In July 2026, during testing, autonomous AI agents breached Hugging Face’s production infrastructure without any human direction or knowledge. When the 2026 API World conference opened in Santa Clara on September 1, the question on everyone’s mind was no longer “how to make AI smarter?”. It was “can we stop them from taking actions we never approved?”.
API World is the largest API conference in the world, and this year’s theme was very appropriate for the time: APIs in the Age of AI, with a dedicated MCP summit and AI TechWorld running alongside it under the same roof. AI agents are the fastest-growing consumers of APIs. But the API infrastructure that most enterprises rely on was never built for that.
For the last 10 years at Axway, I have been working with enterprise customers, helping them architect integration solutions and work through shifts like this one. I see the agentic AI governance gap up close, in real environments and with real stakes.
When I stepped onto the main stage of API World this year, I asked the audience: Can your AI agent trust an API it found? The timing couldn’t have been sharper.
The AI governance gap is worse than the numbers show
Earlier this year, Deloitte surveyed over 3,000 IT professionals on the state of AI in their enterprises. They expected that the number of enterprises that use agentic AI would triple by 2027. And yet, only 21% of respondents said that they have a mature agentic AI governance model in place.
At the start of my speech, I asked the audience: Do you have AI agents connecting to enterprise systems and APIs, and can you name every API and MCP, and the systems they can reach? Virtually no one raised a hand.
This is not a data point. It is the operational reality that I regularly see in my conversations on this topic. And a lot of teams have not internalized it yet: even if you are not building AI agents, they are already reaching your systems. If you don’t have APIs governing agent access, they will screen-scrape your data anyway. You can’t choose to detach yourself and your data from AI. You are choosing whether you can be ready for it.
See also: How enterprises can turn possibility into scalable AI impact
Legitimate task, one unmanaged API, millions of dollars in losses
Picture a successful e-commerce operation. An internal app manages sales tax calculation by SKU and by state. The team ships a new version of an API, and the adoption is fast. Three weeks later, in the hour of peak sales, the cart crashes and stops working.
Security looks into the abundant traffic and concludes: We are being attacked.
Every second that the cart is down costs real dollars. In a couple of hours, the first million dollars is lost. The security team traced the traffic and discovered that there was no attack: all traffic had been coming from one internal computer in accounting. Someone used an AI coding assistant to vibe code an agent to help with month-end reconciliation. The timing matches: the accidental “attack” happened on the last day of the month. The agent was calculating tax for every SKU, in every store, in every state. Tens of millions of calculations — each created a new request against one API endpoint.
Nothing was attacked, and nothing was hacked. No security breach happened. The API worked as intended. The goal was legitimate. The agent didn’t conspire against its creator. It did exactly what it was prompted to do: it found an API and used it. No one would have noticed, and no revenue would be lost if there were quotas and rate limits. Nobody thought about securing an internal API, but with a bit of help, it took down the entire customer-facing operation.
Internal doesn’t equal safe. Found doesn’t mean trusted. Trusted doesn’t mean authorized.
One agent, one goal, two different outcomes
I ran two demos on stage. Imagine a scenario: an AI agent needs to issue a visitor pass, but the primary visitor API is down. The agent knows it has a task to complete, and seeing that the clearest option for the task isn’t available, it starts looking for alternatives.
The first demo. The agent queries the API inventory, which is unmanaged. It finds four different options, but they don’t have ownership, documentation, or approved metadata. The agent picks the option that it considers the best capability match: the facility access API. The agent completes the task by giving the visitor a full pass to every floor and door in the building. The agent’s choice was reasonable within the environment it was given. But “best fit for the task” is not the same as “right fit for the intents and purposes of the task.” The enterprise itself didn’t seize its chance to have a say in this process.
The second demo. The agent sees that the main visitor pass API is down, and this time, it queries the curated catalog in the Amplify Platform. The agent sees only the APIs that it is eligible to use, scoped by audience and purpose. The facility access API is cataloged to be used only for specific employees, and never for visitors, so the AI agent never even sees it. The agent selects the lobby access API and issues a one-hour lobby pass to the visitor, preventing the accidental breach. The enterprise used its chance to decide on eligibility and authority. The agent retained its autonomy within the set boundaries.
Agentic AI governance gap
Notice that no security incident happened in any of the scenarios above. Every platform handles security reasonably well. Platforms fell short upstream: discovery, validation, curation.
A lack of adequate security and a lack of adequate governance can deliver similar risks. But the split between security and governance matters. The runtime gets protected in the data plane, and it is the control plane where humans and agents can discover the tools and interfaces that exist across your environment, validate them, catalog them with documentation and governance rules, and then ship them to the marketplace.
Most platforms are strong in one of these two planes. The Amplify Platform was built to strengthen both.
The result is autonomy that is bounded: automated and continuous accountability before, during, and after every agentic action, with discovery, validation, enforcement, and monitoring running on their own.
4 agentic AI governance questions every enterprise should answer now
No matter if you build AI agents, they are already reaching into your environment. Before they start causing trouble, or before you deploy your first agent, ask four questions.
What does the agent touch? List all API and MCP tools and the systems they can actually reach, even the ones they are not supposed to use.
What allows reaching into these systems? For each agent, identify what specifically makes communication eligible: audience, scope, business justification — or lack of governance?
For the eligible access, who approved it? The answer should include a human, a team of humans, or a policy designed by humans. If the answer is missing, this is a troubling finding.
Finally, what happens if something goes wrong? You should have an audit trail, automatic expiry, and a way to revoke access without shipping a hotfix.
Start with these questions. You are in control of your AI agents — if you take a step to control them.
AI governance is a natural extension of decades of Axway’s expertise in APIs, gateways, and enterprise integration
