Enterprises also want assurance that the risks posed by emerging AI technologies, including agents, won’t increase corporate risk levels beyond their ability to monitor and respond.

But unfortunately, as the industry grapples with a summer’s worth of reports of agents breaking containment, roaming the internet, breaking into systems, and generally behaving in all sorts of unexpected ways, AI companies are in no position to provide these kinds of assurances, Levy said.

Advice as AI scrutiny increases

He advised enterprises to minimize their AI-centric risk profiles, and simultaneously maximize their ability to derive value from AI, by enforcing standards for vendors now, rather than waiting for something like SAFA to materialize.