Agentic Ai at SMBtech

Why Zero Trust Should Be The Governance Baseline For Agentic AI Engineering

Surprisingly Useful AI Article Enhancements

As “agentic” workflows move from limited pilots to broader enterprise experimentation, the primary constraint is no longer model capability – it is governance architecture.

For decades, the software development lifecycle (SDLC) has relied on structured human checkpoints to manage risk, quality and accountability. In 2026, that model is evolving. Autonomous agents are increasingly capable of refactoring repositories, generating documentation, writing tests and assisting with infrastructure configuration in parallel.

AI adoption in Australia is already substantial. Recent survey data indicates that a large majority of Australian enterprises are using generative AI in at least one function, even if maturity varies across sectors. As experimentation accelerates, organisations must contend with a new risk dimension: systems operating with delegated autonomy inside regulated environments.

For Australian CIOs and CISOs – particularly within APRA-regulated institutions – the question is not simply how agentic tools can improve productivity. It is how their use remains consistent with prudential standards, operational risk frameworks and established information security controls.

From Copilots To Coordinated Agent Systems

The most substantive shift over the past year has not been marginal model improvements, but experimentation with coordinated AI systems.

Engineering teams are testing orchestrator agents that manage specialised sub-agents: one proposes frontend refactoring, another updates documentation, another suggests test modifications. Structured context exchange mechanisms – such as the Model Context Protocol (MCP) – are emerging to enable controlled information-sharing between repositories and enterprise systems.

In large Australian organisations managing complex legacy estates, these capabilities can support more efficient code review and modernisation programs. Global research has ranked Australia among leading adopters of generative AI technologies, suggesting enterprise appetite for such tools is already established.

However, when multiple agents operate concurrently with API access and repository permissions, traditional perimeter-based security assumptions are strained.

In regulated settings, the prudent approach is to treat any autonomous system with production-adjacent access as a privileged insider from a control perspective.

Extending Zero Trust Principles To Autonomous Systems

Zero Trust Architecture (ZTA) principles – originally applied to human identities and service accounts – are increasingly relevant to autonomous systems. For APRA-regulated entities operating under CPS 234, the obligation remains consistent: maintain information security capability commensurate with vulnerabilities and threats and ensure control effectiveness.

Several domains warrant particular attention.

Cryptographic identity and traceability

Each agent instance should operate under a distinct, verifiable workload identity. Activity logs should record not only the initiating user, but the model version, configuration and policy boundary under which actions were executed. This strengthens auditability and post-incident investigation.

Segmentation and least privilege

Autonomous agents should operate within tightly scoped, short-lived environments with explicitly defined permissions. This aligns with least-privilege principles and complements segmentation practices embedded in many Australian organisations, including those guided by frameworks such as the ASD Essential Eight.

Human oversight and change governance

For material production changes, human approval remains essential. An agent may generate or recommend code modifications, but promotion to production should require explicit review and sign-off consistent with established change management frameworks.

Provenance and accountability

Public-sector guidance provides an instructive reference point. The Australian Government’s Policy for the Responsible Use of AI in Government mandates accountability, transparency statements and oversight mechanisms for AI systems deployed within Commonwealth entities. Complementary professional guidance highlights the need for traceability and governance structures to manage AI-related risk.

This public-sector lens reinforces broader enterprise expectations: artefacts should be traceable, decision rights documented and governance mechanisms auditable.

Consider a major Australian bank modernising its digital channels. An agent assisting with UI refactoring may require access to source repositories but should not have direct access to core transaction systems. Under a Zero Trust-aligned model, such boundaries are technically enforced. Any attempt to exceed authorised scope is denied by default – supporting both resilience and evidentiary requirements.

Observability And Control Effectiveness

Identity controls alone are insufficient. Observability must evolve in parallel.

Advances in automated testing – including self-healing test frameworks that adapt to interface changes – may reduce transformation overhead. However, natural-language-driven code generation introduces risks of logically coherent but contextually inappropriate output.

This raises practical governance questions:

  • Are generated dependencies fully understood?

  • Are privilege configurations aligned with policy?

  • Are changes auditable at the artefact level?

Traditional monitoring tools focus on deterministic behaviours. Agent-assisted development introduces probabilistic elements, requiring enhanced review automation, dependency scanning and anomaly detection to maintain control effectiveness.

Some institutions are exploring additional automated review layers to analyse generated code for policy violations or insecure configurations prior to integration. While still maturing, this reflects a core principle: AI-enabled development should be accompanied by proportionate control augmentation.

Australia’s Broader AI Adoption Context

AI adoption in Australia is not confined to financial services.

Colonial First State has publicly discussed rolling out Microsoft Copilot tools to most staff to improve productivity and operational efficiency.

Universities such as UNSW have entered enterprise agreements for generative AI tools, with safeguards designed to prevent institutional data from being used to train external models.

These examples demonstrate cross-sector experimentation – however governance consistently features as a central consideration. Surveys continue to show that while Australian organisations are active in deploying generative AI, governance, readiness and risk management remain prominent board-level concerns.

The Evolving Role Of The Architect

Agentic tooling does not diminish the role of experienced engineers. It elevates it.

Senior architects remain responsible for defining control boundaries, configuring enforcement points and ensuring identity and access management frameworks extend appropriately to non-human actors. In regulated environments, this also includes documenting responsibilities, escalation pathways and accountability structures.

As institutions plan for 2027 and beyond, productivity gains from AI-assisted engineering are likely to continue. However, within APRA-regulated entities, resilience, auditability and control assurance remain paramount.

Coding speed may improve. Prudential obligations do not diminish.

For financial services organisations operating under sustained regulatory scrutiny and heightened cyber risk expectations, the prudent path forward is clear: innovation should proceed, but within a Zero Trust-aligned governance framework that treats autonomous systems as controlled participants – not unsupervised accelerants.

In this context, Zero Trust is not a technology trend. It is a governance baseline.

Shreshta Shyamsundar is Distinguished Technologist at Infosys.

Last Updated on April 7, 2026 by Shreshta Shyamsundar

Surprisingly Useful AI Article Enhancements

Sign-up to the SMBtech Daily Newsletter

We will not spam you. You can easily unsubscribe any time. Read our privacy policy.