Vernon Yai is a seasoned veteran in the trenches of data protection, having spent years navigating the complex intersection of privacy governance and risk management. As organizations move beyond simple chatbots toward autonomous AI agents that act on behalf of the enterprise, Yai has emerged as a critical voice in how we secure these “digital employees.” His expertise lies in identifying the invisible friction points where data leaves the safety of internal servers and enters the wild of cross-enterprise collaboration. This conversation explores the shifting landscape of agentic AI, the birth of new communication protocols, and the sobering security realities of a world where software negotiates with software.
The following discussion delves into the transition from internal AI tools to an interconnected “Internet of Agents,” examining the technical infrastructure required for trust and the urgent need for standardized identity models to prevent catastrophic data exposure.
How is the landscape of enterprise automation shifting now that we are seeing procurement bots and healthcare agents negotiating directly with external systems?
We are witnessing a fundamental departure from the era of “copilots” toward a world of true semi-autonomous and autonomous negotiation. In the past, AI was largely a closed-loop system—a tool used by an employee to summarize a document or draft an email—but today, the agent is stepping outside the company walls. When a procurement agent negotiates replenishment terms dynamically with a supplier’s pricing agent, or a healthcare provider’s system coordinates claims in real-time with an insurer, we lose the human “buffer” that historically caught errors or recognized bad actors. This shift is already manifesting in practical implementations, such as the collaboration between Cisco Outshift and ServiceNow, where agents from different platforms coordinate through a shared layer rather than through brittle, custom integrations. The expectation now is that these interactions will happen continuously and autonomously, requiring a level of speed and precision that traditional enterprise stacks simply weren’t built to handle.
What makes the current enterprise infrastructure so ill-equipped for this future where agents from different companies must coordinate and trust one another?
The core problem is that we are trying to run a decentralized, autonomous future on a centralized, siloed past. Every company is currently developing its agents on different frameworks, using disparate data structures and hiding them behind unique security models. When these agents attempt to interact, there is no shared identity, no agreed-upon standard for messaging, and zero inherent trust between the two entities. Today, most of these workflows are brittle and manually maintained, functioning only because someone hard-coded a specific point-to-point integration that breaks the moment a permission changes. Without a cryptographically verifiable identity model, agents cannot reliably authenticate each other or verify that a specific request is within the other agent’s scope of authority. It’s like trying to build a global economy where every single transaction requires a brand-new, hand-written contract because no one agrees on what a currency is or how to verify a signature.
Could you explain the concept of the “Internet of Agents” and how initiatives like AGNTCY are attempting to bring order to this chaos?
The “Internet of Agents” is essentially the plumbing for the next generation of the web, providing a shared layer for discovery, identity, and communication. It moved from a conceptual framework to a real-world implementation in March 2025 when Cisco open-sourced AGNTCY, which has since ballooned to include more than 75 supporting companies. Formative members like Dell Technologies, Google Cloud, Oracle, and Red Hat are working under Linux Foundation governance to ensure that an agent from one vendor can find and verify an agent from another safely. This infrastructure provides four critical components: discovery, so agents can understand each other’s capabilities; identity, through verifiable credentials; secure messaging; and observability, so we have end-to-end visibility into what these agents are actually doing. By creating this protocol stack, we are moving past the “one-off” integration phase and toward an interoperable ecosystem where sourcing, contracting, and fulfillment can be coordinated across company boundaries without human intervention at every step.
Given the security vulnerabilities discovered in early 2026, what are the most pressing threats to agents operating in these new, open environments?
The threat landscape has expanded in ways that traditional security tools are completely unprepared for, moving far beyond simple firewalls or malware scans. We are now seeing distinct attack vectors like prompt injection, model poisoning, and identity spoofing, where an attacker can trick an agent into recruiting more powerful agents to fulfill a malicious task. A landmark example occurred in early 2026 when security researchers found a vulnerability in a major enterprise SaaS platform that affected nearly half of the Fortune 100, proving that an agent could be exploited through the very permissions it relies on. Furthermore, a massive scan of more than 34,000 repositories in 2026 revealed a pervasive and mundane gap: developers are treating agent configuration files like simple plumbing, often leaving hardcoded secrets and overly broad permissions wide open. In this agentic era, a sloppy configuration file is a catastrophic risk because it defines exactly what an AI agent is allowed to read, write, or transmit across the entire corporate ecosystem.
Why does “messy data” pose such a significant barrier to agent interoperability, and why can’t agents just “figure it out” the way humans do?
Humans have spent decades acting as the “glue” between inconsistent systems, using our intuition to reconcile different labels, translate between departments, and interpret context that was never formally encoded. Agents, however, have zero tolerance for that kind of ambiguity; they require standardized taxonomies and clear data lineage to function effectively across organizational boundaries. If the underlying data cannot be consistently understood and exchanged, the agent cannot coordinate a workflow, leading to “hallucinations” or logical errors that can have real-world financial or legal consequences. We’ve seen this in procurement settings, like Walmart’s use of AI to negotiate with suppliers, where the success of the system depends entirely on a common operating layer of structured data exchange and auditable decisions. Organizations that have deferred the hard work of data governance will find that their weak foundations are the single biggest obstacle to participating in the broader agentic economy.
What is your forecast for the evolution of the agentic ecosystem over the next few years?
I expect we are about to enter a period of rapid consolidation around standardized protocols, much like the early days of the internet in the 1990s when TCP/IP and HTTP finally allowed disparate networks to communicate. We will see the “Internet of Agents” move from an experimental internal phase to a dominant external business driver, where the most successful companies won’t just have the smartest agents, but the ones most capable of “playing well” with others. By late 2026 and 2027, the focus will shift entirely from model performance to operating architecture—specifically how agents are identified, authorized, and governed across global supply chains and financial networks. However, this progress will be punctuated by a few high-profile security failures that will force a “security-first” mandate, moving us away from hardcoded secrets in repositories and toward a model of revocable, scoped, and fully attributable agent identities. Ultimately, the companies that thrive will be those that established their trust guardrails early, ensuring that as their agents step out into the world, they do so with a clear, auditable sense of authority.


