7 min readAI Agents · Cybersecurity
Your First 90 Days With AI Agents
By Michelle Savage, Experience Design Director, PayPal

TL;DR: You don't have to pick between speed and safety on your first AI agent. Find the AI you already have and choose one contained internal use case. Build the boundaries in from day one. Ninety focused days gets you one secure working agent that becomes the template for every one after it.
Last updated October 6, 2026. This piece was rebuilt from the ground up as a 90-day plan, with the real wins and faceplants that shaped it.
Every executive says a version of the same thing: we need agents fast, but we can't afford one going rogue. They've seen the headlines. Zillow's AI overpaid for houses and cost the company hundreds of millions. A dealership chatbot agreed to sell a truck for a dollar. Air Canada got dragged into honoring a refund policy its own bot invented. Each one worked exactly as designed, and none worked as intended. The part nobody tells them: the fix isn't slowing down. It's building the guardrails in from the start.
Can you ship an agent fast without it going rogue?
Yes, and building security in is what makes it fast. A retail leader we'll call Mary came in under pressure: a competitor was using agents to optimize delivery routes, and her CISO said security review alone would take six months. Her first agent was designed with never trust, always verify as its core instead of a gate bolted on at the end. The security review took 3 days. The agent was live in 3 weeks.
It now handles route optimization for 900 store-to-home deliveries a day, making hundreds of autonomous decisions inside clear limits, with zero security incidents and zero unauthorized actions. Think of it like raising a teenager and the car keys. You don't hand them over and set the rules later. You set boundaries first, then expand freedom as trust gets earned, the same model as onboarding your agent like an intern.
How do you find the AI you already have?
Assume you have more than you think, then go looking. A partner named Sean was sure his firm had zero agents. A closer look turned up 12: marketing generating content, sales running a lead-scoring bot, facilities tuning the HVAC. None fully autonomous yet, all candidates.
Start with one email: what tools are you using that make decisions or predictions, and what tasks do you wish could run without your constant input? Then dig. Check expense reports for AI subscriptions. Look in Slack and Teams for bot integrations. Review API logs for calls to AI services. Build a simple spreadsheet with the tool name, what it does, what data it touches, who owns it, and the damage if it goes wrong. Declare a Shadow AI Amnesty Week so teams register unofficial tools without getting in trouble. Your people aren't creating risk on purpose. They're trying to kill busywork, so help them do it safely. The full discovery play is in the shadow AI playbook.
How do you pick the right first agent?
Choose one important enough to count but contained enough to control. Score each candidate from 1 to 5 on business impact, autonomy potential, boundary clarity, data availability, risk containment, and how visible success will be. The best first agents are internal and rule-based.
Good first agents | Save for later |
Purchase-order approval | Customer-facing pricing |
Meeting scheduling | Healthcare diagnosis |
Inventory reorder | Financial trading |
IT ticket routing | HR termination decisions |
Expense-report review | Anything your CEO wants to show off at a conference |
The left column has clear rules and contained risk, with built-in audit trails. Mary picked last-mile delivery routing because the rules were clear: minimize time and fuel, respect driver preferences, stay legal. The agent could recommend routes and drivers could override. That's the balance you want on a first try.
What trips teams up in the first 90 days?
Old systems and dirty data, more than anything technical. About 45 percent of organizations hit an integration wall: the 20-year-old ERP with no API, the customer database that needs 17 permissions to read, the procurement system that only updates at midnight. The teams that win phase the integration, getting one system working perfectly before adding the next. One leader's team spent two months just mapping how their systems talked to each other. Boring work, and then their first agent went live in 2 days instead of 2 months.
Then the data. You think yours is clean until an agent starts using it and you find customer names spelled six ways and SKUs that don't match. Governance first, agents second.
Four traps kill most rollouts: building agents without boundaries, trusting without monitoring, treating autonomy as all-or-nothing, and spending four months on a 200-page governance document. One financial firm did exactly that last one while a rival shipped three agents in the same window using one-page charters. Documentation counts. Shipping counts more.
What can you do this week to start the clock?
Send the AI discovery email
and start your inventory.
List your top 5 agent candidates
and score them on the six criteria.
Name one agent owner
who thinks like a manager and asks how this could go wrong.
Write a one-page charter for your first agent:
what it does and what it must never do. The five questions in
are the charter's skeleton.
Give existing AI tools unique credentials and turn on logging now,
before you build anything new.
The goal for day 90 isn't to be the company running 47 agents. It's one clear win: a single agent, tight boundaries, measurable value, and enough confidence to keep going. Sean's second agent, automated vendor-payment approval, went live in 18 days and caught three duplicate invoices humans had missed. The first one is the template. The rest get cheaper.
Frequently asked questions
What's the best first AI agent to ship?
An internal, rule-based agent with a contained blast radius. Purchase-order approval, inventory reorder, IT ticket routing, and expense review all work because the rules are clear and a mistake stays small. Avoid anything customer-facing or safety-critical until the model is proven.
Why not ship several agents at once?
Because you'll drop something important. Securing several agents at once splits your attention across authentication, monitoring, logging, and shutdown for each one. Get a single agent perfectly right first. That work becomes a template, and each later agent takes a fraction of the time.
Was Zillow's AI failure preventable?
Largely, yes. The model overpaid for homes it couldn't resell at a profit, and the losses compounded before the business changed course. Tighter limits on what the agent could commit to, plus monitoring that caught the drift early, would have contained it. The agent did its job. The limits around it were too loose.
Do we need a separate security team to review agents?
No, and separating them usually backfires. Security becomes a bottleneck at the end instead of a design input at the start. Build one team that creates secure agents from day one, with a compliance partner embedded rather than gating. Security works best as a mindset, not a final checkpoint.
Key takeaways
Speed versus safety is a false choice. Boundaries built in from day one made Mary's security review 3 days and her launch 3 weeks.
You have more AI than you think. One email, expense reports, chat integrations, and API logs will surface it, and an amnesty week gets it registered.
Pick a first agent that's internal and rule-based, with a contained blast radius. Score candidates on six criteria before choosing.
Old systems and dirty data stall more rollouts than any security concern. Phase the integration and clean as you go.
One-page charters beat 200-page governance documents, because the rival with charters ships while you're still writing.
Before you pick your first agent, see where the ones you already have stand. The free self assessment takes about ten minutes and shows you what to close first.
The choice was never speed versus safety. It's whether you lead this rollout or scramble to catch up after a headline, and ninety focused days is enough to be on the right side of that.