AI coding agents are increasingly doing real enterprise software development work, but most organizations are deploying them without the governance infrastructure needed to manage the risks. Key recommendations include restricting network access by default, running agents in temporary controlled environments rather than developer laptops, using delegated identity rather than shared API keys, applying least-privilege tool access, and maintaining clear human accountability for agent-generated work. The core argument is that agents should be treated as production infrastructure with mature identity, audit, and access controls — not as experimental features.