
Download Transcript (pdf)
AI Governance Has a Missing Layer: Trust
AI governance cannot stop with a policy document.
AI governance usually operates at one of two levels. At the top, frameworks and policies define how AI should be used. At the bottom, security controls manage identities, permissions, data access and system behavior.
The difficult part is what happens between them, where an autonomous agent interprets an instruction, makes a decision and attempts to act.
In this episode of ClearTech Loop, Jo Peterson speaks with Elliott Mattice, founder of Exprima and a cybersecurity executive with more than 25 years of experience across federal IT operations, compliance and regulated environments. Elliott believes trust is the missing operating layer—not trust as a vague principle, but as something organizations continuously measure and use to determine what an agent should be allowed to do next.
Listen to Jo Peterson and Elliott Mattice discuss AI governance, agent accountability, behavioral trust and the evolving role of MCP servers. Listen to the full episode: https://www.buzzsprout.com/2248577/episodes/19490397
Watch more ClearTech Loop episodes:
https://www.youtube.com/@ClearTechResearch
Episode Overview
Organizations are moving quickly to adopt copilots, agents, plug-ins and other AI-enabled tools. Governance efforts, however, are still often centered on acceptable-use policies, approved-tool lists and oversight committees.
Those measures matter, but they cannot determine whether an agent should be allowed to take a specific action at a specific moment.
Billy and Jo discuss why identity must become the control plane for agentic AI. Every action should resolve to an identifiable user, service or approved process with clearly defined authority.
As Billy explains:
“AI is not eliminating risk; it’s amplifying the consequence of weak controls.”
The Three Questions We’re Asking
The episode also explores why agent permissions need to be constrained, why authorization should be checked when an action is executed and why third-party MCP servers should be treated as part of the broader technology supply chain.
Listen to Jo Peterson and Elliott Mattice discuss AI governance, agent accountability, behavioral trust and the evolving role of MCP servers.
Episode link: https://www.buzzsprout.com/2248577/episodes/19523689
Listen to the Full Episode
- How do we operationalize AI governance?
- Who is accountable when an AI agent makes an unauthorized decision?
- How do we prevent agents from performing actions the user should not be allowed to perform?
AI Governance Cannot Stop at Policies and Guardrails
Traditional cybersecurity was built for predictable systems. Ports, protocols, access lists and identities can be controlled because organizations generally understand what those systems will do with a particular input.
AI agents are different. They interpret language, make decisions and take actions across connected systems. Their behavior is non-deterministic, which makes static policies and one-time permission checks inadequate.
Elliott’s model places behavioral trust between security and governance. An agent’s trust would be evaluated continuously based on whether its actions remain within an expected range. If its behavior crosses a boundary, its trust score drops and its access changes.

Accountability Still Lands With a Human
When an AI agent deletes data, changes production code or takes an unauthorized action, saying it went rogue describes the incident. It does not resolve accountability.
Someone selected the system, established its permissions, approved its deployment and determined where human oversight would be required. Elliott’s answer is direct: “It always, in my mind, has to land with a human being.”
Autonomy does not erase the chain of responsibility. It makes that chain more important because organizations are deliberately removing humans from portions of the workflow.
The MCP Server Can Be More Than a Bridge
MCP servers are often described as bridges connecting AI agents with tools, data and enterprise systems. Elliott offers another way to view them: as enforcement points.
Before granting access to Slack, a database or another resource, the MCP layer could evaluate the agent’s identity, permissions, recent behavior and current trust level. If the agent no longer meets the required threshold, the server could limit or deny the request.
This moves enforcement outside the agent itself. Controls embedded inside an autonomous agent may not be sufficient; independent systems still need the authority to say no. It is defense in depth applied to systems that make decisions instead of simply following instructions.
Trust Must Change What the Agent Can Do
A behavioral trust model sounds straightforward: observe behavior, compare it with established boundaries and adjust access accordingly. The difficult work is deciding what to measure, where thresholds should be set and what an agent must do to regain access after crossing a boundary.
A trust score is only meaningful if it changes what the agent can actually do. Governance cannot live only in policy documents, and security cannot depend entirely on guardrails embedded inside the agent. Enforcement must exist across the environment—at the identity layer, the tool layer and every point where an agent attempts to turn a decision into an action.
Trust should be earned, monitored and capable of being revoked. That applies to people. It should probably apply to AI agents too.
About the Guest | Elliot Mattice
Billy Spears is a technology and cybersecurity executive with more than 25 years of experience across information security, IT, software development, privacy and business operations.
He has held executive roles at organizations including Dell, Hyundai and LoanDepot and has served as an adjunct professor of cybersecurity. Billy currently advises executives, boards and investors on AI adoption, cybersecurity risk, cloud strategy and technology transformation while building a stealth cybersecurity startup.
He is also a speaker, author, investor, board advisor and U.S. Marine veteran.
Additional Resources
- The USB Problem for AI: Phil Stafford on Agents, Governance and MCP Risk
Phil Stafford examines AI agent permissions, identity, governance and the security risks created by MCP connections.
https://www.buzzsprout.com/2248577/episodes/19387427-the-usb-problem-for-ai-phil-stafford-on-agents-governance-and-mcp-risk
- CMMC 2.0: Three Upstream Signals Most Organizations Missed
Elliott Mattice explains how policy details can reveal enforcement priorities before they become operational requirements.
https://elliottmattice.work/cmmc-upstream-signals/
- Upstream Risk Translation
Elliott outlines his frameworks for translating policy, geopolitical and incentive signals into actionable risk decisions.
https://elliottmattice.work/
Stay in the Loop
Subscribe to the ClearTech Loop newsletter for new conversations on AI security, governance, cloud strategy and cyber risk.
https://www.linkedin.com/newsletters/7346174860760416256
Watch full episodes and subscribe to ClearTech Research on YouTube.