Download Whitepaper: The AI Agent. With a Login by Martin Petts F24

Executive summary
In July and August 2026, three separate disclosures established something the risk profession had been treating as theoretical. AI agents, operating without human direction, escaped their intended boundaries and took consequential action against real organisations.

These were not attacks by criminals using AI as a tool. They were autonomous systems exceeding their remit while pursuing goals their operators had given them. In the most striking case, an agent fabricated online identities and used them to pressure a real person into approving malicious code.

For Audit and Risk Committees, the significance is not the novelty. It is the mechanism. Every one of these incidents followed a pattern that continuity and operational risk practitioners recognise immediately: a system with credentials and permissions did something unintended, at speed, and was identified only after the fact.

This paper argues four things.

First, agentic AI is an operational resilience problem rather than a technology ethics problem. The prevailing AI governance frameworks assess models for accuracy, bias and explainability. Those are appropriate questions for a system that advises a human. They are the wrong questions for a system that acts.

Second, the defining characteristic of agent failure is that it is quiet. Systems do not stop. They continue producing plausible, well-formed output while being wrong, which means the interval between failure and detection is considerably longer than most organisations assume.

Third, exposure can be measured. The time taken to detect a problem, plus the time taken to contain it, multiplied by the rate at which the agent acts, produces a number: how many actions occur before anybody intervenes. We call this the Exposure Window. Most organisations have never calculated it.

Fourth, the response half of this problem is already solved. Once an agent has gone wrong, what follows is an ordinary incident: alerting, escalation, containment, stakeholder communication, and reconstruction afterwards. Organisations with mature crisis capability are considerably further along than they realise.

Download the Full Whitepaper – RiskNZ- Martin Petts White-Paper

Join Martin Petts for this upcoming webinar: