AI Agent Security Is an Engineering Discipline
AI security requires defined requirements, enforceable controls, designated ownership, and evidence that protections work. As AI capabilities advance, organizations must accelerate security engineering, expand access to defensive tools, and share effective practices more quickly.
Security fundamentals still apply to AI systems
The internet and cloud computing changed how software operates, but the core responsibilities of security remain the same: establishing identity, controlling access, limiting exposure, and verifying that protections work.
AI agents introduce new capabilities, including the ability to reason, use tools, and adapt their actions based on the data they encounter. These capabilities require established security principles to be applied to new operating conditions.
This pace creates pressure for organizations that want the productivity benefits of AI while practices for managing and securing these systems continue to evolve.
Secure every layer of the AI agent stack
Applications depend on code, data, identity, services, and infrastructure. AI security depends on how these components interact with AI agents. Learn more about where security fits in the AI agent stack.
Models provide functionality. The harness organizes context, tools, and workflows. The runtime environment provides the infrastructure where actions are performed. Every layer has security responsibilities, and controls across the full stack are necessary as data, instructions, and actions move through the system.
Consider an agent updating a customer record. A malicious instruction in an attachment could cause the agent to attempt to export customer data to an unauthorized destination.
Network policies should block unauthorized transfers, while secure logs should record attempted tool invocations, authorization decisions, and outcomes. This evidence helps security teams identify which tools were used and which destinations they attempted to reach.
Permission to update customer records should not automatically include permission to export that data. Agents can request additional access, but they must not approve that access themselves.
Build security into how AI agents operate
Security boundaries must remain in place even when agents make incorrect decisions. Because the operating environment determines what an agent can do, organizations should restrict access to files, network destinations, and processes regardless of the agent’s reasoning.
Instructions and safeguards can guide agent behavior, but effective AI security also requires enforceable boundaries.
Each agent needs a traceable identity and credentials specific to its assigned tasks. Organizations should define what information agents can access, which systems they can modify, and which actions require approval. Consequential actions and permission changes should require human approval.
Teams must also verify the source and integrity of the tools, skills, and dependencies used by agents. If something goes wrong, secure records of tool invocations, approval decisions, and results can help investigators reconstruct what happened. Clear procedures for revoking access and containing incidents make that evidence actionable.
NVIDIA OpenShell is an open-source secure runtime that provides sandboxed execution, enforces policies beyond the scope of agent access, and controls how agents access data, networks, and system resources.
The Open Secure AI Alliance brings together partners building on OpenShell. Cisco DefenseClaw adds a governance layer, while JFrog integrates with OpenShell to scan and validate agent skills and enforce policies governing which skills agents can access.
Use security evidence to validate AI agent deployments
Before deployment, engineering teams need evidence that appropriate controls block attempts to obtain credentials or send sensitive data to unauthorized destinations beyond the agent’s approved scope.
Testing should cover permission changes and attempts to bypass monitoring. Tests should be repeated after significant changes to models, tools, or workflows.
The designated owner should use these results to determine whether the system is ready for deployment and ensure that failed tests lead to corrective action. Failures discovered during testing or operation must be reproduced, investigated, and addressed. Each finding can become a repeatable test that verifies the fix continues to work in future releases.
For example, CrowdStrike SafeMind uses repeated attack simulations to test and strengthen defenses. Palo Alto Networks Prisma AIRS supports continuous red teaming as models and applications change.
Give defenders the right AI security tools
Investigating failures requires capable tools suited to the task, data, and operating environment. Open and closed models address complementary needs.
Closed models offer managed functionality and services. Open models give defenders options to inspect relevant components, adapt strategies, and address the infrastructure they control.
During an incident, this control can help teams reproduce failures and test fixes against their own systems while keeping sensitive evidence in their environment.
Capable AI can support security teams by helping discover vulnerabilities, verify fixes, and investigate attacks. Its value should be measured through reproducible discoveries, verifiable fixes, and reduced response times.
Examples include Capital One VulnHunter for AI-powered code security and ReversingLabs Spectra Assure, which analyzes software packages with AI to detect malware and tampering.
Strengthen AI security through open collaboration
Sharing evidence about what failed, which controls worked, and how fixes were validated helps other teams strengthen their systems.
NVIDIA security research and the Open Secure AI Alliance support the exchange of research, practical tools, and expertise across the broader security community.
AI security is an engineering issue. Every agent deployment requires enforceable boundaries, responsible ownership, and evidence that its protections work. Open research and shared tools can help more defenders meet that standard and improve it as AI capabilities advance.
Learn more through NVIDIA security research and join the Open Secure AI Alliance.
Source: blogs.nvidia.com


