> ## Content Index
> Fetch the complete content index at: https://rootcauseview.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# How I’m mapping enterprise AI risk
- URL: https://rootcauseview.com/mapping-enterprise-ai-risk/
- Published: 2026-08-24T11:20:32.000Z
- Updated: 2026-08-24T11:27:42.000Z
- Description: As part of an AI transformation effort, I’ve been mapping the enterprise AI market. For risk, three layers are becoming clear: AI governance, agent identity, and content trust.
- Author: Ian Vale
- Tags: AI transformation, AI governance, AI, AI security

As part of an AI transformation effort at my company, I've been spending quite a bit of time mapping the market.

At first, I was mostly looking at the obvious layers: models, agents, developer tools, automation platforms, and the applications built on top of them.

But once AI starts moving from individual experiments into actual company workflows, another layer becomes more important.

**How do you manage all of this as an organization?**

The way I've started thinking about the enterprise control layer is through three fairly simple questions:

1. **Risk — what can go wrong?**
2. **Cost and assets — what are we spending, and what are we accumulating?**
3. **Effectiveness — is AI actually making us better?**

I'll cover each of these separately.

For this first post, I want to focus on the first one: **risk**.

The interesting thing is that "AI risk" quickly becomes too broad to be useful. While mapping the companies working in this space, I found it more useful to break it into three different problems.

**Can we control the AI itself?** 
**Can we control what agents are allowed to do?** 
**Can we trust the information AI creates and consumes?**

## 1\. AI governance and security

  
Companies need to know what AI systems exist, what models and applications are being used, whether they comply with internal policies and regulation, and whether those systems can be attacked or manipulated.

But governance and security are not exactly the same problem.

[*Credo AI*](https://rootcauseview.com/open-source-iot-platforms/) is a good example of the governance side. Its platform focuses on maintaining an inventory of AI systems, assessing risk, applying policies and controls, and mapping them to frameworks such as the EU AI Act, NIST AI RMF and ISO 42001\. It now extends the same model to agents, including agent registries, tools, data sources and deployment controls.

In other words, the question is less:

> Can someone attack this model?

> Are we allowed to deploy this AI system, under what conditions, and can we prove how it is governed?

Security products approach the same landscape from a different direction.

[Lakera ](https://www.hiddenlayer.com/?ref=rootcauseview.com)focuses heavily on runtime protection for generative AI and agents: prompt attacks, data leakage, unsafe inputs and outputs, and increasingly MCP and agent security. It also offers discovery and red-teaming capabilities.

[HiddenLayer](https://www.hiddenlayer.com/?ref=rootcauseview.com) takes a broader AI security lifecycle approach. Its platform covers discovering AI assets, scanning the AI supply chain, attack simulation and red teaming, and runtime protection that can monitor or block model inputs and outputs.

They overlap, but I don't see them as identical products.

**Governance asks whether AI should be allowed to operate.** 
**Security asks what happens when someone tries to make it behave badly.**

In practice, enterprises will probably need both.

## 2\. Agent identity

This is the category I find more interesting as agents become capable of taking actions rather than simply generating text. A chatbot mostly needs access to information.

An agent may need permission to:

- read a document,
- query a database,
- send an email,
- modify a ticket,
- call an API,
- deploy code,
- or trigger another agent.

At that point, the security problem begins to look surprisingly similar to identity and access management.

We already have mature systems for answering:

> Who is this employee?  
> What can they access?  
> Who approved that access?  
> When should it be revoked?

Agents introduce the same questions for identities that aren't people.

[Okta](https://www.okta.com/?ref=rootcauseview.com) is explicitly extending its identity model in this direction. Its AI-agent capabilities treat agents as identities with owners, scoped permissions, lifecycle management and audit trails, applying concepts such as least privilege that companies already use for human users.

[Token Security](https://www.token.security/?ref=rootcauseview.com) approaches the problem from the non-human identity side. It discovers agents and the credentials they use, maps ownership and permissions, monitors access over time and provides lifecycle and remediation controls.

[Astrix Security](https://astrix.security/?ref=rootcauseview.com) has been another notable company in this category, focused on discovering AI agents, MCP servers and non-human identities and controlling their access. Cisco acquired Astrix, and standalone sales of new Astrix licenses ended in June 2026, but I still find the company useful as a signal of where this market is going.

This layer feels fundamentally different from AI guardrails.

A guardrail might determine:

> The agent shouldn't send customer PII.

Identity control determines:

> This agent shouldn't have access to that customer database in the first place.

That distinction becomes much more important as agents start acting autonomously across several systems.

## 3\. Content trust

  
The third risk sits further downstream. Even if the AI system itself is governed and the agent has appropriate permissions, companies still have to deal with the information flowing through it.

**Was this text generated by AI?** 
**Was this image manipulated?** 
**Where did this media come from?** 
**Did sensitive information leave the organization?**

This is already splitting into several different technical approaches.

For text, [GPTZero](https://gptzero.me/?via=ilgeun&ref=rootcauseview.com) and [Copyleaks](https://copyleaks.com/?ref=rootcauseview.com) use detection models to estimate whether content was generated by an LLM. GPTZero provides document- and sentence-level AI detection, while Copyleaks provides AI detection alongside plagiarism and other content-integrity capabilities.

Turnitin applies similar AI-writing detection in an education and academic-integrity context and continues to update its detection model.

For media rather than text, [Reality Defender](https://www.realitydefender.com/?ref=rootcauseview.com) focuses on detecting AI-generated or manipulated audio, video and images. Its products are designed to put deepfake detection into workflows such as calls, meetings, identity verification and security operations.

There is also a different problem: preventing sensitive information from becoming part of the AI workflow at all.

[Private AI](https://privateai.com/?ref=rootcauseview.com) detects and redacts personally identifiable information from text, documents, images and audio, and can sit between enterprise data and an external LLM.

And then there is provenance.

[C2PA](https://c2pa.org/?ref=rootcauseview.com) isn't a product company. It is an open technical standard behind Content Credentials, designed to attach cryptographically verifiable provenance information to digital assets. Importantly, C2PA does **not** attempt to determine whether a piece of content is "true." It provides evidence about its origin and modification history that other systems or people can use when making that judgment.

---

The bigger takeaway from this market research is that AI transformation isn't only creating a new application layer. It is gradually creating **a new enterprise control plane around AI.** And the further agents move from *answering questions* toward *taking actions*, the more important that control plane becomes.

In the next two posts, I'll look at the other sides of the same map: **how companies measure whether AI is actually creating value, and how they track the cost and assets accumulating underneath it.**

## References

1. Credo AI — AI governance platform, registry, risk intelligence and agent governance.
2. Lakera — AI-native security for GenAI, agents and MCP environments.
3. HiddenLayer — AI discovery, supply-chain security, attack simulation and runtime security.
4. Okta — identity and lifecycle controls for AI agents.
5. Token Security — identity lifecycle and access governance for AI agents and other non-human identities.
6. Astrix Security — AI-agent and non-human identity security; now part of Cisco.
7. GPTZero — AI-generated text detection.
8. Copyleaks — AI text and content-integrity detection.
9. Turnitin — AI-writing detection for academic workflows.
10. Reality Defender — multimodal deepfake detection.
11. Private AI — PII detection, de-identification and redaction.
12. C2PA — technical specification for verifiable content provenance and Content Credentials.