TL;DR: Semgrep’s static analysis and AI-assisted triage can catch vulnerabilities in AI-generated code, according to WorkOS, but code scanning does not authenticate agents, enforce authorization boundaries, or provide enterprise identity infrastructure. That gap means production AI agents still need identity controls, not just stronger code review.
Editorial analysis by NHI Mgmt Group, based on content published by WorkOS: “Semgrep for AI Agent Security: Features, Pricing, and Alternatives”.
Key questions
Q: What breaks when AI agent security is handled like ordinary application security?
A: Application security assumes a relatively stable workload boundary and a predictable request path.
Q: Why do production AI agents need authorisation controls beyond secure code review?
A: Because secure code review cannot decide whether a runtime actor should have access to enterprise data, customer systems, or privileged APIs.
Q: How do security teams know if an AI agent has too much access?
A: Look for agents that can reach multiple systems without task-specific limits, use persistent tokens, or touch high-value services such as email, chat, cloud consoles, and file stores.
Practitioner guidance
- Separate code security from runtime identity governance Use SAST to inspect generated code, but define a distinct control plane for agent authentication, authorisation, audit logging, and revocation.
- Inventory every production agent as a non-human identity Track each agent’s system accounts, OAuth grants, API tokens, and delegated scopes so access can be owned and retired with the same discipline as other NHI credentials.
- Enforce least privilege at the agent boundary Scope each agent to the smallest set of resources and actions it needs, then review whether its session or delegation model creates standing access that outlives the task.
Bottom line: The core issue is not whether AI-generated code is safe enough to deploy, but whether the runtime agent has been given identity and access controls that match its operational reach.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Code scanning and identity control solve different failure modes: static analysis reduces vulnerability density in generated code, but it does not establish who is allowed to act at runtime. That separation is not academic. A production AI agent can produce clean code and still be over-authorised, unaudited, or impossible to revoke cleanly. Practitioners should stop treating code security and identity security as substitutes.
A few things that frame the scale:
- Gartner predicts that more than 50% of successful cyberattacks against AI agents through 2029 will exploit access control weaknesses.
A question worth separating out:
Q: What is the difference between securing the AI model and securing the code it generates?
A: Securing the model focuses on protecting the AI system from threats such as malicious prompts, injection, and misuse. Securing the code it generates focuses on the quality and safety of the output artifact itself. A model can behave as intended and still produce insecure code, so organisations need both input protection and output assurance before they can trust AI-assisted development.
👉 Read our full editorial: AI agent security still needs identity controls beyond code scanning