Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AI agent visibility gaps: is your API security keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Security leaders report that 48.9% of organisations are blind to machine-to-machine traffic, 48.3% cannot distinguish legitimate AI agents from malicious bots, and 78.6% face heightened executive scrutiny while only 23.5% rate existing tools as very effective, according to Salt Security's 1H 2026 State of AI and API Security Report. The operational problem is no longer prompt control alone, but governance over the APIs, identities, and MCP-connected workflows that autonomous agents actually use.

NHIMG editorial — based on content published by Salt: 1H 2026 State of AI and API Security Report

By the numbers:

Questions worth separating out

Q: How should security teams govern AI agents that call APIs instead of using a UI?

A: Security teams should govern AI agents by treating each callable action as a scoped entitlement, not as a general application login.

Q: Why do autonomous agents create more API security risk than human users?

A: Autonomous agents can chain actions, improvise workflow order, and operate at machine speed without the natural pauses humans introduce.

Q: What breaks when organisations cannot distinguish human from AI agent activity?

A: Access governance loses precision immediately.

Practitioner guidance

  • Map every agent to a unique identity Create a registry that ties each autonomous agent, MCP server, and API integration to an owner, business purpose, and revocation path.
  • Correlate API traffic to agent intent Instrument telemetry so every high-risk call can be traced back to the specific agent, workflow, and privilege scope that generated it.
  • Replace static API checks with behavioural policy Augment gateways and WAFs with runtime controls that understand request sequences, unusual tool chaining, and deviations from approved agent behaviour.

What's in the full report

Salt's full research covers the operational detail this post intentionally leaves for the source:

  • Survey methodology and the full response breakdown from more than 300 security leaders, useful if you need to benchmark your programme.
  • Expanded findings on agentic security posture management and agentic detection and response, including how Salt frames the control model.
  • The report's discussion of machine-to-machine visibility, Shadow AI, and the Agentic Action Layer in more implementation detail.
  • The source article's view of how executive scrutiny, board concern, and release delays are shaping AI security decisions.

👉 Read Salt's research on the 1H 2026 state of AI and API security →

AI agent visibility gaps: is your API security keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Agentic AI governance now depends on identity, not just content filtering. The source correctly shows that prompts are only one layer of risk, because the real execution path runs through APIs, MCP servers, and connected systems. That means the identity of the agent, the scope of its privileges, and the traceability of its actions matter more than perimeter controls alone. For practitioners, this reframes AI security as a governance problem spanning IAM, NHI, and runtime enforcement.

A question worth separating out:

Q: Who is accountable when an AI agent accesses sensitive data it was not meant to use?

A: Accountability sits with the team that approved the agent, its connectors, and its policy boundaries, not with the runtime behaviour alone. Organisations need ownership for intent, permissions, monitoring, and validation so they can prove whether the agent stayed inside its approved purpose. Without that, audit and regulatory response become retrospective guesswork.

👉 Read our full editorial: AI agent visibility gaps are exposing the agentic action layer



   
ReplyQuote
Share: