NOMENON
NOMENON Manifesto Cases
© 2026 Nomenon Technologies, Inc. All Rights Reserved Patents Pending
Monitoring Rogue Agents Is Not Prevention

How to Effectively Secure AI Agents

Why Policy and Guardrails Fall Short
Assumptions are foundational to security. Take the iconic example of the firewall. The implemented rules are determined by the device's use case(s). But underlying those rules is the basic assumption that the device is publicly addressable at all.
To effectively determine the impact and applicability of a security solution within your environments, you must first understand their underlying assumptions.

Foundations

The Foundational Premise

Despite the differences in product offering, even modern approaches to securing AI Agents all share a very traditional underlying premise: first the subject of security exists, then the means of securing it. All the assumptions that follow owe their limitations to this foundational premise.

NOMENON's Foundation

NOMENON's AI Enforcement Architecture rejects the foundational premise. Instead, it implements its own law: what is legitimate shall exist, and what is illegitimate shall not. There is no existence pre-security and there is no existence post security failure.

The question beneath the category

What determines whether an agent action is legitimate?

Discovery says
what we found
Policy says
what the agent should do
Monitoring says
what behavior should be detected
NOMENON says
what the architecture permits to exist

What follows is six premises, not six product categories. Each one is held by several vendors across several categories at once, so the axis is the assumption — not the aisle it is sold in. Every premise is stated in its holders' own words, followed by what that premise leaves possible.

Premise 01 · Existence

Agents can be governed once they are found.

Held by: Palo Alto/CyberArk, Cisco/Astrix, Zscaler, Neo, NewCore, Segura

What follows
  1. The agent is created
  2. It begins acting
  3. Discovery locates it
  4. Governance is applied
  5. The interval between creation and discovery is permanent
The unavoidable shortcoming

An inventory is a record of what has already happened. Every agent on it acted before it appeared on it.

Their own words
“This extension ensures no agent goes unnoticed, whether created intentionally or through autonomous processes.”
CyberArk·Securing Identities for the Agentic AI Landscape·September 2025
“Discover and secure every AI agent and non-human identity.”
Cisco·Intent to acquire Astrix Security·May 2026
AI Asset Management “discovers embedded AI in SaaS and internet traffic, identifies AI agents and MCP servers in public cloud environments.”
Zscaler·Zenith Live·June 2026

NOMENON rejects the premise that agents must be found.

  1. An agent requests access
  2. It arrives without standing
  3. Enrollment is the request
  4. The acting population and the enrolled population are the same set

There is nothing to find, because acting is how an agent enrolls.

Premise 02 · Authority

The agent holds its own identity and authority.

Held by: Keycard, NewCore, Palo Alto/CyberArk, Segura

What follows
  1. Identity is issued to the agent
  2. Credentials are delivered into its runtime
  3. Scope and duration are minimized
  4. Compromise of the agent is compromise of the authority
The unavoidable shortcoming

Shortening a credential's life reduces the window. It does not change what the holder can do inside it.

Their own words
Agents built using Keycard “have their own identity, delegate access per-task and operate with no standing privileges or static credentials.”
Keycard·Ian Livingstone, CEO, launch release·May 14, 2026
“When an agent starts, it automatically receives its identity through runtime attestation.”
Keycard·Launch release·May 14, 2026
“AI agents are first-class identities with their own lifecycle, trust scoring, and revocation path, not service accounts in disguise.”
NewCore·Emerges from stealth·June 15, 2026
Agents are “governed logical entities that may rely on multiple operational identities, credentials, and delegation mechanisms.”
Segura·AI Agent Identity Security

NOMENON rejects the premise that the actor should hold what governs it.

  1. Authority is defined outside the agent
  2. The agent never carries it
  3. Compromise yields nothing to present

What an attacker holds after compromise is the measure. Here, it is nothing.

Premise 03 · Timing

Legitimacy is determined when access is requested.

Held by: Neo, Aembit, Keycard, Zscaler, Palo Alto/CyberArk

What follows
  1. A request is formed
  2. It reaches a decision point
  3. Policy is evaluated
  4. The request is permitted or refused
  5. Refusal must remain possible, so the request must remain formable
The unavoidable shortcoming

A decision made at the moment of access requires that unauthorized access be attemptable. The volume of decisions is the volume of attempts.

Their own words
The MCP Identity Gateway “validates tokens and enforces policy on every MCP request, then exchanges credentials on the agent's behalf.”
Aembit·IAM for Agentic AI, GA·April 9, 2026
An Agent Registry “that tracks which agents are permitted to access what.”
Zscaler·AI Broker, Zenith Live·June 2026
And the admission underneath it — behavior “will be tracked continuously using advanced machine learning and behavioral analysis… critical for securing autonomous AI agents where preventive policies may be difficult to apply and enforce.”
CyberArk·Securing Identities for the Agentic AI Landscape·September 2025

NOMENON rejects the premise that legitimacy is decided at the moment of access.

  1. Legitimacy is established before arrival
  2. Only legitimate states form
  3. There is no request to adjudicate

No decision is made at request time, because nothing illegitimate arrives to be decided about.

Premise 04 · Topology

The network exists, and identity is applied to it.

Held by: Zscaler, Aembit

What follows
  1. A network is built
  2. Resources are reachable on it
  3. A broker, proxy, or edge is inserted
  4. Identity is checked at the insertion point
  5. The underlying reachability persists
The unavoidable shortcoming

Concealing a reachable resource does not make it unreachable. An agent that infers correctly arrives at something that is there.

Their own words
“A proxy or agent intercepts outbound requests, validates the workload's identity, and injects credentials; no code changes required.”
Aembit·Workload Identity Management·January 28, 2026
Aembit Edge is “a multiprotocol transparent forward proxy deployed alongside workloads that intercepts access requests between client and server workloads.”
Aembit·Proxy·March 6, 2026
Enterprises can “onboard AI agents into the same fabric used today to connect users and applications,” then “hide internal applications from direct exposure.”
Zscaler·Zeus Kerravala, SiliconANGLE·June 2026Analyst

NOMENON rejects the premise that topology precedes identity.

  1. Identity constitutes the path
  2. Unenumerated paths have no existence
  3. A correct inference terminates in nothing

Agents can't infer what does not exist.

Premise 05 · Scope

Governance is divisible by domain.

Held by: Segura, Neo, Keycard, Zscaler — each defending a different boundary

What follows
  1. Each product governs its layer
  2. Boundaries are declared
  3. Gaps between products are unowned
  4. Attribution across a chain must be reconstructed after the fact
The unavoidable shortcoming

Attribution is a product because the architecture does not produce it. Four products with four boundaries leave the seams to the buyer.

Their own words
Prompt injection, tool injection, and model intent validation “are outside today's current scope.”
Segura·AI Agent Identity Security
Neo “gives SecOps teams the inventory, posture intelligence, attribution, and policy control to manage enterprise-wide agentic transformation.”
Neo·Launch·July 20, 2026
“AI agents communicate with each other and with enterprise data through emerging protocols like MCP and A2A. Most security tools can't see these channels at all.”
Zscaler·Zenith Live·June 2026

NOMENON rejects the premise that governance can be divided by layer.

  1. Identity, path, and runtime are one determination
  2. The chain is a property of instantiation
  3. Attribution is not reconstructed

The audit is not a product. It is what the architecture already is.

Premise 06 · Unit

The thing to govern is the action.

Held by: Neo, Keycard, Aembit

What follows
  1. Actions are enumerated
  2. Rules are written per action
  3. New actions appear
  4. Rules are added
  5. The set is never closed
The unavoidable shortcoming

An inferential actor generates novel requests faster than an enumerable ruleset closes. The gap widens with capability.

Their own words
AI agents are “giving software the ability to reason, act, invoke tools, and move through workflows with valid user permissions.”
Neo·Nick Warner, CEO, launch·July 20, 2026
Delegation patterns include “agents impersonating other agents or humans under policy constraints for specific operational workflows.”
Keycard·Launch release·May 14, 2026
“Neo is betting that the bigger market is the control layer: not who the agent is, but what it is allowed to do.”
TNW·On Neo·July 2026Press

NOMENON rejects the premise that an unbounded action space can be enumerated.

  1. Legitimacy attaches to existence, not to acts
  2. The set to govern is finite
  3. Capability growth does not widen the gap

The ruleset does not race the model.

Synthesis

Six premises, their control points, and what each one leaves possible

Premise Control point What remains possible Proof
Agents must be found Inventory Everything before discovery Coverage claim
The agent holds authority Credential issuance Full use of the credential Token validity
Legitimacy decided on request Request time Every attempt Decision log
Network precedes identity Broker or edge Correct inference Concealment
Governance is per-domain Each layer The seams Reconstructed attribution
The unit is the action Rule per action Unenumerated actions Ruleset coverage
NOMENON Instantiation Only legitimate states The architecture

One page to take into a review. Each row is a premise established above, not a product category — several vendors hold more than one of them at the same time.

Operational proof

A compromised agent attempts unauthorized data access

The same incident, run through every premise. The bar is what remains possible; the mark is where that architecture first gets to act.

Existence
The inventory names the agent after the movement.
Authority
Whatever the credential permits, for as long as the window lasts.
Timing
The attempt itself — the request has to be formable to be refused.
Topology
Anything reachable that does not traverse the insertion point.
Scope
The seams between products, and the chain, until it is reconstructed.
Unit
Any action no rule anticipated — the set that grows with the model.
NOMENON
Only legitimate states. The determination is made before t0.
Limits

What NOMENON does not claim

NOMENON does not claim that discovery, policy, monitoring, IAM, or guardrails have no value. Each does something real, and an environment running them is better off than one that is not.

Policy
Communicates intent. Intent still has to be stated somewhere, by someone accountable for it.
Discovery
Produces an inventory worth having. It is a record, and records are how organizations answer questions.
Monitoring
Supports investigation and accountability, and is the only thing that answers “what happened” after the fact.
IAM
Controls initial access, and remains the boundary for the humans and legacy systems that are not going anywhere.
Guardrails
Can reduce undesirable model interactions at the input and output boundary.
Runtime brokers
Are a real control point for traffic that must traverse them.

None of them, individually, determines the complete set of states an agent can create. That is the only claim on this page.

Fit

What changes in your environment

Where does it sit?
Not between the agent and the resource. Identity constitutes the path, so the control is in how the path is formed — not in an inspection point inserted along one that already exists.
Does it replace existing controls?
No. Policy, IAM, and monitoring keep doing what they do. What changes is what remains possible when one of them is wrong.
Does it require model cooperation?
No. The architecture does not ask the agent to comply, disclose, or behave. It determines what the agent can make happen.
What data does it inspect?
It does not adjudicate content. Legitimacy is a property of what exists, not of what a payload turns out to contain.
How is authority defined?
Outside the agent, and never delivered into it. What an attacker holds after compromising an agent is nothing that can be presented.
Answered against your environment, not in the abstract
  • What happens to existing traffic if NOMENON is unavailable.
  • How a first deployment is scoped, and what can be tested before broad rollout.
  • Which of your agent populations is the honest place to start.
The metaphor underneath

Six architectures, calibrated for something that hesitates

Rebuilt “for the workforce that actually exists today: humans, machines, and AI agents.”
NewCore·Emerges from stealth·June 15, 2026
Agents as “an entirely new class of coworker.”
Cisco·Intent to acquire Astrix Security·May 2026

A coworker is provisioned, credentialed, trusted, reviewed, and offboarded. Every control above follows from that shape.

But a coworker reasons within bounds and hesitates. An agent infers — and inference is the method it uses to breach. The industry built six architectures calibrated for something that hesitates.

The decision

The right control is the one that matches what you can accept

  • Choose discovery when an inventory is enough.
  • Choose credentials when a shorter window is enough.
  • Choose a decision at request time when a refusal is enough.
  • Choose enforcement when the prohibited state must not exist.

Your data. Your environment. Your terms.

Evaluate the architecture against your environment.