The bottom line: governing AI agents does not prove that people changed their behavior
Policing an AI agent and validating a person are two different things, and it pays not to confuse them. Putting guardrails around an autonomous agent, logging what it does and limiting its permissions solves a real problem: software that acts on its own. But it says nothing about whether the person who gets a fraudulent email at five on a Friday afternoon will fall for it. Human risk is measured by watching how someone behaves under the pressure of a deception, and that is not governed from an agent's control panel.
We lead with this because the noise of 2026 pushes in the opposite direction. The conversation is moving toward agents, and it is easy to assume that controlling them also covers the human part. It does not. These are separate risk surfaces measured with separate instruments, and treating them as one leaves a gap exactly where attackers get in most.
What changed in 2026: the market is racing to police autonomous agents
So far this year, AI agent governance has gone from a conference topic to a product category. Companies started deploying agents that run entire workflows with no person reviewing each step, and with that came the inevitable question: who is accountable when an agent with broad permissions makes the wrong call. Gartner placed agent governance, agent security and agent cost control as emerging profiles in its hype cycle, and warned that applying uniform governance to every agent alike will fail, because each one has a different level of autonomy, access and operational risk.
Human risk is managed automatically.
Turn human risk into your first line of defense.
Book a demoFree demo · 30 minutes · No commitment
The concern is legitimate. A poorly governed agent can cause financial or reputational loss, disrupt a service or leak data. None of that is trivial. The point is something else: all that attention concentrates on the agent as an actor, and overlooks the actor that remains attackers' number one target, which is the person.
Agent risk versus human risk: two different problems worth keeping apart
Agent risk and human risk look alike just enough to be confused, and differ in what matters. Agent risk is that of an autonomous system acting with permissions: the question is what it can do, how tightly scoped it is and how it is audited. Human risk is that of a person deciding under pressure, often deliberately deceived: the question is whether they recognize the pretext and resist, or hand over their credentials without noticing.
Cisco's 90-5-5 framework, which estimates that around 90 percent of security breaches involve a human factor, still describes where most of the damage comes from (source: Cisco). Having agents in the equation now does not change that split; it adds a new surface without retiring the old one. In fact it complicates it, because an attacker who fools a person can end up manipulating, through that person, the agent they supervise. The link that breaks first is still human, which is why we talk about the human factor and not human error: the person is the target of the attack, not the one to blame for it.
Why automating the attack does not prove a person's resilience
Generating more sophisticated attacks with AI, or launching them at greater scale, does not prove that people know how to resist them. It is a convenient mix-up: if the tool can produce a perfect phishing email or a convincing business email compromise (BEC, the fraud where someone impersonates an executive or supplier to redirect a payment) pretext, it looks like we are already measuring risk. But building the attack and validating the person's response are different steps. The first produces ammunition; the second produces behavioral evidence.
Behavioral evidence only appears when the person is tested again. Completing training does not, on its own, predict that someone will stop falling for a real deception, and the same goes for having survived a simulation once: they may have memorized the email without changing anything underneath. Validating behavior change means putting the person in front of an equivalent situation again, weeks later, with a different context, and watching whether they recognize the signal this time. That is what an automated attack, by itself, does not deliver. We wrote earlier about why traditional training falls short in why your training program is not working.
Human risk management (HRM) validates behavior change, not agent autonomy
Human risk management (HRM, the category devoted to measuring and reducing the risk that people introduce) answers a question that agent governance does not touch: did the person's behavior actually change. It does not measure whether the employee knows the theory or whether the agent is well scoped. It measures how the person acts when pressured with a realistic deception, and whether that behavior improves over time.
The core of that approach is testing again, known as retest: after someone fails and receives a short correction, they are sent another test of the same kind but different, later on, to confirm they learned the lesson and did not just memorize an email. It is a neutral concept, not a brand feature: any serious human risk program should be able to show that behavior changed, not just that the course was completed. While the market debates how to put guardrails on agents, this question about people remains, in most organizations, without a verifiable answer.
What a CISO should keep measuring while the noise moves toward agents
A security leader can govern their agents and, at the same time, not lose sight of their people; the two do not compete for the same attention budget if they are kept clearly apart. The trap is letting the novelty of agents absorb the entire risk conversation, because the human factor has not gone anywhere: it is still where most attacks get in.
In practice, that means keeping measuring the same things with more discipline, not less. How many company credentials are exposed and how long the team takes to react when one shows up. How vulnerable each person is to a pretext aimed at their role, measured with realistic simulations and not with a test the employee knows they are taking. And, above all, whether that vulnerability drops over time, validated by testing again, the only signal that truly shows behavior changed. None of those questions is answered by any agent governance dashboard, and they are the ones that hold up an organization's real risk score.
This is the line Fensivo works on: a human risk management platform built for LATAM that detects exposed credentials, tests each person with personalized simulations and validates behavior change by testing again weeks later, rather than accepting course completion as proof. It is the use case we address when the risk lies in people and not only in technology, and which you can review in our use cases.
As your organization prepares to govern its AI agents, what evidence could you show today that your people resist a deception better than they did three months ago?
Sources and references
- Cisco, "The 90-5-5 Concept: Your Key to Solving Human Risk in Cybersecurity", May 27, 2025. blogs.cisco.com
Human risk is managed automatically.
Turn human risk into your first line of defense.
Book a demoFree demo · 30 minutes · No commitment
