Control stack
The six layers every AI agent program needs.
Zero Trust for AI agents is not just network segmentation. It is a chain of identity, authorization, runtime policy, tool governance, containment, and provenance that keeps working after agents connect to real systems.
Unique identity for every human, service account, model workflow, and AI agentJust-in-time access and short-lived credentials for tools, APIs, repos, and cloudModel gateway policy for provider routing, logs, token budgets, and data handlingMCP and tool registry controls for what agents can call, read, write, and changeRuntime containment with sandboxing, egress limits, approvals, and revocationProvenance logs that tie prompt, model, tool call, command, artifact, and reviewer
AI Agent Security2026-08-23
Zero Trust in the age of AI agents means every human, model, agent, device, API, repository, and workflow must prove identity, need, context, and authority before action. Network location is no longer the trust boundary.
AI in Security2026-04-01
NIST's February 2026 work on AI agent identity and authorization is a timely signal that the real enterprise risk is no longer model output alone, but what agents are allowed to do, prove, and audit once they start acting.
AI in Security2026-05-15
AWS used mid-May 2026 guidance to make a useful point for defenders: secure AI programs start with identity, access, and guardrails in the prototype phase rather than after agents reach production.
AI in Security2026-07-11
Security teams do not need every product team wiring its own OpenAI, Anthropic, Bedrock, Vertex AI, and coding-agent credentials. A centralized LiteLLM gateway can make GenAI and agentic-code usage more controlled, vetted, auditable, and cost-aware.
AI in Security2026-04-24
Model Context Protocol can make AI tools dramatically more useful, but it also expands trust boundaries. Security teams should treat MCP like a privileged integration layer: sandbox servers, minimize scopes, block token passthrough, defend against SSRF, and review every tool as a potential remote-action surface.
AI in Security2026-08-08
Frontier AI models are moving from code suggestions to sustained cyber operations. Security teams should assume quiet, multi-step AI-driven intrusion attempts are becoming realistic and update controls before attackers operationalize them.
CISOs, platform security teams, AI platform owners, and security architects2026-08-19
A practical comparison of LiteLLM, Portkey, and AWS multi-provider GenAI gateway patterns for security teams centralizing model access, policy, logging, and token controls.
AppSec teams, security engineers, platform security teams, developer experience teams, and CISOs2026-08-22
Reusable security-team workflows for Antigravity CLI, GitHub Copilot CLI, Claude Code, and OpenAI Codex, including secure code review, dependency triage, CI/CD audit, sandboxed remediation, and agent governance.
AppSec teams, security engineers, developer platform teams, and CISOs2026-08-22
A security-focused comparison of Claude Code, OpenAI Codex, GitHub Copilot CLI, Antigravity CLI, and Cursor for secure code review, vulnerability remediation, AppSec workflows, and enterprise guardrails.
AppSec teams, software security engineers, platform teams, and developers2026-08-21
Practical AI-assisted GitHub security skills for code scanning, secret scanning, pull request review, dependency triage, and secure coding workflows.