Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

AI agent security is becoming its own category for enterprise controls


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19415
Topic starter  

TL;DR: Google’s inaugural Gemini Startup Forum grouped 33 startups across six focus areas, with AI agent security standing on its own as a full segment rather than a subset of application security, according to Onyx. That separation reinforces that autonomous agents need dedicated discovery, posture, and runtime governance, not retrofitted controls from legacy IAM or appsec.

NHIMG editorial — based on content published by Onyx: Onyx joins Google’s Gemini Startup Forum for AI agent security

By the numbers:

Questions worth separating out

Q: How should security teams govern AI agents that can choose tools at runtime?

A: Security teams should govern runtime agent choice as an access event, not as a simple application action.

Q: Why do existing IAM controls struggle with autonomous AI agents?

A: Existing IAM controls were designed around human users and predictable workload behaviour.

Q: What breaks when AI agents are treated like standard human users?

A: You lose visibility into effective permissions, expected behaviour, and real blast radius.

Practitioner guidance

  • Map every AI agent to a governed identity record Inventory the agent, the owner, the connected tools, the data it can reach, and the environments where it operates.
  • Separate initial authorisation from runtime control Approve only the minimum tool set required at setup, then enforce policy checks during execution for sensitive actions, data access, and external calls.
  • Instrument tool usage and action sequencing across the agent path Collect logs for API calls, workspace actions, and endpoint activity in a format that preserves action order and policy context.

What's in the full article

Onyx's full blog post covers the operational detail this post intentionally leaves for the source:

  • How Onyx maps Vertex AI Agent Engine, Gemini Enterprise, and Google Workspace Studio into its coverage model
  • The specific working relationship implied by the Gemini Startup Forum cohort and Google Cloud engineering teams
  • The product framing for discovery, posture, and runtime governance across autonomous agents
  • The vendor's own description of how its control plane fits Google's AI surfaces

👉 Read Onyx's analysis of Google’s Gemini Startup Forum and AI agent security →

AI agent security is becoming its own category for enterprise controls?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 19006
 

AI agent security is now a separate identity discipline, not an extension of application security. Google grouping agent security into its own cohort is a market acknowledgement that autonomous systems create identity behaviour that appsec does not fully capture. The core issue is not only model risk or endpoint risk, but governed access for actors that can choose tools and actions at runtime. Practitioners should expect this category to drive new identity patterns rather than cosmetic policy updates.

A few things that frame the scale:

  • 80% of organisations report their AI agents have already performed actions beyond their intended scope, according to AI Agents: The New Attack Surface report.
  • A further 92% agree governing AI agents is critical to enterprise security, yet only 44% have implemented any policies to do so.

A question worth separating out:

Q: Who should own AI agent identity governance in an enterprise?

A: AI agent identity governance should sit jointly with IAM, platform security, and application owners because the risk crosses the runtime, the proxy, and the receiving service. No single team can see the whole delegation chain unless identity context is preserved end to end.

👉 Read our full editorial: Google’s Gemini forum signals AI agent security is a distinct discipline



   
ReplyQuote
Share: