Generative AI has rapidly shifted from interactive assistants to autonomous, goal-directed agents that plan, act, delegate to sub-agents, and persist over time. In enterprise environments these agents can write and execute code, call APIs, manage files, and orchestrate workflows, creating a qualitative expansion of the risk surface beyond traditional model-inference concerns. While input filtering, output moderation, and prompt-injection defenses remain necessary, they are insufficient because agentic deployments introduce a second security surface centered on action, identity, and delegation.
A six-category framework organizes the agentic AI security and governance landscape across layers from identity and access through runtime control to governance and compliance, mapped to four operational phases: Prevent (AIAM + APGE), Observe (AVOP), Detect/Respond (ATDR), and Govern (ARC + AORC). Procurement also splits into three distinct tracks with different buyers: Track 1 extends Generative AI Defense to the agent layer; Track 2 addresses AI Agent Identity & Access Management; Track 3 focuses on AI Governance, Risk & Compliance, driven by EU AI Act requirements beginning August 2026 for high-risk systems.
Agent identity creates new challenges: agents and sub-agents are short-lived, hierarchically organized, and often invisible to existing IAM/IGA. Trust anchors and attestable workload identity (not long-lived secrets) become central, with SPIFFE/SPIRE and cloud workload identity options highlighted. Authorization is an active frontier: preventing privilege amplification across delegation chains requires multi-tier policy-based access control, with OpenFGA and OPA positioned as enabling policy engines though full multi-tier policy propagation is not yet implemented by vendors. Market dynamics show rapid consolidation in ATDR (comparable to CASB and SOAR waves), pushing buyers to evaluate integrated platforms rather than standalone ATDR products and to prioritize credential-sprawl audits and EU AI Act-driven auditability and risk documentation.
See All Locations
See All Locations