DXC and Primary Build Action-Level Security for AI Agents
Dawn-Marie Vaughan explains why enterprises need granular governance that controls what autonomous systems do, not just who they are.
Controlling what AI does, not just what it accesses
As AI agents move from pilot projects into production workflows, enterprise security teams confront a fundamental shift: these systems don't just retrieve information—they invoke tools, coordinate processes, and execute decisions at machine speed.
Dawn-Marie Vaughan, Global Cybersecurity Business Leader at DXC Technology, argues that traditional Zero Trust frameworks remain necessary but insufficient. "The issue is not whether an agent can authenticate," she told Cyber Magazine. "The issue is whether it should be allowed to take a particular action, with particular data, through a particular tool, all at that precise moment."
DXC and Primary are partnering to address that gap with what they describe as an AI-native Zero Trust approach—one that governs agent behavior at the decision level rather than relying solely on identity verification and perimeter controls.
Why identity alone doesn't secure agentic systems
Vaughan points to a structural problem: AI agents can present valid credentials and still take unsafe or unauthorized actions. "An agent can reason at runtime, use legitimate tokens, call multiple tools and take actions that appear individually normal but are collectively very risky," she said.
Traditional security models assume activity traces back to a person, a stable application, or a predictable service account. Agents are none of those. They operate across boundaries that legacy products weren't designed to manage, making repository-level access or blanket permissions a liability.
The partnership aims to enforce policy at the interaction layer—evaluating every prompt, response, tool invocation, and data exchange against business context and compliance requirements before the agent executes.
How DXC and Primary plan to scale governed AI
Primary provides the control layer for AI actions. DXC integrates that capability into clients' existing security estates—identity systems, network controls, cloud infrastructure, and SOC operations—without requiring wholesale replacement.
"We are not asking clients to rip and replace their security estate," Vaughan said. "We are giving them a way to make it work as one governed system—especially where AI is now crossing boundaries that legacy products were never designed to manage."
The model assigns each agent a distinct identity, applies attribute-based policy, enforces access at the session layer, and records the full transaction—prompt, response, tool call, and data movement—as auditable evidence. Vaughan describes this as making control "programmable," allowing organizations to define agent mandates, codify policy, and enforce decisions automatically at runtime.
Why it matters
Enterprise AI adoption hinges on whether organizations can govern hundreds or thousands of agent interactions without manual security review for every workflow. Action-level governance shifts the security question from "Is this agent trustworthy?" to "Is this specific action, at this moment, authorized?" That distinction becomes critical as agents gain autonomy and operate at speeds that make human oversight impractical. The approach also addresses compliance and audit requirements by creating decision-level evidence for every interaction.
Details of the partnership and Vaughan's comments were first reported by Cyber Magazine.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call
