Highlights
An AI policy is a promise: it records what people intend and cannot see what they do.
Agents carry no risk of their own: they inherit it from whoever launched them.
The unit of analysis is the pair: one person plus the agents acting for them.
The consensus on AI risk fits on one slide: write an acceptable use policy, publish an approved tools list, train people on both. It is tidy, auditable, and the first thing a board asks for. It is also a control that has rarely been tested against an employee on a deadline.
In conversations this month, a security leader told us their AI policy has been driven mostly by legal, because the security team cannot see what employees do with AI agents or which MCP servers they connect. Another team has a written policy and no enforcement layer: employees pick their own model and their own editor, and nothing stops client data under NDA from landing in an external model. A third described an incident in which an AI agent served a malicious link back to an employee.
Here is the claim: an AI policy is a statement of intent by humans about humans, and the risk it is meant to govern lives in behavior it cannot see. Agents carry no risk of their own. They inherit it from the person who launched them.
The attack ran through a person
Look at the shape of the incident. Nobody attacked a model. An employee asked an agent for help, the agent returned something hostile, and the path to harm ran through a human who trusts the output. Whether anyone clicked matters less than the structure: the agent was the delivery vehicle, and the person was the target.
That leader's ask is revealing. They want malicious links sandboxed and stripped from agent responses before they reach the user. Of AI security, they said: "we need a layer in there for AI specifically." They are not asking for a better policy. They are asking for a place where behavior can be seen and acted on.
Same human, larger blast radius
If risk is inherited, the unit of analysis is the pair: a person plus the agents acting for them. The employee who pastes credentials into a chat window will hand the same credentials to an agent with tool access. The employee who reports every odd email will probably scrutinize a dangerous tool call. The habits are the same. The blast radius is larger.
A policy document cannot tell you which pairs to worry about. Behavior can. A policy is a moat drawn on paper, and behavior decides whether anything crosses it.
The narrower claim
None of this means throwing the policy out. A policy is the starting condition. But a control you cannot observe is a hope, and a control you observe but never act on is a log.
The useful version has three parts: see which agents each person runs, test the policy against those agents before an incident does, and nudge the person at the moment of the risky action. That is human risk work, pointed at a larger surface. The agent era does not replace the human column of risk. It multiplies it.
Key Takeways
Treat your AI policy as a statement of intent, not as a control.
Inventory which agents and MCP servers each employee actually uses.
Evaluate people and their agents as pairs, not as separate risk categories.
Test the policy against real agent behavior before an incident does.
Intervene at the moment of the risky action, not in the next quarterly training.




