Enterprise AI agents can run inside the security, identity, compliance, and audit systems that companies already use.
2
IT teams can manage AI agents like employees by creating accounts, setting permissions, applying policies, and monitoring activity.
3
Email and other existing enterprise tools can give agents observable ways to communicate without adding new portals and credential systems.
Summary
Steven Moon argues that enterprise AI should use the infrastructure companies already trust instead of creating a parallel stack of portals, credentials, security reviews, and monitoring tools. He compares AI agents to employees: they should have accounts, permissions, approved systems, data boundaries, and audit records. Private clouds, identity management, governance controls, compliance frameworks, and existing APIs already provide much of what deployment requires. Moon describes email as one practical way for agents to communicate because messages can be logged, permissions can be enforced, and data flows can be inspected. He also points to Microsoft 365, ERP systems, document management, internal messaging, and workflow tools as places where agents could add capabilities. The talk's central proposal is to ask which existing systems can be enhanced with agents before building a new interface.
Moon says software can now understand human requests, interpret context, and interact through channels that people already use. He sees large language models as enabling applications that communicate more directly with users. This changes the role of the interface because an agent may be able to work through an existing business system instead of requiring a separate product screen. The benefit depends on deploying the agent inside the organization's normal workflows, where users already know how to work and where the organization already has controls.
New AI portals repeat an outdated deployment pattern
Moon criticizes the tendency to make every AI agent another external system with its own portal, credentials, and security review. He connects this pattern to Satya Nadella's statement that SaaS is dead, meaning that traditional business software interfaces may no longer be the main way people interact with systems. Building more dashboards and portals adds translation layers at the moment when software can understand requests directly. Moon asks teams to consider whether an agent can deliver its capability through a system users already know and trust.
AI agents should receive the controls given to employees
Moon says agents should follow security policies, use approved systems, stay within data boundaries, access only what they need, and undergo monitoring and audits. He compares this to how organizations manage human employees. Enterprises already have secure compute environments, identity management, data governance, compliance frameworks, and audit capabilities. Many also have private clouds where agents can run without leaving the organization's security boundary. Moon's point is that the technology and operating controls for private deployment already exist.
Existing enterprise platforms can carry their security into agent systems
Moon describes Microsoft 365 and ERP systems as platforms that companies have integrated into their security and compliance programs over many years. Building agents on those platforms allows teams to reuse that work. He says IT departments can create agent accounts with existing Active Directory tools, apply standard policies, set permissions, and use familiar audit and monitoring tools. This makes agent administration resemble employee administration, so teams do not need a separate operating model for every new agent.
Email can make agent collaboration visible and controllable
Moon presents email as a way for agents to communicate with one another. Agents can send information and coordinate work through a channel that organizations already understand. Each interaction can be logged and audited, while existing permissions can control access. The resulting data flows are visible and manageable. Moon says Aech AI uses Microsoft's ecosystem, but he believes the same pattern can work with Google Workspace and other enterprise platforms. Email is an example of using a trusted system instead of creating a new agent communication layer.
The right starting point is usually an existing business system
Moon says teams should spend their effort on new capabilities and problems instead of rebuilding infrastructure that already provides identity, security controls, compliance processes, and enterprise APIs. He names document management systems, internal messaging platforms, and workflow tools as possible places for agent features. Since agents can understand human intent, those systems can become entry points for AI capabilities. The design question changes from which new tool to build to which trusted system can be improved with an agent.
"Enterprise AI agents should work like any other employee following security policies using approved systems staying within data boundaries accessing only what's needed and being monitored and audited just like human employees."01:53
Who should watch
You are designing enterprise agents and keep adding separate portals, credentials, and security reviews to each deployment.
Your IT or security team needs an operating model for agent accounts, permissions, monitoring, and audits.
You want to add agents to email, document management, messaging, or workflow systems that your organization already controls.