Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Agentic fabric on endpoints: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20538
Topic starter  

TL;DR: The real AI agent exposure sits in the agentic fabric on endpoints, not the model itself, because instructions, memory, MCP servers, skills, hooks, connectors, and sub-agents can combine into legitimate but risky actions, according to Backslash Security. The governing assumption that endpoint tools can judge agent intent from process and network events no longer holds.

NHIMG editorial — based on content published by Backslash Security: When AI Agents Own The Endpoint: The Security Gap That No One Is Watching

By the numbers:

  • 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, inappropriately sharing sensitive data, and revealing access credentials.

Questions worth separating out

Q: What breaks when organisations rely only on EDR to control AI activity?

A: EDR can miss the browser-mediated steps where users paste data, approve access, or move between SaaS tools and AI services.

Q: Why do AI agents complicate access governance more than ordinary automation?

A: AI agents complicate access governance because they can branch at runtime, wait on external services, and continue later with the same operational context.

Q: How can security teams tell when an agentic control model is failing?

A: The clearest sign is when approved components behave safely on paper but unsafe outcomes still occur in practice.

Practitioner guidance

  • Inventory the full agentic fabric Catalogue instructions, memory stores, MCP servers, skills, hooks, connectors, and sub-agents on employee endpoints so you can govern the assembled access path, not just the application name.
  • Classify connector and skill combinations as policy objects Review high-risk pairings such as filesystem-capable skills plus persistent memory plus broad OAuth connectors as one runtime boundary, then approve or deny the combination as a unit.
  • Add agent-aware audit logging Log instructions, tool calls, connector use, and the reasoning trail that links them so investigations can separate manipulation, overscoped action, and genuine error.

What's in the full article

Backslash Security's full analysis covers the operational detail this post intentionally leaves for the source:

  • How the agentic fabric maps across endpoint components, including instructions, hooks, connectors, and sub-agents.
  • Examples of runtime failure modes, including prompt injection, malicious skills, and unsafe connector combinations.
  • The approval and audit limitations the article observes in real agent workflows.
  • The webinar context and the vendor's endpoint protection approach for practitioners who need implementation detail.

👉 Read Backslash Security's analysis of AI agents on employee endpoints →

Agentic fabric on endpoints: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 20129
 

Endpoint security no longer governs the real unit of risk when the agentic fabric becomes the access layer. Instructions, memory, connectors, skills, hooks, MCP servers, and sub-agents create a composite identity surface that endpoint tooling was never designed to understand. That means the governance problem is not device monitoring alone, but control over how delegated runtime authority is assembled and used. Practitioners should treat agentic fabric as an identity domain in its own right.

A few things that frame the scale:

  • 92% agree governing AI agents is critical to enterprise security, yet only 44% have implemented any policies to do so, according to AI Agents: The New Attack Surface report.
  • Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.

A question worth separating out:

Q: How should organisations govern AI agent tool access as connectors change?

A: Organisations should treat connector updates like identity change events. Every new tool should start disabled, be classified against the trust ladder, and be added to a signed policy export before it can act. That keeps the access model aligned with the live system instead of the last review cycle.

👉 Read our full editorial: AI agents on endpoints expose an ungoverned identity layer



   
ReplyQuote
Share: