
What happened
Bhakti Pitre, ServiceNow's VP of AI platform security product, said at Okta's Oktane event that agent "kill switch" is not just on and off. She cited an agent authorized to discount 10% that got prompt injected and began discounting 100%.
Why it matters
ServiceNow is framing AI governance as five steps — discover, observe, govern, secure and measure — and says containment should scale with risk, so companies are pushed to weigh business impact before cutting an agent off.
What to watch
Pitre says no single provider sees every layer an agent touches, so ServiceNow is working with Okta on agent session tokens and identities. The test is whether vendors cooperate, which Pitre said requires being "each other's friends or frenemies."
WHO IT HITSThis lands on security and IT governance teams at enterprises that have already moved AI agents into production, plus the identity and endpoint vendors they rely on. It suggests those teams may need to define agent permissions and containment thresholds before granting agents authority over pricing or other business actions, based on the discount scenario Pitre described.
Summaries like this, in your inbox every morning.
ServiceNow has spent the year pitching itself as the control tower for enterprise AI, and agent containment is the latest piece of that pitch. The company's argument, as laid out by vice president of AI platform security product Bhakti Pitre at Okta's Oktane event, is that governance does not end at deployment. ServiceNow frames the work as five steps — discover, observe, govern, secure and measure — and says containment should scale with risk. Pitre's contrast between an agent that simply stops producing results and one that was authorized to discount only 10% but, after prompt injection, began discounting 100%, is the concrete illustration of that scale: one case calls for a pause and investigation, the other for pulling the plug.
The harder half, in Pitre's telling, is knowing why to act, not just how. ServiceNow maps an agent to the business processes that depend on it and uses Veza's identity security technology to adjust excessive permissions, which is meant to supply the business context for that decision. Pitre also said no single provider sees every layer an agent touches, from the endpoint to the network and the gateway, and that ServiceNow is working with Okta on agent session tokens and identities.
What the outcome hinges on may be that cross-vendor cooperation. Pitre's remark that the industry needs to be "each other's friends or frenemies" suggests the containment question is likely to be settled less by any one product than by whether platforms and identity providers can cover the layers between them. For enterprises already running agents in production, the practical stake is whether they can define risk thresholds and permission limits before an agent goes beyond what it was authorized to do.
For example, today's edition would include:
AI-summarized, only the topics you pick: one digest a day via Email, LINE, or Slack.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.
1Password CTO Nancy Wang said at Okta's Oktane event that agents need just-in-time, task-based access, and the…
Meta is launching the Meta Enterprise Platform, led by CJ Desai, who joins as chief enterprise platform office…
Futurum's report, sponsored by QumulusAI Inc., finds agentic AI can drive token consumption per task 10 to 100…
Claude Code's creator Boris Cherny answered a developer's question on September 11, 2026, saying throwaway pro…

ITR principal analyst Hiroaki Koumoto said Japanese firms' efforts in harness engineering are 'almost nonexist…

Stagwell CEO Mark Penn told Power Players most digital ads "are not very good" and said AI's payoff is doing t…
