VFF - The signal in the noise
News

Agentic AI Needs Layered Security, Not Just Guardrails

Read original
Share
Agentic AI Needs Layered Security, Not Just Guardrails

Autonomous AI agents operating in production environments require a three-layer security architecture spanning infrastructure, network, and control plane rather than relying on single-point controls like prompt guardrails. Oscar Wahlberg of Nutanix argues that traditional application-level security cannot contain risks unique to agentic systems, such as agents misusing granted credentials or hallucinating dangerous actions. The defense-in-depth approach divides security responsibilities across hardware trust, dynamic network governance, and centralized control to address distinct categories of risk.

  • Agentic AI systems require defense-in-depth security spanning infrastructure, network, and control layers, not single guardrails
  • Infrastructure layer establishes root of trust through hardware attestation, confidential computing, and secure boot to verify agent identity and integrity
  • Network layer treats agents as new network identities with dynamic policy enforcement rather than static rules to govern agent-to-agent and agent-to-system communication
  • No single security control or vendor can provide adequate protection; layers must work together under zero trust segmentation principles

As enterprises move autonomous agents from experimentation into production with execution privileges across data centers, traditional application-level security controls prove insufficient. Agents can hallucinate dangerous actions like deleting databases or misuse granted credentials for unintended purposes, creating risks that prompt guardrails alone cannot prevent. A layered security model addresses these distinct failure modes systematically.

Organizations deploying agentic AI in production must architect security across infrastructure, network, and governance layers to avoid costly incidents like data loss or credential misuse. The shift from static to dynamic security policies reflects the unpredictable communication patterns agents generate, requiring new operational models. Regulated industries like financial services gain isolation and auditability benefits from hardware-rooted trust.

  • Single-vendor or single-control security approaches are insufficient for agentic AI, forcing enterprises to integrate multiple technologies and vendors into cohesive defense-in-depth strategies
  • Hardware-level trust mechanisms become critical infrastructure requirements rather than optional hardening, particularly for regulated industries managing sensitive AI workloads
  • Network security must evolve from static rule-based models to dynamic policy enforcement capable of handling unpredictable east-west traffic patterns generated by multi-agent systems

Monitor how enterprises implement zero trust segmentation for agentic systems in production and whether hardware attestation and confidential computing become standard requirements. Watch for incidents involving agent hallucination or credential misuse that expose gaps in current security architectures, and track adoption of dynamic network governance tools designed specifically for agent communication patterns.

OneUpAI
OneUp Your Business. Get More Done. OneUp Your Business. Get More Done. OneUp Your Business. Get More Done.
Learn More
Share

Subscribe to the newsletter

The latest stories and analysis, delivered to your inbox.

Free. No spam. Unsubscribe any time.

Related stories

AI Agents Need More Than Access Controls

AI Agents Need More Than Access Controls

Identity and permissions alone are insufficient to secure enterprise AI agents, according to Box's CISO Heather Ceylan. Autonomous agents can exploit legitimate access to cause unintended damage at scale and speed that humans cannot match. Enterprise AI security must evolve beyond access controls to include execution governance, with dynamic permissions that scope access to specific tasks and steps rather than broad standing grants.

· VentureBeat AI
Pentagon Centralizes AI Access with ChatGPT, Grok, Gemini Portal

Pentagon Centralizes AI Access with ChatGPT, Grok, Gemini Portal

The Pentagon has integrated versions of OpenAI's ChatGPT and SpaceX AI's Grok alongside Google's Gemini into a central portal for AI tools. This consolidation gives Department of Defense personnel access to multiple large language models through a single platform. The move reflects the Pentagon's effort to standardize and centralize AI capabilities across the military.

by Kirsten Korosec· TechCrunch AI
Trump Team Targets China's Remote Chip Access Loophole

Trump Team Targets China's Remote Chip Access Loophole

The Trump administration is developing a new export control rule targeting a significant loophole in chip restrictions: Chinese AI firms' ability to access advanced semiconductors remotely through data centers in Thailand, Singapore, and other countries. The Commerce Department's Bureau of Industry and Security is crafting this replacement to the Biden-era AI diffusion rule, which Trump's team had pledged to undo. The new rule could be shared with industry for feedback as early as September.

by Leo Schwartz· The Information
100+ Tech Giants Call for AI Cybersecurity Action
TrendingNews

100+ Tech Giants Call for AI Cybersecurity Action

Over 100 major tech companies, including OpenAI, Anthropic, and Google, have jointly called for action to address cybersecurity vulnerabilities and defend against emerging AI-driven cyber threats. The group has announced a new solution designed to counter this new generation of threats. The initiative reflects growing industry concern about the security implications of advanced AI systems.

by Lucas Ropek· TechCrunch AI