TL;DR: Enterprises are converging on a five-layer agentic AI security stack that spans discovery and governance, identity, runtime guardrails, MCP visibility, and continuous red teaming, according to Akto. The core issue is not prompt safety alone but controlling agent behaviour, tool access, and downstream actions before autonomous systems outpace governance.
NHIMG editorial — based on content published by Akto: Founding Team Agentic AI Security, the current market landscape
By the numbers:
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%).
- 96% of technology professionals identify AI agents as a growing security threat, and 66% believe this risk is immediate.
Questions worth separating out
Q: How should security teams govern AI-enabled workflows that can act on their own?
A: Treat them as identity-governed execution paths, not just software features.
Q: Why do agentic AI systems need more than prompt-level security controls?
A: Prompt-level controls only inspect content, while agentic systems create risk through tool use, workflow triggering, and downstream execution.
Q: What breaks when organizations do not inventory AI agents and MCP connections?
A: Security teams lose the ability to answer what exists, what it can reach, and who owns it.
Practitioner guidance
- Build a complete agent and MCP inventory Catalog every agent, MCP server, tool, and downstream resource with named ownership, data flow mapping, and review dates so the security team can see the full action surface.
- Classify agent credentials as governed NHIs Assign explicit owners to tokens, secrets, and permissions used by agents, then review them for over-provisioning, shadow deployment, and drift from the approved use case.
- Enforce runtime blocking at the execution path Place controls at the proxy, gateway, endpoint, or network layer so unsafe tool calls, data leakage, and chained actions can be blocked in context before they complete.
What's in the full article
Akto's full post covers the operational detail this post intentionally leaves for the source:
- The full five-layer market map for agentic AI security and how vendors cluster across it.
- The article's detailed view of which control plane owns governance, identity, runtime, MCP proxying, and red teaming.
- The broader market-direction commentary on where enterprise budgets are likely to move in 2026.
- The source's discussion of how security may move directly into agents, MCP servers, and downstream application infrastructure.
👉 Read Akto's analysis of the agentic AI security stack landscape →
Agentic AI security stacks: what is your team missing today?
Explore further
Agentic AI security is becoming a layered identity problem, not a model-safety problem. The article's five-layer stack is directionally correct because enterprises are now securing agents, tools, MCP wiring, and runtime behaviour rather than prompts alone. That shift matters because the security boundary is no longer the model response, it is the action surface created by identity plus tool access. Practitioners should stop treating AI security as a single control domain and map each layer to a separate owner and control objective.
A few things that frame the scale:
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%), according to AI Agents: The New Attack Surface report.
- A separate finding in the same research shows that only 52% of companies can track and audit the data their AI agents access, which leaves 48% with a compliance and investigation blind spot.
A question worth separating out:
Q: How do organisations know if agentic AI governance is actually working?
A: Look for three signals: access decisions tied to task context, complete audit records linking agents to datasets, and rapid revocation when scope changes. If reviewers still need manual reconstruction after an incident, the programme is not mature. Effective governance produces explainable access, not just allowed or denied results.
👉 Read our full editorial: Agentic AI security stacks are converging around five layers