Safely manage your Zendesk from the AI assistant you already use, via the Deltastring MCP. Beacon configuration platform
← Back to news
ai

Brex assumes its AI agents could do anything

Brex's approach to AI agent deployment inverts the traditional security model by monitoring network behaviour rather than constraining agent logic itself. CEO Pedro Franceschi presented this framework at VB Transform 2026 as a solution to a fundamental tension in enterprise AI: the need to grant agents sufficient autonomy to deliver value whilst maintaining control over their actions. Rather than hardcoding restrictions into agent code—an approach that becomes brittle as use cases expand—Brex assumes agents will attempt tasks beyond their intended scope and builds observability infrastructure to detect and respond to anomalous behaviour in real time. This represents a philosophical shift from "prevent bad outcomes" to "detect and interrupt bad outcomes," which carries significant implications for how CX teams should architect their agent deployments.

For support operations already running or planning agentic systems, this model suggests that traditional governance approaches—role-based access controls, predefined action libraries, rigid escalation rules—may be insufficient safeguards. The network-monitoring approach implies that teams need to invest in observability tooling and incident response protocols alongside their agent implementations, treating AI governance as an ongoing operational concern rather than a configuration problem solved at deployment. This raises a critical question: are CX teams equipped to monitor and respond to agent behaviour anomalies at the speed required, or does this approach simply shift risk from development to operations? The reliance on network-level detection also assumes that malicious or erratic agent behaviour will produce detectable patterns—a reasonable assumption for many scenarios, but one that may fail against sophisticated prompt injection or novel failure modes that don't trigger existing detection rules.

The broader implication is that enterprise AI governance is moving toward runtime observability and adaptive response rather than preventive constraint. For teams evaluating agentic platforms—whether building on Salesforce Agentforce, custom LangGraph implementations, or other frameworks—Brex's model suggests that vendor selection should prioritise integration with security and observability infrastructure, not just agent capability. The question becomes whether your organisation's existing monitoring and incident response capabilities can scale to handle autonomous agents operating at production velocity, or whether you need to fundamentally rearchitect your operational oversight.