Before You Let AI Act Within Your Facility, Ask These Four Questions
By David Strickland, COO of Kenton Brothers
For most of the last decade, artificial intelligence in physical security meant one thing: a smarter alert. A camera learned to tell the difference between a person and a swaying tree branch. An access control system learned to flag a badge used at two doors on opposite sides of a campus within the same minute. The technology got better at noticing, and then it handed the decision to a human being.
That handoff is now the thing changing. The most discussed topic in our industry this year is not a new camera or a new credential. It is agentic AI: security systems that observe a situation, decide what it means, and take an action without waiting for an operator to tell them to.
Manufacturers are calling 2026 a turning point. Some of the largest security services companies in the world signed reseller agreements for agentic platforms this summer. And at the same time, boards, insurers and regulators are asking a harder question than “does it work.” They are asking “who authorized it, and can you prove what it did.”
Both halves of that conversation matter to every enterprise we serve in Kansas City, across Missouri and Kansas, and beyond. Here is how we think about it.
What agentic actually means
The word gets used loosely, so it is worth drawing the line clearly.
Video analytics detect. They identify an object, a behavior or an anomaly and generate an alert. The person watching the screen still decides whether to lock a door, dispatch a guard or call law enforcement.
Agentic AI acts. Given a detection, the system can trigger a localized lockdown of nearby access points, escalate to a monitoring center with a summarized incident package, issue a live audio warning through a speaker, or dispatch a drone or robot to investigate. It can chain those steps together, adjust based on what it sees next, and close out the routine cases entirely so that a human only touches the ones that require judgment.
The promise is straightforward. No security team can watch every feed, verify every door alarm and catch every anomaly in real time. Alarm fatigue is a real operational risk, not just an annoyance. An agent that handles the ninety percent of events that are clearly nothing, and packages the ten percent that might be something, changes the math for a lean team.
Why the momentum is real
Three things are pushing this from concept to purchase order.
First, the manufacturers have committed. In this year’s industry roundtables, the major camera, access control and platform vendors all put agentic capability at the center of their 2026 roadmaps. That means the features are shipping in products our customers already own or are already evaluating.
Second, the infrastructure is ready. A manufacturer survey of more than 2,700 IT and security leaders published this month found that organizations running cloud-based physical security use AI at well over twice the rate of organizations running fully on-premise systems. That gap is not about cloud being magic. It is about where the compute lives and how quickly new capability can be turned on. Hybrid architectures, with edge devices on site and management in the cloud, are the deployment model that makes agentic response practical.
Third, the channel is moving. When global services firms sign agreements to resell agentic platforms, it signals that the demand is coming from enterprise buyers, not just from vendor marketing.
Why the guardrails matter just as much
Here is where we want to be direct with you, because this is where integrator experience earns its keep.
An agent that can lock doors can also lock the wrong doors. An agent that can issue a live warning can issue it to an employee retrieving a forgotten laptop. An agent that draws on video, access logs and identity data is an attractive target for anyone who wants to manipulate what it sees. These are not hypotheticals. Independent evaluations this year have documented that agentic systems are meaningfully easier to compromise through chained attacks than conventional tooling when they are deployed without hardening.
Regulators have noticed. As of this month, the EU AI Act’s obligations on record-keeping, human oversight and accuracy apply to high-risk systems, which includes biometric and critical infrastructure applications. In the United States, CISA, NSA and FBI published joint principles for integrating AI into operational technology late last year. And boardrooms are responding: roughly four in ten public companies now assign AI oversight to a named board committee, nearly four times the share of a year ago.
The practical translation for a security director is this. Before an agent is allowed to act on your facility, your organization should be able to answer four questions:
FOUR QUESTIONS TO ASK BEFORE AN AGENT ACTS
1. What is the agent permitted to do on its own, and what requires a human approval?
2. What record exists, after the fact, of what it saw, what it decided and why?
3. Who can override it, from where, and how fast?
4. How is the agent itself protected from being fed bad data or bad instructions?
If a vendor cannot answer those cleanly, the product is not ready for your environment, no matter how impressive the demo.
Where AI belongs in a security program
At Kenton Brothers we design every enterprise program around the KB Advantage Pyramid. The foundation is security policy and procedure. Above that sit high security physical hardware, detection, access control and video surveillance. Analytics and AI support sit near the top, and cyber hardening caps the structure.
That ordering is deliberate, and agentic AI makes it more important, not less. An autonomous agent is only as trustworthy as the data it acts on and the policy it is acting under. If your door hardware is inconsistent, your access control database is full of stale credentials, or your camera coverage has gaps, an agent will make confident decisions on bad information. And if the network carrying all of that is not hardened, the agent becomes the most powerful tool an intruder could ask for.
This is exactly why we built our CYPHY cyber and physical convergence practice. A door controller that is now co-owned by IT and can trigger automated responses is part of your attack surface. It needs to be treated that way from the first site survey.
How we recommend approaching it
For most of our enterprise customers, the right path is not to flip the switch on full autonomy. It is a staged progression:
• Start with detection you trust. Deploy the analytics, tune them against your actual environment, and measure the false alarm rate. Agentic response layered on top of noisy detection just automates the noise.
• Define the autonomy envelope in writing. Decide, with your security, IT, legal and operations leaders in the room, which actions the system may take without a person and which it may only recommend. Put it in your security policy, which is where the pyramid starts.
• Turn on narrow autonomy first. Let the agent handle the lowest risk, highest volume events: after-hours motion in an empty lot, a propped door that closes on its own, a tailgating alert that resolves on the next badge read. Watch the logs. Expand from there.
• Keep the human loop visible. Whether that is your own operators or a monitoring partner, someone should be reviewing the agent’s decisions on a cadence, not only when something goes wrong. Managed service programs like our SecureCare portfolio exist in part to make that review sustainable.
• Harden before you automate. Network segmentation, credential hygiene, firmware management and secure remote access are prerequisites, not follow-ups.
The bottom line
Agentic AI is going to be part of enterprise physical security. The capability is real, the vendors are shipping it, and the operational case for lean teams is strong. The organizations that get value from it will be the ones that treated it as a program decision rather than a product feature: clear policy, clean data, hardened infrastructure, and a human who can always answer for what the system did.
That is the work we have been doing for enterprise customers for 129 years. The tools change. The standard does not.
LET’S TALK
If you are evaluating agentic capability in your current platform, or a vendor is pitching it to you, we are glad to walk through the four questions above against your specific environment. Reach out to your Kenton Brothers security consultant or contact us at kentonbrothers.com.



Leave a Reply
Want to join the discussion?Feel free to contribute!