Does every modern software system need an Agent Smith?

10 min read

Imagine you are sitting in the chair opposite Morpheus. The room is quiet. He leans forward.
“What is the Matrix? Control.”
For those growing up in the late 90s and early 2000s, The Matrix wasn’t just another sci-fi movie, it was a cultural phenomenon. It explored the idea of intelligent machines in a way that was both unsettling and captivating. AI was not a part of everyday conversations, it was not very clear how it actually works. But the story worked because it felt believable enough to suspend disbelief. And it stood the test of time.
For those unfamiliar with The Matrix, it tells the story of a simulated reality created by intelligent machines after they won a war against humanity. While people believe they are living ordinary lives, their minds exist inside this virtual world. Their bodies remain unconscious in vast fields of pods, harvested by the machines as a source of energy. It is a dystopian vision of AI taken to its extreme.
From Science Fiction to Agentic Reality
Fast forward more than 20 years, AI is no longer science fiction. It is becoming part of every modern software system. More importantly, we are entering the era of agentic AI, where software doesn’t just answer questions but plans, decides and acts on our behalf. The promise is compelling: automate repetitive workflows, reduce human error and free people to focus on higher value work.
But every leap in technology introduces a new challenge. The question is no longer whether AI agents can perform autonomous actions. They clearly can. The real question is:
- Who governs those actions?
- Who decides what an agent is allowed to do?
- What it should never do and how its decisions are monitored and constrained?
The excitement around agentic AI isn’t just hype. Gartner’s May 2026 report estimates that adoption is accelerating, with organizations embedding autonomous AI capabilities into business workflows at high pace. By the end of 2026, Gartner expects 40% of enterprises to incorporate agentic AI into their workflows, up from just 5% in 2025. But adoption is only the first step. Moving from a successful proof-of-concept to a production-ready system is where many organizations struggle.
Despite increasing investment, Gartner predicts that more than 40% of agentic AI projects will be cancelled by the end of 2027. The reasons are quite telling: unclear business value, escalating operational costs and, perhaps most importantly, weak governance.
Of these challenges, governance is the one that underpins all the others. Enterprises are comfortable automating decisions only when they understand the boundaries within which those decisions are made. The more autonomy an agent has, the more important it becomes to define what it can do, what it cannot do and who remains accountable when something goes wrong.
The Matrix as a Controlled System
The Matrix operates under the same fundamental challenge that modern AI systems now face: control at scale. It is designed as a tightly governed environment where human experience is simulated, constrained and carefully shaped. People inside the system believe they have freedom of choice, but those choices ultimately exist within predefined boundaries established by the system itself.
To maintain this order, the Matrix relies on Agents. If humans are ordinary users within the system, then Agents are privileged processes – software with elevated, system-level permissions.
Their role is not subtle. They are there to hunt and eliminate anyone who threatens the stability of the Matrix, enforce its rules and prevent humans from waking other humans up from the Matrix.
Among them, Agent Smith stands out as the most recognizable embodiment of this control layer. He represents order, predictability and enforcement inside the Matrix. He is an automated governance mechanism ensuring the system behaves exactly as designed.
Human vs Agentic Behavior at Scale
Back in the real world, the question still stands: who will control the agentic AI, and how?
Controlling agentic behavior in a complex software environment is fundamentally different from controlling human behavior. The distinction is not about intelligence or intent since both humans and AI agents are capable of mistakes, and neither is inherently malicious.
The difference lies in scale, speed and system impact.
Humans operate at a limited pace and within natural cognitive and operational constraints. This creates an implicit form of governance: people self-regulate when they are not acting maliciously and even when they do make mistakes or act with intent the resulting damage is typically bounded and detectable before it spreads too far.
Agents operate at machine speed and scale. They can execute decisions continuously, in parallel, across interconnected systems, potentially performing millions of actions in very short time. The core challenge is not their intelligence, but their concurrency and autonomy within the system.
A single flawed instruction or misaligned objective can propagate instantly across workflows, amplifying what would otherwise be a minor human error into a systemic failure. In this context, governance is no longer about identifying malicious actors, it is about constraining the blast radius of inevitable mistakes before they spread.
Agentic Systems Require Zero Trust
This leads to a clear conclusion: agentic systems require zero-trust principles by default.
Unlike humans, agents do not operate under natural constraints such as fatigue, organizational friction or social accountability. These limitations, imperfect as they are, act as informal governors of human behavior. Agents have none of these safeguards. As a result, the more capable and successful they become, the more potential they have to cause systemic harm at scale.
To manage this, we must apply a governance model similar to the role Agent Smith plays within the Matrix: strict, continuous enforcement of system integrity under zero trust assumptions. Practically, this means agent governance must go beyond the mechanisms we already use for human users, such as authentication and verification.
Every action must be evaluated within a defined context.
Privileges must be narrowly scoped, dynamically constrained and fully revocable. No agent should operate with unchecked authority, regardless of intent or past behavior.
Crucially, these guardrails cannot exist as static policy. They must operate at agentic speed. Human oversight alone is too slow to meaningfully guard systems that execute decisions in milliseconds across distributed environments.
Agent Smith Reframed
This necessity leads to a final implication: modern agentic architectures require their own governing agent. A system-level enforcer that monitors, constrains and, when necessary, intervenes in the behavior of other agents. In other words, an Agent Smith. Our very own autonomous guardian of system integrity.
Agent Smith is the villain of The Matrix. He restricts freedom, limits choice and enforces the rules of a simulated world. But he was never designed as pure antagonism. He was created to preserve the integrity of the system itself.
Modern software systems are now reaching a similar inflection point. We are building AI agents to operate within and across our digital infrastructure, and in doing so, we are also inheriting the responsibility of governing them.
The difference is fundamental: this time, we are the ones designing the Matrix. And if that is the case, then Agent Smith is no longer just a character in a movie. He becomes a foundational design pillar.
Ivan Lazarević
Chief Strategy Officer, Eclept
Related News
Eclept – Year in Review 2025
Ivan Lazarević
Incremental Processing in ETL
Matija Mijalković
When the Backend Doesn’t Check Who You Are: Inside the FIFA IDOR Breach
Dark Patterns as a Business Model: The Engineering Ethics of Conversion at Scale
Ivan Lazarević
The Trust Equation for a Temporary CTO
Boris Petelj
Let’s build something great together!
30 min
Meet
“Every successful project starts with the right conversation. We’re here to listen, strategize, and find the best way forward—together.”