Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Artificial Intelligence

Why enterprise AI programs must move from discovery to enforcement

Many enterprise shadow AI programs have completed discovery: they found more AI tools than expected and recorded them in a spreadsheet. According to TechRadar contributor Brad LaPorte, the work often stalls there.

Microsoft’s February 2026 Cyber Pulse research found an average of 37 agents per enterprise. More than half operated without security oversight or logging. An inventory records what happened; enforcement changes what happens while an AI action is taking place.

For an agent, enforcement means one of four interventions: blocking a tool, limiting what it can reach, requiring approval for a specific action, or terminating the process during execution. These controls have different trade-offs. Blocking is easy to deploy but produces complaints. Scoping is more durable but harder to configure. Approval gates can become routine clicks, while termination must happen before the action finishes.

Network blocking alone misses local models, embedded copilots, IDE and command-line agents, localhost MCP servers, and AI tools on personal devices. Identity systems can confirm that a person or service account is allowed to perform an operation, but they generally cannot determine whether software acting for that person should have done it.

LaPorte argues that controls should operate where the action executes, such as an endpoint or runtime. The article recommends measuring enforcement actions in the first quarter, including blocks and approvals. It concludes that discovery is an inventory, while enforcement is the decision that changes an outcome.

The article was produced for TechRadar Pro Perspectives. The views expressed are those of the author and are not necessarily those of TechRadarPro or Future plc.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.