TL;DR: As AI agents and MCP servers multiply, APIs are becoming the primary attack surface and existing endpoint, network, and cloud controls do not provide enough inventory, runtime oversight, or behavioural context, according to Salt Security. The security model is shifting toward agentic AI security because machine-speed API use changes how access, monitoring, and governance need to work.
At a glance
What this is: This is an analysis of why APIs, AI agents, and MCP servers are pushing agentic AI security into a distinct cybersecurity category.
Why it matters: It matters because identity, access, and governance teams now have to control machine-driven API behaviour, not just human logins and traditional workloads.
By the numbers:
- APIs now account for over 80% of web traffic.
- Enterprises often have 10–20x more APIs than traditional applications.
- Only 18% of MCP server deployments implement any form of access scoping for tool permissions.
👉 Read Salt's analysis of agentic AI security as the fourth pillar
Context
Agentic AI security is the discipline focused on protecting autonomous AI agents, MCP servers, and the APIs they use to act on behalf of users and systems. The core problem is governance: existing endpoint, network, and cloud controls were built for static assets and predictable traffic, while API-driven agent behaviour is dynamic, ephemeral, and difficult to inventory.
Salt Security frames the issue as a structural blind spot in current security architecture. That lens is credible because identity and access governance now extend beyond humans and workloads into machine identities, delegated authority, and API-scoped permissions. For IAM, PAM, and NHI programmes, this is a real control boundary, not a niche product category.
Key questions
Q: What breaks when AI agents are given broad standing access?
A: Broad standing access breaks governance because the agent can move from one task to another without a fresh authorization check. That creates a control gap between intended scope and actual runtime behaviour. The result is weak accountability, limited containment, and audit trails that show activity without explaining why the activity was allowed.
Q: Why do MCP environments increase identity governance complexity for AI agents?
A: MCP turns model-tool interaction into a repeatable identity event, which means access, logging, and approvals must work at the capability level rather than at the application level. That complicates governance because the same tool may be reused across many workflows, making privilege review and audit trails harder to standardise.
Q: How do organisations know if agentic AI governance is actually working?
A: Look for three signals: access decisions tied to task context, complete audit records linking agents to datasets, and rapid revocation when scope changes. If reviewers still need manual reconstruction after an incident, the programme is not mature. Effective governance produces explainable access, not just allowed or denied results.
Q: Who should own AI agent security across IAM, API, and platform teams?
A: Ownership should be shared but explicit. IAM teams should define identity and access policy, API teams should enforce request controls, and platform teams should manage the runtime boundary and logging. If ownership is split informally, gaps appear exactly where agents cross from one service to another.
Technical breakdown
Why API inventory breaks down in agentic environments
APIs are not discrete assets like laptops or servers. They are interfaces distributed across microservices, SaaS integrations, cloud platforms, and AI workflows, which makes discovery and ownership harder than classic asset management. When AI agents and MCP servers can dynamically create or consume API paths, shadow interfaces emerge faster than governance teams can catalogue them. The control problem is not just exposure. It is the inability to answer which APIs exist, who owns them, and what sensitive systems they can reach.
Practical implication: maintain a continuously refreshed API and MCP inventory tied to owners, data sensitivity, and access scope.
How machine-speed API calls change authorisation risk
Traditional application security assumes requests are relatively bounded by human intent or fixed service logic. AI agents break that assumption by generating high-volume, context-sensitive requests that can chain across systems without a human in the loop. That creates confused deputy risk, where a legitimate agent or MCP server is induced to perform actions beyond the original intent. In identity terms, the issue is delegated authority at machine speed, where the scope of access matters more than the credential alone.
Practical implication: bind agent permissions to task-scoped, least-privilege API entitlements and review those entitlements continuously.
Why runtime behavioural baselines matter more than static policy
Static policy can tell you what an agent should be allowed to do, but not whether it is being manipulated or malfunctioning. A behavioural baseline describes normal call patterns, frequency, payload structure, and destination systems for each agent or MCP connection. That makes it possible to spot anomalies such as sudden expansion in API volume, new destinations, or unusual data access paths. In agentic environments, runtime context is essential because policy without behavioural evidence is too blunt to detect abuse early.
Practical implication: pair policy enforcement with runtime anomaly detection that inspects agent intent and API call patterns.
Threat narrative
Attacker objective: The attacker wants to use trusted API and agent pathways to reach sensitive data or business workflows without triggering traditional perimeter controls.
- Entry occurs when an AI agent or MCP server connects to exposed APIs that were never formally inventoried or tightly scoped.
- Escalation follows when the agent inherits broad delegated authority and can chain requests into higher-value systems or sensitive data stores.
- Impact occurs when manipulated or over-permissioned agent activity drives unauthorised data access, workflow abuse, or credential exposure at machine speed.
NHI Mgmt Group analysis
Agentic AI security is becoming a control plane issue, not a point-solution category. The article is right to treat APIs as the connective tissue of the AI era, because the risk is concentrated in who or what can invoke them, under what scope, and with what downstream authority. That makes the issue inseparable from IAM, PAM, and NHI governance. Security teams should treat agentic API access as a lifecycle problem, not a perimeter problem.
API blindness creates a new version of shadow identity sprawl. When organisations cannot inventory MCP servers, agents, and the APIs they touch, they also cannot govern their machine identities with confidence. The result is not just missing telemetry. It is unmanaged delegated trust that can outpace access review, secret rotation, and offboarding discipline. Practitioners should read this as an identity governance failure with a cyber implementation layer.
Machine-speed delegation changes what least privilege has to mean. In agentic systems, broad reusable access is especially dangerous because agents can combine tools, contexts, and timing in ways humans rarely do. Least privilege now needs to be task-scoped, observable, and revocable at runtime. That is where NHI governance and PAM principles become central to AI security architecture.
Agentic AI security will converge with broader platform governance. The market is likely to move toward discovery, runtime enforcement, and policy orchestration across APIs, agents, and data bridges rather than isolated monitoring tools. That aligns with where identity governance has already gone in cloud and NHI environments. Practitioners should expect board-level scrutiny to shift from model risk alone to end-to-end machine access control.
Shadow MCP exposure is the named concept security teams should track. The article describes a world where MCP servers and AI-to-data bridges appear outside formal governance, which creates hidden routes into sensitive systems. That is a specific control gap, not a generic visibility issue. Teams should use it as the organising concept for discovery, policy, and runtime control work.
What this signals
Agentic AI will force security teams to treat API reach as an access-governance problem, not just an integration problem. The practical shift is toward continuous ownership mapping for machine identities, especially where APIs connect to sensitive data or business workflows. That is where IAM and NHI programmes will be asked to prove they can govern ephemeral authority, not only static accounts.
Shadow MCP exposure is likely to become a recurring audit finding. If development teams can stand up agents and tool bridges faster than security can inventory them, governance will drift out of sync with reality. Practitioners should expect more demand for runtime discovery, policy enforcement, and evidence that machine access can be explained end to end.
The next control priority is not simply blocking AI agents. It is proving that every agentic pathway is observable, scoped, and revocable before it becomes a persistent route into sensitive systems. That is where API security, identity governance, and PAM converge.
For practitioners
- Build a live inventory of agents, MCP servers, and APIs Track every AI agent, MCP server, and downstream API in one ownership model so security can see shadow deployments, exposed bridges, and unregistered endpoints before they become part of production workflows.
- Scope delegated access to task-level permissions Assign each agent only the specific API actions it needs, then remove broad reusable access paths that create confused deputy risk and unnecessary reach into sensitive systems.
- Enforce behavioural baselines for machine-to-machine traffic Measure normal call frequency, destination systems, and payload patterns for each agent so anomaly detection can flag logic abuse, prompt-driven misuse, or sudden expansion in data access.
- Tie runtime controls to identity governance Connect API protection to NHI, PAM, and access review processes so delegated authority can be approved, monitored, revoked, and audited with the same discipline used for privileged human access.
Key takeaways
- Agentic AI security emerges here as an access-governance problem because AI agents and MCP servers can extend authority far beyond what traditional controls were designed to monitor.
- The strongest evidence in the article is structural: APIs are now the primary attack surface, but organisations still struggle to inventory them, scope them, and observe their runtime behaviour.
- Practitioners should respond by tightening task-level permissions, building live inventories, and linking agent controls to IAM, NHI, and PAM governance.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | A3 | The article centers on agentic AI attack surface and tool misuse. |
| OWASP Non-Human Identity Top 10 | NHI-01 | The post links agent access scope to non-human identity governance. |
| NIST AI RMF | GOVERN | AI governance and accountability are central to agentic access control. |
| NIST CSF 2.0 | PR.AC-1 | The article is fundamentally about access management and visibility. |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege is the core control challenge in agentic access paths. |
Map agent permissions to access-control outcomes and verify every machine identity has an owner and scope.
Key terms
- Agentic AI Security: Agentic AI security is the discipline of securing autonomous AI systems that can take actions, use tools, and chain decisions without direct human approval at each step. It covers identity and access management for AI agents, prompt injection defence, tool call governance, credential scoping, and runtime monitoring. As agentic systems acquire real-world authority — API access, file writes, workflow triggers — the security model must treat them as non-human identities with explicit lifecycle controls, not trusted processes.
- Model Context Protocol: Model Context Protocol is an open protocol that lets AI agents connect to tools and data sources through a standard interface. In security terms, it expands the number of machine-to-machine trust relationships that must be inventoried, scoped, and monitored.
- Model Context Protocol: Model Context Protocol is an open protocol that lets AI agents connect to tools and data sources. It expands what an agent can reach, so governance has to cover not only the model and its prompts, but also every system that can receive or return agent-driven data.
- Confused Deputy: A confused deputy is a privileged system that is tricked into performing an action on behalf of an untrusted requester. In agentic AI, the agent may misread malicious input as legitimate intent and then use its own authority to act, which turns a logic problem into a security incident.
What's in the full article
Salt's full article covers the operational detail this post intentionally leaves for the source:
- The article lays out the full four-part argument for treating agentic AI security as a separate cybersecurity pillar.
- It expands the comparison between endpoint, network, cloud, and API-driven control gaps in modern environments.
- It describes Salt's own discovery, governance, and behavioural monitoring approach for agentic traffic.
- It includes the operational framing for continuous discovery of MCP servers, shadow agents, and API relationships.
👉 Salt's full article covers API blind spots, machine-speed governance, and runtime monitoring detail.
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps security and identity practitioners align access control with the realities of modern digital identities.
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org