TL;DR: Enterprise AI security now spans models, prompts, agents, training pipelines, and MCP servers, while the time from initial breach to next-stage attack has collapsed from eight hours to twenty-two seconds, according to Salt. The operational gap is no longer visibility into one platform, but governable access across the full agentic path.
NHIMG editorial — based on content published by Salt: Michael Callahan on the state of enterprise AI security and the Agentic Security Graph
Questions worth separating out
Q: How should security teams govern access when AI agents and humans share the same apps?
A: Treat AI agents as separate identity subjects with their own approvals, scope limits, and monitoring.
Q: Why do autonomous agents make traditional access reviews less effective?
A: Access reviews assume permissions persist long enough to be observed, challenged, and recertified.
Q: What breaks when AI security only covers one cloud or one model stack?
A: Teams lose the ability to see how access moves between platforms, which means they miss the real attack path.
Practitioner guidance
- Map agent reachable access paths Inventory every model, prompt, agent, MCP server, API, SaaS connector, and data store that an AI workflow can reach.
- Tighten agent permission boundaries Reduce broad, inherited access so each agent can only call the tools and data sources required for its task.
- Govern MCP servers as privileged integrations Assign owners, logging requirements, and change control to every MCP server that brokers agent actions.
What's in the full article
Salt's full analysis covers the operational detail this post intentionally leaves for the source:
- How Salt maps agent, MCP server, API, and data-path relationships into a single security graph
- The specific examples behind the SharePoint and multi-cloud exposure scenarios discussed in the interview
- The practical policy and posture details that show how platform-independent agentic security is operationalised
- The board-level framing Salt uses to explain why agentic risk now sits across security, platform, and data teams
👉 Read Salt's analysis of AI agentic security risk and cross-platform exposure →
AI agentic security gaps are widening beyond platform boundaries?
Explore further
AI agentic security is becoming an identity problem before it is a model problem. The article shows that attackers do not need to defeat the model first if they can abuse the agent’s reachable tools, connectors, and data paths. That means the governance question is who or what can act, where, and with which scope. For IAM and NHI teams, the practitioner conclusion is that agent identity must be controlled as a first-class security object.
A question worth separating out:
Q: Who should be accountable for AI agent security incidents?
A: Accountability should sit with the team that owns the agent's business function and permission model, not with a single security tool owner. If the organisation cannot name who approved the agent's scope, who can revoke it, and who reviews runtime exceptions, the governance model is incomplete.
👉 Read our full editorial: AI agentic security gaps are widening beyond platform boundaries