How to Address Security and Governance Challenges for Coding Agents (Ai4 Conference)

By Vladimir Tsakanyan

The rapid rise of coding agents such as Claude Code and Codex is changing not only how software is built, but also how organizations think about control, accountability, and risk. What started as a productivity boost for developers has become a broader governance issue, because these systems increasingly operate with access to codebases, tools, and enterprise infrastructure.[swapcard +1]
That is why the AI4 2026 session “How to Address Security and Governance Challenges for Coding Agents” is so timely. The talk, featuring Sheng Liang, CEO and Co-founder of Obot AI, reflects a larger shift in the industry: coding agents are no longer just assistants, but delegated actors inside the enterprise.[obot +1]
The new governance problem
Traditional IT security was built around human users, defined roles, and predictable software behavior. Coding agents challenge that model by combining autonomy, external tool access, and conversational interfaces that can be misused, over-permissioned, or manipulated.[cloudsecurityalliance +2]
This creates a governance gap that is both technical and political. Whoever defines the rules for agent identity, access, logging, and approvals will shape the balance of power between security teams, developers, business users, and platform vendors.[cloudsecurityalliance +1]
Why this matters politically
The political significance of coding agents is that they blur the line between software and delegated authority. If an AI agent can access repositories, call APIs, modify code, or interact with production systems, then it is no longer just a tool; it becomes part of the organization’s decision-making structure.[recordedfuture +1]
That shift raises familiar policy questions in a new form: who is responsible when something goes wrong, what level of autonomy should be allowed, and how much control should remain with humans versus automated systems. These are not only cybersecurity issues; they are questions of institutional power and accountability.[cloudsecurityalliance +1]
What security teams need
According to the AI4 session description, IT and security teams need stronger identity and access controls, better visibility into agent activity, tighter governance over tool and MCP server access, and reliable audit trails for usage and cost management.[swapcard]


Discover more from Center for Cyber Diplomacy and International Security

Subscribe to get the latest posts sent to your email.

Discover more from Center for Cyber Diplomacy and International Security

Subscribe now to keep reading and get access to the full archive.

Continue reading