AI agents cannot be tamed with legacy government controls

ServiceNow’s Amit Zavery notes that there is a strategic mismatch between traditional slow-moving public sector governance systems and the velocity of AI development and deployment that needs to be addressed.

ServiceNow’s president, chief product officer, and chief operating officer, Amit Zavery, says that public agencies should build robust layers of security and risk management that operate on top of their existing, messy digital infrastructure. Image: ServiceNow.

There is a major dichotomy in the adoption of artificial intelligence (AI) by public sector organisations; many are trying to do so while using control frameworks built for a different era.


Explaining why this is problematic, ServiceNow’s president, chief product officer, and chief operating officer, Amit Zavery, says there is a strategic mismatch between traditional slow-moving bureaucratic governance systems and the exponential velocity of AI development and deployment.


Speaking to GovInsider, he adds that the speed associated with AI evolution is so high that even agile private sector companies “are having a difficult time” keeping up.


“When you extend that to [public sector] organisations which don't have the capability, capacity, or have not been thinking this way, it gets even more complicated”.


The core issue is not necessarily bad policies; rather, it is about traditional bureaucratic controls assuming human-paced systems and predictable change.


Zavery says that AI agents do not behave that way and “if you give access to them, unlike humans, they are relentless and can go after anything round-the-clock and even learn new pathways in which to get access”.


In this situation, compromised AI agents pose a serious risk. Even highly skilled human attackers have limits; AI does not, he adds.


For the public sector, this creates a profound “custodian’s burden”, says Zavery.


Governments are the ultimate repositories of society's most sensitive data, from national security assets to medical records.


Because of this high-stakes environment, visibility and governance must be a “first step” in AI deployment, rather than a post-script, he adds.


If an AI system is fully deployed without these guardrails, “it’s too late”.

Uncontrolled sprawl of agents


Zavery notes that this necessitates the need for immediate oversight over a new and often invisible threat: the uncontrolled sprawl of agents within government networks.


While shadow IT is a decades-old headache, agent sprawl represents a more dangerous evolution, he adds.


With AI agents increasingly embedded in software, they often enter government ecosystems without explicit approval or even the users’ knowledge, Zavery notes.


This creates what he calls a “sandbox illusion”.


In many agencies, AI is treated as an “experimental” tool, yet these agents often do not recognise the boundaries of a test environment; they behave as if they are in full production, often breaching sandbox boundaries to touch live data.


This hazard is compounded by the often informal, high-risk practice where individuals build and deploy their own agents within secure environments without permission.


Zavery warns that these “hidden” systems create significant security gaps.


Instead of letting individuals experiment in secret, he urges public agencies to create a central team that provides clear rules and oversight for how AI is used.


There is a need for a unified system that can track where AI is running across all government networks, he adds.


This allows leaders to keep an eye on how these tools operate and ensure they don't access sensitive information they should not.

Unifying data not a good idea


Zavery is sceptical of the ambition of several governments to fully unify data across the entire public sector for “better service delivery”.


He warns that this collides with harsh security and operational realities.


The sheer volume and speed at which information is now generated means that attempting to “clean the data first” before launching any projects is a recipe for stagnation, he says.


Instead of pursuing this unattainable goal of total centralisation, he urges public sector leaders to accept that data and AI tools will naturally be scattered across various systems.


The real challenge for the government is not eradicating this fragmentation but learning how to govern it effectively, he adds.


Zavery says that rather than fighting a losing battle against data sprawl, agencies should build robust layers of security and risk management that operate on top of their existing, messy digital infrastructure.


By shifting to a proactive mindset that is constantly monitoring vulnerabilities and adapting quickly, public sector leaders can maintain control and safety without sacrificing the agility needed to modernise services for citizens, he adds.


Zavery also links data unification directly to heightened cyber risk.


The priority, he argues, is not one grand, centralised database, but layered governance and exposure management that can span fragmented systems and decide “which one you can take risks on, which one you do not”, before attackers exploit the weakest link.

Who is responsible?


As AI becomes central to national infrastructure, the burden of responsibility is shifting, notes Zavery.


AI resilience is no longer a niche technical concern for the IT department; it is a mandate for heads of agencies and cabinet-level leaders.


When a breach occurs, Zavery advocates for a mature, “all hands-on deck” response model that unites vendors, system operators, and communications experts.


He notes that in a highly interconnected world, “trying to hide things” is a failing strategy that destroys citizen trust.


What this means is that institutional ownership means security is “no longer just the Chief Information Security Officer’s (CISO) problem”.


All layers of leadership must assume responsibility for a core that “changes every day”, ensuring the organisation learns and adapts after every incident rather than treating breaches as isolated shocks, says Zavery.

How to achieve success


He notes that nations that have successfully moved past “pilot mode” to achieve systemic AI adoption treat the technology as a societal shift rather than just an IT upgrade.


In this case, he adds that countries like Singapore and Estonia are great examples of “top-down, end-to-end” statecraft as far as adoption of AI is concerned.


These countries treat AI as a holistic transformation affecting training, revenue, and the broader private sector ecosystem, notes Zavery.


The key to their success is that the national government sets broad, shared standards regarding safety and transparency, while allowing individual agencies the flexibility to craft granular, context-specific rules for their unique domains, he adds.


This prevents a fragmented landscape of conflicting departmental policies while maintaining a coherent national direction.


Zavery observes that apart from government policy changes to accommodate AI, civil servants are also seeing a fundamental change in the way they do their work.


AI is stripping out the routine “drudgery” and taking care of “some of the soul‑crushing, painful things” in government roles. This is freeing officials for “more value add or much more strategic” work.


Zavery, however, stresses that public officers can’t remain passive users.


“You also have to be able to direct it, not just use it,” and understand what to hand over to AI and what to retain for human judgment.


This is easier said than done.

Don't wait for the next training course


Public officers cannot wait for the next training course to be posted on the intranet to develop these skills.


“You have to go out and train yourself; individuals will have to be very proactive,” he adds.


In his view, AI will not “take jobs” but will separate those who adapt from those who don’t.


“AI will make people who are not adopting unsuccessful, versus people who are adopting to be much more productive and successful,” he adds.


Zavery notes that ServiceNow offers public sector organisations an AI platform to manage and secure their digital operations at scale.


The company’s tools provide central visibility and control over AI use, including features like an AI control tower, exposure and security management across devices and cloud, and identity and lifecycle governance.


These capabilities, Zavery says, are designed to help governments adopt AI in a governed way, track return on investment (ROI), and avoid fragmented, ad hoc deployments.