekeeper and a budget line. This week, in security, platform engineering and data architecture at once, the thing wielding it turns out to have been hired without an identity, a manager, or a dictionary.

Sources: Michael Leland (Island), Cloud Security Podcast, "Shadow AI & Sandbox Escapes: Why You Need an Agentic Control Plane?," Aug 18, 2026. Clare Liguori (Amazon Web Services), Dev Interrupted, "Agent, skill, or MCP? Which to use and when to use them | AWS' Clare Liguori," Aug 18, 2026. Aaron Zollman (Microsoft Gaming), a16z, "Microsoft's Deputy CISO on Securing AI Agents," Aug 21, 2026. Raman Tallamraju (Vanguard), The Data Chief, "How Vanguard is Architecting its AI Semantic Layer," Aug 19, 2026.

Security, platform engineering and data architecture independently described AI agents as hires that skipped intake: no identity, no owner, and no written definitions for the data they act on.