As enterprise AI moves from chatbots toward autonomous agents capable of accessing files, applications and business data, governance is becoming a more difficult problem than model selection. The AI Governance World Conference 2026, scheduled for October 12–14 in Las Vegas, will bring technology, cybersecurity, privacy, legal, risk and governance leaders together to examine that challenge, with agentic AI and sensitive-data governance expected to be central themes.
Enterprise AI adoption is creating a new security boundary—and it is not necessarily the model.
As organizations deploy AI agents capable of retrieving information, invoking tools and completing multi-step tasks, the question of who or what can access sensitive enterprise data becomes increasingly important. The upcoming AI Governance World Conference 2026 will focus on that problem when it takes place October 12–14 at the Flamingo Hotel in Las Vegas.
The event is positioned at the intersection of artificial intelligence, cybersecurity, privacy, legal compliance and enterprise risk. Its focus reflects a broader shift in AI governance: companies are moving beyond evaluating whether an AI model produces accurate answers and toward determining whether autonomous systems can safely operate inside corporate environments.
Among the companies presenting at the conference is Kiteworks, a Silicon Valley-based data-security provider focused on protecting sensitive information as it is transmitted, shared and used.
Kiteworks says its software protects more than 100 million end users across thousands of enterprises and government agencies. Its platform uses a unified control plane intended to track, govern and protect sensitive data moving within organizations and across organizational boundaries.
That emphasis on data in motion is particularly relevant to agentic AI.
Traditional data-security programs have often concentrated on data at rest: databases, file repositories and other locations where sensitive information is stored. But an AI agent may need to retrieve a document, send information to another system, call an external service or share data with another agent to complete a task.
Each interaction creates another potential control point.
Kiteworks Chief Strategy Officer Tim Freestone argues that organizations need to extend data governance to those moments when AI agents request, use and share information.
The issue is becoming more pressing as agentic AI moves from experimental deployments toward enterprise workflows.
Unlike conventional software, an AI agent can interpret instructions and dynamically decide which tools or information sources to use. That flexibility is part of its value—but it also makes traditional permission models harder to apply.
An employee may have permission to access a collection of documents, for example, without every AI system acting on that employee’s behalf necessarily being appropriate for unrestricted access. Organizations therefore need to establish not only who can access data, but what an AI system is allowed to do with it.
This creates a governance problem spanning identity, authorization, data classification, auditability, privacy and compliance.
Kiteworks’ General Counsel Camilo Artiga-Purcell will address the legal dimension at the conference in a session titled “Your AI Passed the Bar Exam. Your Governance Didn’t.” The presentation is expected to focus on the exposure created when AI systems interact with privileged or otherwise sensitive information.
Freestone will separately present “Controlling Data Access and Use by AI Agents for Compliant AI,” focusing on the governance of data as it moves through AI-enabled workflows.
The company’s argument is supported by findings from its 2026 Data Security and Compliance Risk Report, which it says found that the average organization has only around one-third of the AI data-governance controls required to meaningfully reduce risk.
That figure should be treated as a vendor-reported industry finding rather than an independent measure of enterprise AI governance. Even so, the underlying issue is widely recognized.
McKinsey’s research has found that organizations are increasingly experimenting with AI agents, while governance and risk-management practices have not necessarily developed at the same pace. Its 2025 State of AI report found that 88% of respondents said their organizations regularly use AI in at least one business function, but most organizations had not yet fully scaled their AI programs.
The governance challenge is likely to become more complicated as companies connect agents to enterprise systems.
Microsoft, Google, Amazon Web Services and Salesforce are among the major technology providers building agentic AI capabilities into enterprise software and cloud platforms. These systems can potentially retrieve data, execute workflows and interact with business applications with substantially less human intervention than traditional AI assistants.
That makes governance an architectural issue rather than simply a compliance checklist.
Enterprises adopting agentic AI will increasingly need to define permissions at the agent and workflow level, maintain detailed audit trails and understand where sensitive information travels during automated processes. They also need controls for revoking access and investigating unexpected behavior.
This is where the distinction between AI governance and data governance becomes important.
A company can have policies governing which models employees are allowed to use while still lacking sufficient visibility into what those models—and the agents built around them—can access.
For legal and compliance teams, the stakes can be particularly high when AI systems encounter regulated information, intellectual property, customer records or attorney-client privileged material.
For security teams, the problem resembles an expanded attack surface. Every additional tool, connector or data source available to an AI agent can potentially create another pathway through which information is accessed or transferred.
For technology leaders, meanwhile, excessive restrictions can undermine the productivity benefits that make agentic AI attractive in the first place.
The challenge is finding a balance between autonomy and control.
That tension will likely define much of the next stage of enterprise AI adoption. Companies cannot treat agents as ordinary software users, but they also cannot realistically require humans to approve every low-risk automated action.
Instead, governance architectures will need to distinguish between different types of data, actions and risk levels.
AI Governance World 2026 arrives at a moment when that conversation is moving from theory to implementation. Kiteworks’ presence at the event underscores the growing connection between AI adoption and data-security infrastructure.
The broader lesson for enterprise teams is straightforward: deploying an AI agent is not just a model decision. It is also a decision about identity, data access, compliance, monitoring and accountability.
As AI systems become capable of acting rather than simply responding, those controls may become as important to enterprise AI strategy as model performance itself.
Market Landscape
The enterprise AI market is moving toward agentic systems that can retrieve information, use software tools and execute multi-step workflows. Microsoft, Google, AWS and Salesforce are all investing in agent-oriented capabilities, creating a rapidly expanding ecosystem around autonomous enterprise software.
This evolution is changing the security model.
Traditional applications generally operate according to explicitly programmed workflows and permissions. AI agents can introduce greater flexibility and variability because their actions may depend on context and dynamically selected tools.
That creates demand for technologies spanning AI governance, data-loss prevention, identity and access management, privacy, compliance monitoring and data-in-motion security.
Kiteworks is competing within that broader security and governance landscape rather than directly against foundation-model providers. Its focus is sensitive-data movement and control, an area that becomes increasingly important when AI agents are connected to enterprise repositories and external services.
For enterprise buyers, the critical evaluation criteria will include granular access controls, auditability, integration with existing security infrastructure, regulatory compliance and the ability to govern agent activity without making automation impractical.
Top Insights
- AI Governance World 2026 will examine enterprise AI readiness, with agentic AI bringing technology, cybersecurity, legal, privacy and risk leaders together around emerging governance challenges.
- Kiteworks will focus on AI data access, arguing that organizations need controls over sensitive information while agents retrieve, process and share data.
- Agentic AI changes enterprise security, because autonomous systems can interact with multiple applications and information sources without requiring human approval for every step.
- AI governance must extend beyond models, covering identity, permissions, data movement, audit trails, compliance controls and the actions agents can perform.
- Enterprise adoption creates a balancing act, requiring security teams to protect sensitive data without restricting the autonomous workflows that make AI agents valuable.
Power Tomorrow’s Intelligence — Build It with TechEdgeAI












