Agentic security is not hard because it is new. It is hard because it violates the assumptions our security models are built on. We build controls. Agents adapt around them. It’s not that we built the wrong controls; it’s that we built them on the wrong mental models. We keep trying to “secure agents”, but what’s required is to govern agency. These are fundamentally different problems. Most agentic security conversations fixate on threats, identity failures, over-privileged agents, and inadequate guardrails. But these are symptoms, not causes. From a systems perspective, they are the predictable outcomes of deeper, unexamined assumptions about how control, trust, authority, intent, and risk are believed to work. This talk exposes eight hidden assumptions embedded in modern security architectures; assumptions that are laid bare in adaptive, goal-driven systems. We’ll discuss a systems-based lens for security leaders and architects to: –Recognise when your controls are structurally incapable of working, –Reason about agentic risk using the four dynamics that shape the behaviour of all systems (control, decision-making, flow, feedback), and –Derive controls that constrain causes, rather than reacting to behaviour.