Policy, authorization, audit and traceability for the teams responsible for keeping agent adoption within the organization's boundaries.
When each department secures its own agents, the organization ends up with as many security models as there are frameworks in use. A requirement approved once shouldn't need a separate implementation for every technology.
Define once. Enforce everywhere.
Enforce security requirements centrally, not team by team.
Define which agents can reach which models, tools, data and systems.
Maintain traceability over configuration changes and runs.
Understand how an agent evolved and who changed it.