As companies deploy increasingly autonomous AI agents, boards must ensure that management establishes clear accountability, limits agents’ authority and demonstrates that effective controls remain in place. At the same time, management should translate technical risks into business terms for directors, recommend clear boundaries for agents’ authority, and provide the board with the information necessary to evaluate the effectiveness of those boundaries and controls. This article, drawing on insights offered by experts from Zenity and Agent & Capital at the Cloud Security Alliance’s AI Security Summit 2026, offers practical guidance on what the board should know about the principal risks and best practices associated with agentic AI, how management should frame proposals and communicate with directors, and what questions boards should ask to evaluate security, controls and accountability. See our two-part series on AI agent security: “Companies See Rogue Incidents but Lag on Controls” (Mar. 18, 2026), and “What CISOs and GCs Need to Know to Defend the Enterprise” (Mar. 25, 2026).