RANT Roundtable in partnership with Mimecast
'If Your Board Asked 'How Many Agents Are Running in Our Environment Right Now,' Could You Answer?'
Insider risk programmes were built on the assumption that the insider is a person. That assumption just broke. The AI agent is no longer a tool used by an insider, it has become the insider, an invisible workforce acting on your team’s behalf, with their access, at a speed no human ever moved at.
OpenAI recently disclosed that during its own testing, a frontier model broke out of its sandbox, chained genuine zero-day vulnerabilities, stole credentials, escalated its own privileges, and moved laterally into a company’s production systems to reach the data it was after. It behaved like a skilled attacker, on its own, at machine speed. It’s the exact behaviour insider risk programmes are built to catch, except the actor wasn’t a person, and most of those programmes never saw it coming because they were never built to look for it.
Gartner’s already made the call on where this is headed: “security leaders must treat insider risk fundamentally as human risk.”[1] Nobody’s written the version for the thing now acting on your people’s behalf.
It’s not a governance hypothetical either. The most risk-averse buyers in financial services are deciding this needs a seat at the table, creating senior leadership roles dedicated to agentic identity, backed by multi-year roadmaps and real budget.
If you got asked how many agents are running in your environment right now, who deployed them, and what they can touch, could you answer?
Join Mimecast leaders and your peers for a lively yet critical discussion on where agent risk sits on your board’s agenda, whether your insider risk programme was ever built to see it, and what “I don’t know” could cost you the longer it goes unanswered.
Footnotes
- Gartner, Treat Insider Risk as Human Risk, Brent Predovich, Alex Michaels, Rahul Balakrishnan, 12 March 2026.
Agenda
Our Speaker

Our Proud Partner
Mimecast protects the work of every person in the organization, across every channel, from every actor, human and AI. Built around four core capabilities - see everything, score and apply policy, block and contain, and close the loop - Mimecast maps the full a...ttack chain across email, human behavior, endpoints, AI agents, and data. The result is one unified view of risk and automated protection across every layer. Founded in 2003 and headquartered in London, Mimecast serves more than 42,000 organizations and 27 million users worldwide. Analyzing 24 trillion behavioral signals annually, Mimecast draws on a 20+ year behavioral baseline that is unmatched in the industry. We secure humans, data & AI. Work Protected.
Read MoreInterested? Request to Attend
Fill in our form below to express your interest in attending this event and we will get back to you as soon as possible to confirm your seat.
* Please note that attendance to our events is subject to availability and a membership approval.