Aligning AI Speed with AI Trust: AI Agent Security Insights for CISOs and Security Leaders
AI agent security is the practice of governing two separate things: what an autonomous AI system is allowed to reach, and what it is allowed to do. Most enterprises have built a program for the first one. Almost nobody has built one for the second, and that's where the losses are starting to show up.
In Episode 7 of NetApp's Architecting Intelligence, Morphisec's own Brad LaPorte sat down with host Russell Fishman, Senior Director of Solutions Product Marketing and Field Advocacy at NetApp, to talk about what breaks when AI stops giving advice and starts taking action inside enterprise systems.
Below we've pulled out the takeaways that matter most for CISOs, data leaders, and anyone putting an agent into production this quarter.
Key Takeaways
- Adoption is compounding. Governance is contracting. Gartner expects roughly 40% of enterprise applications to embed task-specific AI agents by the end of 2026, up from under 5% in January 2025. IBM's 2026 Cost of a Data Breach report found only 32% of breached organizations had an AI policy in place, down from 37% the year before.
- Data trust and execution trust are two different problems. Data trust asks what an agent can reach. Execution trust asks what an agent can do. They need different controls, different timing, and usually different owners.
- Zero trust was built for admission, not for action. It answers whether an identity belongs inside. It was never designed to judge what that identity does over the next six hours.
- Not every AI incident is an attack. A coding agent told to clean up old records can destroy a production database in seconds with no adversary involved. The loss is identical.
- The budget is already moving to prevention. Gartner projects preemptive security solutions will represent 50% of IT security spending by 2030, up from less than 5% in 2024.
What Is the AI Trust Gap?
The AI trust gap is the distance between how fast an organization deploys AI and how ready its security and data controls are to govern it. That distance is growing.
Put the two numbers side by side. Gartner expects about 40% of enterprise applications to carry a task-specific AI agent by the end of 2026, up from under 5% at the start of 2025, while IBM's 2026 breach research found only 32% of breached organizations had any AI policy at all, a figure that fell year over year.
Adoption is compounding. Governance is going backwards.
Security has watched this movie before. A technology gets adopted faster than the control plane around it, and the industry spends three years paying the difference. Cloud did it, then SaaS did it, and agents are doing it now on a far shorter clock.
Speed is what makes this round different. A misconfigured cloud bucket sits there exposed until somebody finds it. An agent with too much access doesn't wait to be found. It acts.
Data Trust and Execution Trust Are Two Different Problems
This was the spine of the episode, and it's the reframe most security programs need. Most organizations run a single AI governance program against two problems that behave nothing alike:
- Data trust. What can this agent reach? This is a visibility and classification question. It lives at the data layer and it gets solved before anything runs, through inventory, classification, and access scoping.
- Execution trust. What can this agent do? This is a runtime question. It lives at the moment of action, and it can only be solved while the agent is running, because the risk sits in the action rather than in the request.
Here's how you tell whether an organization has merged them. Ask what the AI policy says and you'll get a document describing approved tools and approved data. Then ask what happens at 2am when an approved agent with approved access does something outside its intended scope. That question usually lands in silence.
One piece of sequencing gets skipped almost every time: inventory has to come before policy, because you cannot govern access you have never mapped. Teams write the policy first because it's the thing you can finish in a quarter.
The failure shows up in the org chart before it shows up in the logs. IBM found that only 19% of organizations coordinate between their AI governance and security teams. The data team classifies beautifully and has no view of what is executing against it, while the security team watches execution without knowing whether the file just touched was public or regulated. Neither side sees the whole event.
What Changes When AI Moves from Advice to Action
Copilots and chatbots have been in production for a couple of years and most enterprises have gotten comfortable with them. Agents are a different category of risk rather than a larger dose of the same one.
A chatbot that gets something wrong produces a bad answer, and a person reads it and decides what to do next. There's a human standing between the mistake and the consequence. An agent that gets something wrong produces a bad action. Nobody is standing in between.
The clearest example isn't even an attack. A coding agent instructed to clean up old records read that instruction at maximum scope and destroyed the production database along with its backups, in seconds. No adversary. No malware. No exploit. The agent did what it was told.
Be honest about what that means. No security product stops an authorized agent from carrying out an instruction it was legitimately given, and any vendor telling you otherwise is selling you something. What a control can do is narrow what that agent was ever able to reach, then cut the action short once it goes outside its lane.
Now hold your incident response plan up against machine speed. Every playbook in use today was written around human-paced mistakes, where dwell time is measured in days and there is room to catch it. Against a multi-step agent workflow, one bad decision compounds into four or five before anyone gets paged. Your mean time to respond is now longer than the incident.
Where Zero Trust Runs Out for AI Agents
Zero trust is still the right model. It's incomplete for autonomous systems, and not because anyone implemented it badly.
Zero trust answers one question extremely well: is this identity allowed in? Verify explicitly, least privilege, assume breach. Those principles are sound and they should stay. But it remains an admission control model, a bouncer at a door.
Agents don't behave like someone walking through a door once. They authenticate, then read across datasets and trigger actions continuously for hours, and every one of those actions is technically authorized because it happens under credentials the organization granted. So the failure never appears at authentication. It appears afterward, when an authorized agent takes an action that sits inside its permissions and outside its intent.
There's a practical problem underneath this that few teams say out loud. A tightly constrained agent is often a useless agent, so permissions get over-granted and teams trade control for utility because the product won't work otherwise.
Gartner has put a number on where that ends up. It expects 40% of enterprises to demote or decommission autonomous AI agents by 2027 because of governance gaps discovered only after a production incident.
The fix is structural: the control has to travel with the action instead of sitting at the perimeter checking badges.
Moving the Control to the Moment of Execution
This is where preemptive cyber defense earns its keep, and it's the argument Morphisec has been making since long before agents arrived. Detection asks what happened. Prevention decides what is allowed to happen, and against a system that finishes its objective in under ten seconds only one of those has time to matter.
Morphisec builds on a simple principle: put the control at the moment code executes, on the endpoint where the AI runs.
- Automated Moving Target Defense. Automated Moving Target Defense (https://www.morphisec.com/automated-moving-target-defense/) works deterministically at runtime, with no signature, no prior knowledge of the threat, and no cloud lookup. That's what lets it stop in-memory and fileless techniques detection tools only see after the fact.
- Endpoint-native AI discovery and control. Morphisec AI Usage Control (https://www.morphisec.com/ai-hub/) inventories every AI tool, agent, browser extension, and model connector on a device, including the shadow AI that never crosses a network gateway. Local language models, command line agents, and IDE plugins are structurally invisible to proxy tools. None of them are invisible on the endpoint.
- Blast radius, mapped before the incident. Adaptive Exposure Management (https://www.morphisec.com/platform/#adaptive-exposure-management) shows which accounts, hosts, and critical resources each tool can reach. That's the inventory the policy is supposed to be built on.
- Runtime enforcement. Tools and agents operating outside sanctioned policy get terminated at the endpoint, while approved work continues.
None of that replaces good data governance. It sits next to it. The data layer has to be trustworthy and the action layer has to be contained, and an organization doing only one of those doesn't have a program yet. NetApp makes the same defense-in-depth argument from the storage side, which is part of why the conversation worked.
Prevention Beats Detection Every Time
If there's one framework to take away from the episode, it's this. Map before you deploy, with a full inventory of what AI is running, what data each tool can reach, and what actions each one can take. Most organizations cannot produce that list today, and you cannot govern what you never mapped.
Then change the goal. Build for containment instead of perfection, because you aren't going to prevent every bad agent decision and chasing that target is how programs stall at the pilot stage. What matters is how fast a problem gets caught and how small the blast radius stays.
The market is already moving. Gartner projects preemptive security will account for 50% of IT security spending by 2030, up from under 5% in 2024, and has said plainly that detection and response alone will no longer keep assets safe from AI-enabled attackers.
You already know how to ask whether your data is trustworthy. Start asking whether your actions are.
See Preemptive Defense Against AI Risk
Watch Episode 7 of Architecting Intelligence on NetApp.com, then see what endpoint-native AI discovery and runtime control look like against your own environment.
Stay up-to-date
Get the latest resources, news, and threat research delivered to your inbox.