How to Effectively Secure AI Agents
Foundations
The Foundational Premise
Despite the differences in product offering, even modern approaches to securing AI Agents all share a very traditional underlying premise: first the subject of security exists, then the means of securing it. All the assumptions that follow owe their limitations to this foundational premise.
NOMENON's Foundation
NOMENON's AI Enforcement Architecture rejects the foundational premise. Instead, it implements its own law: what is legitimate shall exist, and what is illegitimate shall not. There is no existence pre-security and there is no existence post security failure.
What determines whether an agent action is legitimate?
What follows is six premises, not six product categories. Each one is held by several vendors across several categories at once, so the axis is the assumption — not the aisle it is sold in. Every premise is stated in its holders' own words, followed by what that premise leaves possible.
Agents can be governed once they are found.
Held by: Palo Alto/CyberArk, Cisco/Astrix, Zscaler, Neo, NewCore, Segura
- The agent is created
- It begins acting
- Discovery locates it
- Governance is applied
- The interval between creation and discovery is permanent
An inventory is a record of what has already happened. Every agent on it acted before it appeared on it.
“This extension ensures no agent goes unnoticed, whether created intentionally or through autonomous processes.”
“Discover and secure every AI agent and non-human identity.”
AI Asset Management “discovers embedded AI in SaaS and internet traffic, identifies AI agents and MCP servers in public cloud environments.”
NOMENON rejects the premise that agents must be found.
- An agent requests access
- It arrives without standing
- Enrollment is the request
- The acting population and the enrolled population are the same set
There is nothing to find, because acting is how an agent enrolls.
The agent holds its own identity and authority.
Held by: Keycard, NewCore, Palo Alto/CyberArk, Segura
- Identity is issued to the agent
- Credentials are delivered into its runtime
- Scope and duration are minimized
- Compromise of the agent is compromise of the authority
Shortening a credential's life reduces the window. It does not change what the holder can do inside it.
Agents built using Keycard “have their own identity, delegate access per-task and operate with no standing privileges or static credentials.”
“When an agent starts, it automatically receives its identity through runtime attestation.”
“AI agents are first-class identities with their own lifecycle, trust scoring, and revocation path, not service accounts in disguise.”
Agents are “governed logical entities that may rely on multiple operational identities, credentials, and delegation mechanisms.”
NOMENON rejects the premise that the actor should hold what governs it.
- Authority is defined outside the agent
- The agent never carries it
- Compromise yields nothing to present
What an attacker holds after compromise is the measure. Here, it is nothing.
Legitimacy is determined when access is requested.
Held by: Neo, Aembit, Keycard, Zscaler, Palo Alto/CyberArk
- A request is formed
- It reaches a decision point
- Policy is evaluated
- The request is permitted or refused
- Refusal must remain possible, so the request must remain formable
A decision made at the moment of access requires that unauthorized access be attemptable. The volume of decisions is the volume of attempts.
The MCP Identity Gateway “validates tokens and enforces policy on every MCP request, then exchanges credentials on the agent's behalf.”
An Agent Registry “that tracks which agents are permitted to access what.”
And the admission underneath it — behavior “will be tracked continuously using advanced machine learning and behavioral analysis… critical for securing autonomous AI agents where preventive policies may be difficult to apply and enforce.”
NOMENON rejects the premise that legitimacy is decided at the moment of access.
- Legitimacy is established before arrival
- Only legitimate states form
- There is no request to adjudicate
No decision is made at request time, because nothing illegitimate arrives to be decided about.
The network exists, and identity is applied to it.
Held by: Zscaler, Aembit
- A network is built
- Resources are reachable on it
- A broker, proxy, or edge is inserted
- Identity is checked at the insertion point
- The underlying reachability persists
Concealing a reachable resource does not make it unreachable. An agent that infers correctly arrives at something that is there.
“A proxy or agent intercepts outbound requests, validates the workload's identity, and injects credentials; no code changes required.”
Aembit Edge is “a multiprotocol transparent forward proxy deployed alongside workloads that intercepts access requests between client and server workloads.”
Enterprises can “onboard AI agents into the same fabric used today to connect users and applications,” then “hide internal applications from direct exposure.”
NOMENON rejects the premise that topology precedes identity.
- Identity constitutes the path
- Unenumerated paths have no existence
- A correct inference terminates in nothing
Agents can't infer what does not exist.
Governance is divisible by domain.
Held by: Segura, Neo, Keycard, Zscaler — each defending a different boundary
- Each product governs its layer
- Boundaries are declared
- Gaps between products are unowned
- Attribution across a chain must be reconstructed after the fact
Attribution is a product because the architecture does not produce it. Four products with four boundaries leave the seams to the buyer.
Prompt injection, tool injection, and model intent validation “are outside today's current scope.”
Neo “gives SecOps teams the inventory, posture intelligence, attribution, and policy control to manage enterprise-wide agentic transformation.”
“AI agents communicate with each other and with enterprise data through emerging protocols like MCP and A2A. Most security tools can't see these channels at all.”
NOMENON rejects the premise that governance can be divided by layer.
- Identity, path, and runtime are one determination
- The chain is a property of instantiation
- Attribution is not reconstructed
The audit is not a product. It is what the architecture already is.
The thing to govern is the action.
Held by: Neo, Keycard, Aembit
- Actions are enumerated
- Rules are written per action
- New actions appear
- Rules are added
- The set is never closed
An inferential actor generates novel requests faster than an enumerable ruleset closes. The gap widens with capability.
AI agents are “giving software the ability to reason, act, invoke tools, and move through workflows with valid user permissions.”
Delegation patterns include “agents impersonating other agents or humans under policy constraints for specific operational workflows.”
“Neo is betting that the bigger market is the control layer: not who the agent is, but what it is allowed to do.”
NOMENON rejects the premise that an unbounded action space can be enumerated.
- Legitimacy attaches to existence, not to acts
- The set to govern is finite
- Capability growth does not widen the gap
The ruleset does not race the model.
Six premises, their control points, and what each one leaves possible
| Premise | Control point | What remains possible | Proof |
|---|---|---|---|
| Agents must be found | Inventory | Everything before discovery | Coverage claim |
| The agent holds authority | Credential issuance | Full use of the credential | Token validity |
| Legitimacy decided on request | Request time | Every attempt | Decision log |
| Network precedes identity | Broker or edge | Correct inference | Concealment |
| Governance is per-domain | Each layer | The seams | Reconstructed attribution |
| The unit is the action | Rule per action | Unenumerated actions | Ruleset coverage |
| NOMENON | Instantiation | Only legitimate states | The architecture |
One page to take into a review. Each row is a premise established above, not a product category — several vendors hold more than one of them at the same time.
A compromised agent attempts unauthorized data access
The same incident, run through every premise. The bar is what remains possible; the mark is where that architecture first gets to act.
What NOMENON does not claim
NOMENON does not claim that discovery, policy, monitoring, IAM, or guardrails have no value. Each does something real, and an environment running them is better off than one that is not.
- Policy
- Communicates intent. Intent still has to be stated somewhere, by someone accountable for it.
- Discovery
- Produces an inventory worth having. It is a record, and records are how organizations answer questions.
- Monitoring
- Supports investigation and accountability, and is the only thing that answers “what happened” after the fact.
- IAM
- Controls initial access, and remains the boundary for the humans and legacy systems that are not going anywhere.
- Guardrails
- Can reduce undesirable model interactions at the input and output boundary.
- Runtime brokers
- Are a real control point for traffic that must traverse them.
None of them, individually, determines the complete set of states an agent can create. That is the only claim on this page.
What changes in your environment
- Where does it sit?
- Not between the agent and the resource. Identity constitutes the path, so the control is in how the path is formed — not in an inspection point inserted along one that already exists.
- Does it replace existing controls?
- No. Policy, IAM, and monitoring keep doing what they do. What changes is what remains possible when one of them is wrong.
- Does it require model cooperation?
- No. The architecture does not ask the agent to comply, disclose, or behave. It determines what the agent can make happen.
- What data does it inspect?
- It does not adjudicate content. Legitimacy is a property of what exists, not of what a payload turns out to contain.
- How is authority defined?
- Outside the agent, and never delivered into it. What an attacker holds after compromising an agent is nothing that can be presented.
- What happens to existing traffic if NOMENON is unavailable.
- How a first deployment is scoped, and what can be tested before broad rollout.
- Which of your agent populations is the honest place to start.
The right control is the one that matches what you can accept
- Choose discovery when an inventory is enough.
- Choose credentials when a shorter window is enough.
- Choose a decision at request time when a refusal is enough.
- Choose enforcement when the prohibited state must not exist.
Your data. Your environment. Your terms.
Evaluate the architecture against your environment.