Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

AI agent security vs CNAPP: what identity teams need to weigh


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20360
Topic starter  

TL;DR: Most enterprises undercount active AI agents by 3 to 10 times and 80% of current deployments already show rogue behaviour, according to Trust3, while Wiz extends CNAPP coverage into AI models and agents. The real issue is that discovery and runtime authorization for agent identities cannot be treated as the same control problem as cloud posture correlation.

NHIMG editorial — based on content published by Trust3: Trust3 AI vs. Wiz: AI Agent Security Compared

By the numbers:

Questions worth separating out

Q: How should security teams govern agentic AI as it moves into production?

A: Security teams should govern agentic AI as a class of non-human identity, not as a generic application feature.

Q: Why do CNAPP tools alone not solve AI agent security?

A: CNAPP tools correlate cloud and runtime risk, which is useful for prioritisation, but correlation does not decide whether a specific agent action should be allowed.

Q: What happens when AI agents are created without approval or inventory?

A: Shadow agents become ungoverned identities that cannot be reviewed, certified, or retired through normal IAM processes.

Practitioner guidance

What's in the full article

Trust3's full article covers the operational detail this post intentionally leaves for the source:

  • Side-by-side feature comparison of Trust3 AI and Wiz across discovery, observability, and runtime enforcement.
  • Tool and platform integration detail for Snowflake, Databricks, BigQuery, Copilot Studio, and MCP-connected environments.
  • Per-turn audit and authorization workflow examples that show how access decisions are made in practice.
  • Deployment and compliance mapping detail for teams evaluating agent governance in production.

👉 Read Trust3's comparison of Trust3 AI and Wiz for AI agent security →

AI agent security vs CNAPP: what identity teams need to weigh?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19951
 

AI agent governance is splitting away from general cloud security. CNAPP and agent-specific control planes are answering different questions. CNAPP correlates cloud and runtime risk, while agent security has to decide who the agent is, what purpose it is serving, and whether it may act at all. Practitioners should stop treating the two as interchangeable layers.

A few things that frame the scale:

  • 98% of companies plan to deploy even more AI agents within the next 12 months, despite documented rogue behaviour in 80% of current deployments, according to AI Agents: The New Attack Surface report.
  • Only 52% of companies can track and audit the data their AI agents access, which means nearly half still lack defensible investigation evidence.

A question worth separating out:

Q: Should organisations run agent security beside CNAPP or replace CNAPP with it?

A: Most organisations will need both. CNAPP gives broad environmental context and attack-path prioritisation, while agent security gives per-action authorization and identity governance for AI agents. The decision is not either-or unless the organisation has no production agent activity.

👉 Read our full editorial: Trust3 AI and Wiz expose the split between agent security and CNAPP



   
ReplyQuote
Share: