Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

CNAPP and AI agents: where the governance gap appears


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18004
Topic starter  

TL;DR: CNAPP can still secure AI agents at the posture, process, entitlement, and cloud-event layers, but ARMO’s analysis shows the agent decision plane sits above what those domains observe. The practical consequence is that prompt-influenced tool use and induced privilege abuse can remain invisible unless teams add instrumentation above the existing stack.

NHIMG editorial — based on content published by ARMO: Can Existing CNAPPs Secure AI Agents in Cloud Environments? Where Each Domain Stops

By the numbers:

Questions worth separating out

Q: Where do CNAPP controls fail for AI agents in practice?

A: CNAPP controls fail when teams assume posture, process, entitlement, and cloud-event telemetry are enough to explain agent behaviour.

Q: Why do local AI agents complicate identity and access management?

A: They can retain legitimate permissions while changing timing, prioritisation, and action sequence outside human presence.

Q: How can security teams tell whether an AI module adds real coverage?

A: Teams should ask whether the module produces new telemetry at the agent decision plane or only tags data the CNAPP already collected.

Practitioner guidance

  • Map each CNAPP domain to its actual observation point Document which controls are handled by CSPM, CWPP, CIEM, and CDR, then note explicitly where the agent decision plane falls outside each domain.
  • Add application-layer telemetry for AI agents Capture prompt context, tool-call sequences, and per-agent behavioural baselines, then correlate that signal back into cloud and identity telemetry.
  • Separate legitimate use from induced use in entitlement reviews Review whether the same identity can exercise permissions for both expected workflows and externally influenced actions, especially where RAG or other retrieved context feeds the agent.

What's in the full article

ARMO's full blog post covers the operational detail this post intentionally leaves for the source:

  • A domain-by-domain breakdown of how CSPM, CWPP, CIEM, CDR, and AI modules behave in live AI workloads.
  • The runtime-context diagnostic used to separate genuine instrumentation from simple correlation or tagging.
  • Practical architectural examples showing how above-CNAPP telemetry can be correlated back into existing cloud and identity controls.
  • A product-specific explanation of the ARMO runtime layer and how it maps to the agent decision plane.

👉 Read ARMO's analysis of CNAPP coverage for AI agents in cloud environments →

CNAPP and AI agents: where the governance gap appears?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

CNAPP stops at the observation point, not the risk boundary. Each domain inside CNAPP is genuinely useful, but none of them alone can see the agent decision plane where prompt-influenced tool selection happens. That means practitioners should stop asking whether CNAPP is 'AI-ready' in the abstract and start asking which layer each module actually observes.

A question worth separating out:

Q: Should organisations replace CNAPP with a runtime AI security platform?

A: No. CNAPP still provides posture, runtime, entitlement, and cloud-event controls that AI workloads need. The better approach is to keep those layers and add an application-layer control above them that can see agent decisions and correlate them back into existing telemetry. Replacement solves the wrong problem; supplementation solves the visibility gap.

👉 Read our full editorial: Can CNAPP secure AI agents? Where each domain stops



   
ReplyQuote
Share: