The security industry likes distinct product categories. A new threat or risk appears, analysts name the category, vendors position around it, and buyers build feature shortlists. That model works when the problem has clear boundaries, but AI security does not.
Many vendors (both established players and AI-native startups) claim to provide “AI security” or “AI governance”. Most of these vendors are directionally right, but the problem space is too broad and dynamic for any one control category or solution provider to address comprehensively.
Securing AI will thus not become one giant market category. It requires a fabric that combines multiple control categories. Much like the need for holistic identity and access management implementations that combine multiple controls led KuppingerCole Analysts to define the identity fabric. Existing security and governance categories must extend and provide coverage for generative AI and AI agents. At the same time, new AI-native controls will emerge for risks that traditional controls are not designed to handle. Enterprises should plan to use both types as part of the emerging AI security fabric.
This matters because AI is moving faster than current controls, both identity and broader cybersecurity can support. AI is being embedded into productivity suites, business applications, development platforms, analytics tools, security systems, and many other types of SaaS applications. Organizations are also building internal copilots and are rolling out specialized AI agents in support of their businesses. Security teams are being asked to secure systems they are currently not even able to comprehensively discover.
Why AI Is Not Just Another Application
Treating AI as just another application is wrong. Traditional controls still apply, but AI dramatically changes what needs to be protected. With conventional applications security teams can focus on users, access control, the code, data, and logs. AI systems behave differently: they combine foundational model behavior with prompts, enterprise context, data retrieval, tools, and delegated action, and their non-deterministic results may change with each run.
This changes the attack surface. Beyond exploiting vulnerabilities or stealing credentials, attackers can now manipulate prompts, poison retrieval, exploit context, induce unsafe output, or trick an agent into taking malicious actions. The resulting risks span application security, identity, data security, and business process control. This shift is why traditional cybersecurity frameworks struggle to fully model AI systems, especially in agentic and generative AI environments.

Existing Security Controls Will Evolve, Not Disappear
Some AI risks can (or will) be handled by current security and governance controls. IAM systems can understand AI users, services, and agents. IGA and PAM systems can govern delegated authority and privileged actions. Data security controls can know which AI systems can access sensitive information and how that information can appear in outputs.
GRC systems can manage AI assets, ownership, policy, risk decisions, and the associated evidence. SOC tools can detect misuse involving AI systems. SaaS security tools can discover AI services, risky grants, and shadow AI adoption inside enterprises.
Existing security categories will not disappear, but vendors must evolve their control models to treat AI systems and AI agents as first-class actors.
AI-native Controls are Required for Security Architectures
Extending existing security categories for AI will not be enough.
Some AI risks need controls built close to the AI interaction layer. Prompt injection is not SQL injection, jailbreaking is not access abuse, and agent runtime control is not service-account monitoring.
Enterprises also need controls that inspect prompts, evaluate outputs, detect manipulation, protect data retrieval, and enforce policy during AI interactions. They need runtime monitoring for agents that can use tools, act across systems, and with and through other agents. They will need evidence that shows what the AI system was asked to do and what happened.
AI introduces failure modes that traditional security controls were not originally designed to manage.
AI Governance and AI Security Are Related, Not Identical
AI governance and AI security are often discussed together, but they are not the same.
AI governance refers to defining policies, ownership, accountability, and evidence requirements for AI systems. AI security refers to enforcing and monitoring those policies across runtime systems, data access, and AI agents.
AI GRC should answer questions such as:
- What AI systems exist?
- Who owns them?
- What are they used for?
- What policies apply?
- What evidence is required?
AI security answers a different set of questions:
- Can this AI system access that data?
- Can it call that API?
- Is a prompt attempting to override policy?
- Did the system expose sensitive information?
- Did an AI action cause an incident?
The two domains must work together, but governance systems and enforcement controls should remain operationally distinct.

Agentic AI Changes the Risk Model
The emergence of agentic AI significantly raises the stakes.
A chatbot that drafts text creates some risk. An autonomous agent that can call APIs, modify records, trigger workflows, communicate with other systems, or delegate to other agents creates a fundamentally different risk model.
That puts agentic AI at the intersection of identity, data access, workflow control, and runtime security. Agents may act with delegated authority, using workload or human identities, and they will make decisions faster than human-in-the-loop review processes can keep up.
This is why enterprises need an AI Security Fabric: a need for integrated control architectures that connect identity, policy, runtime protection, telemetry, incident response, and audit evidence across AI systems and agents.
Start with Controls, Not Category Labels
The best buyer strategy is straightforward: map AI use cases to control requirements before evaluating product categories.
Organizations should begin by identifying:
- Which AI systems are in scope
- What data they can access
- Who or what can act through them
- Which business processes they affect
AI Security requires a Fabric
AI security requires both evolution and invention. Existing security and governance categories will become AI-aware. At the same time, new AI-native controls are also emerging where prompts, models, context, data retrieval, and agents create new risks.
Securing AI will not be one market category. It will be a discipline, an architecture, a fabric, or a mesh, and requires a multi-year shift in how enterprises govern and protect this new class of IT system. The challenge is no longer whether AI introduces new risk. It is whether organizations can design controls fast enough to match adoption.
Organizations should begin now by:
- Mapping AI systems and agents
- Identifying control coverage gaps
- Separating governance from enforcement
- Evaluating where existing controls apply
- Identifying where AI-native protections are required
Organizations evaluating AI security and governance strategies will increasingly need cross-domain expertise spanning these domains.
To dive deeper into this topic, check out this analyst chat on the AI Security Fabric.