Provided by Nutanix
AI Agent Security Requires a Defense-in-Depth Architecture
Autonomous AI agents can reason, make decisions, and take action across enterprise environments. However, their ability to operate independently introduces security risks that traditional application-level controls were not designed to address. According to Oscar Wahlberg, senior director of product management at Nutanix, treating these risks as a single security challenge can leave critical gaps in an organization’s architecture.
“Guardrails designed to detect malicious prompts won’t stop agents from hallucinating or taking actions they should never take, such as accidentally deleting a database or using authorized credentials to expose sensitive data,” Wahlberg says. “This is the core security challenge companies face as they move autonomous AI agents from experimentation into production.”
Once AI agents receive execution privileges across the data center, security must extend beyond the application or model layer. Organizations need a defense-in-depth strategy that covers infrastructure, storage, compute, networking, and management control planes. Each layer should address a distinct category of risk instead of duplicating controls across the technology stack.
No single security control or vendor can provide complete protection for agentic AI environments. Effective AI agent security depends on multiple layers working together. By dividing responsibilities across the stack and applying Zero Trust principles, organizations can create a framework that limits risk while allowing autonomous agents to operate at scale.
This approach can be organized into three core security layers, each with a defined role in protecting AI agents: the infrastructure layer, the network layer, and the control plane layer.
Infrastructure layer: Establishing trust for AI agents
The infrastructure layer establishes the root of trust for the environment in which AI agents operate. Its fundamental responsibility is to answer a basic question: Who or what is running inside the environment?
A trusted identity is a prerequisite for every other security control. Before an organization can trust an agent’s behavior, it must verify the integrity of the infrastructure hosting that agent. When an AI agent requests permission to perform an operation, the environment must be able to confirm that the request originated from a legitimate, authorized agent rather than an impersonator.
Achieving this level of assurance requires technologies that establish trust at the hardware level. Examples include secure boot, platform attestation, confidential computing, and controls that prevent unauthorized access both within and outside the server environment.
For regulated industries such as financial services, the infrastructure layer can isolate AI workloads and ensure that agents, models, and runtime environments remain within their assigned boundaries. This helps reduce the risk of model tampering, runtime compromise, supply chain attacks, and unauthorized access to sensitive AI workloads.
Hardware-based security is especially important for agentic AI because agents may interact with sensitive systems and data without requiring a human to approve every individual action. Strong infrastructure controls provide the trusted foundation on which identity, authorization, and runtime policies can operate.
Network layer: Controlling how AI agents communicate
As AI agents communicate with other agents, APIs, applications, databases, and enterprise systems, they create a level of dynamic interaction that traditional static network configurations were not designed to manage. Agents may call APIs, query data sources, invoke tools, and create additional agent workflows, generating extensive east-west traffic across the environment.
This complexity can make it difficult for security teams to understand how information is moving through the infrastructure. Without appropriate network security controls, lateral movement, unauthorized access, and data exfiltration can remain hidden within legitimate-looking agent activity.
“We need to treat AI agents as a new class of network identity, allowing agents to communicate with other agents or data sources only when explicitly permitted,” says Wahlberg. “That means moving from strictly static rules to dynamic policy enforcement.”
Nutanix’s Agent Gateway, part of the Nutanix Agentic AI solution, is designed to provide a managed layer for governance and cost control across autonomous AI agents. When combined with Zero Trust segmentation, Nutanix Flow micro-segmentation, and integrations with networking providers such as Cisco Secure AI Factory, Agent Gateway can help enterprises manage interactions between agents, models, data sources, and business applications.
The network layer helps control lateral movement, restrict data extraction, and govern the systems with which an AI agent can communicate. A Zero Trust framework that blocks access by default and continuously monitors agent interactions is particularly important because autonomous agents may exhibit unexpected or untrustworthy behavior.
Integration between Nutanix software, Cisco UCS servers, and Cisco AI PODs can also provide a more streamlined physical foundation for AI factories by combining compute, storage, and networking capabilities. Together, these technologies support the infrastructure required to deploy and operate enterprise AI workloads.
Control plane layer: Managing what AI agents are allowed to do
The control plane acts as the operational center for agentic AI security. It provides a centralized location for managing agent privileges, tool access, resource consumption, policy enforcement, and runtime visibility.
One of the most important advantages of a centralized control plane is consistency. Instead of recreating policies for every individual agent, IT and security teams can apply governance rules from a single point of control.
“The Agent Gateway acts as a universal endpoint for different models and tools, so IT teams can configure agents to communicate through a single control point,” Wahlberg explains.
A centralized AI gateway allows administrators to observe, audit, and control access to models and enterprise tools. It can also help protect sensitive data and manage privileged access through Model Context Protocol (MCP) tools.
This layer is designed to mitigate risks such as privilege abuse, unauthorized tool usage, runaway agents, data leakage, and excessive model consumption. For example, an agent caught in a runtime loop could continue generating requests and consuming tokens, resulting in unexpected costs and reduced system performance.
Effective governance must therefore function as a runtime control system rather than simply serving as a compliance record. Organizations need continuous visibility into agent behavior, real-time policy enforcement, and the ability to revoke access or limit resource consumption when an agent behaves unexpectedly.
Why one-size-fits-all security fails in agentic AI environments
One of the most common architectural mistakes is assuming that a single security model can be extended across every layer of the AI stack. Application-level controls cannot solve hardware-level trust problems, while legacy network rules may not be flexible enough to manage dynamic agent interactions.
When organizations apply the wrong controls to the wrong layer, they may create systems that prevent AI agents from completing legitimate tasks or leave critical security gaps open. A one-size-fits-all approach can also create performance issues and increase operational complexity.
“When companies do not assign specific responsibilities to the appropriate layers, they encounter governance blind spots,” Wahlberg says. “The model output may be protected, but data could still leak between agents. Or the network may be secured, but the organization may lack the control plane visibility needed to identify an agent stuck in a runtime loop and consuming excessive tokens.”
Focusing exclusively on the AI model creates some of the largest security gaps. Prompt guardrails may detect malicious instructions, but they cannot always prevent an agent from misusing legitimate credentials, accessing an unauthorized system, or taking an unintended action.
A full-stack defense-in-depth strategy helps contain these risks. If a model-level threat bypasses initial filters, hardware-based trust, network isolation, agent identity controls, and centralized authorization policies can provide additional protection.
How Intel, Cisco, and Nutanix support defense-in-depth AI security
The collaboration between Intel, Cisco, and Nutanix illustrates how a layered security architecture can support an enterprise-grade AI cloud. Each company contributes capabilities at a different part of the AI infrastructure and security stack.
Intel provides the computing foundation for AI agent workloads. Its hardware-based security features and confidential computing capabilities help protect the execution environment, while accelerators support more efficient AI processing. Intel Xeon 6 processors with built-in Intel Advanced Matrix Extensions (AMX) can accelerate AI inference without requiring organizations to rely exclusively on high-cost GPUs.
Cisco provides networking and security capabilities that help manage communication between AI agents, enterprise tools, data sources, and applications. This secure fabric can support segmentation and policy enforcement as agent interactions become more dynamic.
Nutanix provides the software platform and management capabilities that help reduce infrastructure silos, enforce privileges, provide operational visibility, and manage costs. Its centralized control plane connects the different layers into a defense-in-depth architecture designed to help enterprises deploy and scale agentic AI more securely.
According to Wahlberg, organizations currently underestimate the importance of the control plane. A mature control plane simplifies day-two operations after deployment and provides the continuous observability, policy enforcement, and token governance required to keep autonomous AI agents secure and cost-effective in production.
“Beyond model and tool selection, managing agent deployment and access to models and business tools through a tightly integrated, full-stack platform will be critical to the success of AI projects,” he says. Organizations are expected to move from a small number of AI use cases to thousands of autonomous agents supporting business operations.
Technology leaders should begin building a centralized governance layer that can manage agent identities, tool permissions, data access, and token budgets in real time. This control point provides the operational foundation needed to expand agentic AI safely.
“You can’t build an AI system without making many complex decisions,” Wahlberg explains. “A defense-in-depth strategy requires a control plane that can communicate with multiple vendors and infrastructure environments.”
Learn more about Nutanix Agentic AI solutions here.
Sponsored articles are content created by companies that pay us to post or have a business relationship with VentureBeat, and are always clearly marked. For more information please contact us [email protected].
Source: venturebeat.com


