Decentralized AI endpoints form an independent infrastructure layer that partially escapes traditional security and control mechanisms, thereby redefining governance models.
NIS2 makes personnel security a binding control requirement; Germany strengthens this through national regulations, requiring CISOs to systematically document and monitor their human risk management processes.
AI agents require not only monitoring but also enforced access controls with least-privilege principles, which proves significantly more difficult in practice than expected.