The conversation around AI agents is accelerating but so is a fundamental misconception. Following a recent IDC dinner, one theme stood out in an AI Agent discussion, a conflation of AI agents with IoT. They are not the same thing. IoT senses and acts, AI agents decide.
That distinction matters. AI agents are not devices, they are autonomous software entities exercising control over devices and systems often dynamically as a black box. They are an autonomous decision making layer sitting above and increasingly embedded within IoT systems. They interpret signals, orchestrate responses and increasingly act without human intervention. In effect, they are becoming the brains of IoT, consider them the non-human identities with the ability to make and execute decision.
This shift changes the assurance problem. Historically, IoT validation focused on devices, firmware integrity, connectivity and data flows but in agent driven environments, the critical question becomes, are the decisions themselves trustworthy? We are moving from validating components to validating autonomous outcomes in the physical world.
IDC projects over a 1 billion agents and over 217 billion agent actions by 2029. That scale introduces a new form of shadow IT, agentic, distributed and operating across edge environments and digital representations of physical systems. AI driven Identity Vulnerability Management (IdVM) platforms are appearing as a counterbalance to this new digital identity with a brain because AI itself is perhaps currently the only way of addressing identity vulnerability at machine speed and scale.
This starts pointing us towards where control must evolve, from the state of the asset to the quality of the action taken … ‘Was the decision correct, safe and within intent and can that decision be evidenced and explained?’ A quick check into your Security Operations and Security Operations centre will give you an insight into this. If they are watching what happened you need to consider how to move to validating what should be happening this demands a shift from static policy to dynamic guardrails … ‘You may act but only within these continuously validated boundaries’. As I wrote earlier on the evolution of the SoC.
The convergence of AI agents and IoT is creating autonomous cyber-physical systems unlocking significant value but also systemic risk. The opportunity is clear, move toward continuous validation of decision integrity not just device security. From securing infrastructure to assuring autonomous intent, authority and outcome at runtime, that is the control plane that does not properly exist yet, which is exactly where the opportunity sits.
Posted on May 4, 2026
0