Enterprise AI deployments have passed a threshold that most security frameworks were not designed for. Agentic AI - autonomous, tool-using systems that chain actions, delegate to sub-agents, and operate continuously on behalf of users - is already in production across a growing number of organizations. Existing approaches, including KuppingerCole's own Generative AI Defense (GAD) Leadership Compass, address one important slice of the problem but leave gaps in identity governance, compliance, and orchestration-layer controls.