Before connecting AI agents to critical systems, companies must address who controls them, what they can do and how their activity will be tested, monitored and reviewed.