Somewhere between the prompt injection demos and the jailbreak panic, the real security problem for enterprise AI shifted. It is no longer mainly about what a model says. It is about what an agent does – which APIs it calls, which data it touches, which actions it takes on production systems. The execution layer is becoming the actual perimeter, and the vendors building there are the ones getting agents past the pilot stage.
The gap between experimentation and production is stark. According to Cisco’s Agent Trust Gap research, published at RSA in March 2026, 85% of organizations are experimenting with agentic AI. Only 5% have reached broad production. Nearly 60% of security leaders say security concerns are the primary barrier. The research is vendor-commissioned – worth noting – but the pattern matches what enterprise teams report independently.
Gartner projects that more than 40% of agentic AI projects will be canceled by the end of 2027, driven by costs, unclear value, and governance gaps discovered only after deployment. That number should focus anyone building or buying these systems.
What is actually going wrong? The OWASP Top 10 for Agentic Applications, published in 2026, names the execution-layer risks directly: tool misuse and exploitation, unexpected code execution, cascading failures across connected tool chains, and rogue agents acting outside their intended boundaries. These are not model-alignment problems. They are operational-control problems – the kind that show up when an agent has access to production systems and insufficient guardrails on what it can do there.
The market is responding with a recognizable pattern. Microsoft shipped Agent 365 to GCC environments on October 1, extending its existing identity and governance stack – Entra for identity, Purview for data governance, Defender for threat detection – to cover agent accounts the same way it covers human users. The message is practical: treat agents as identity-bearing entities inside the systems you already use to manage access.
Snowflake took a similar path at Black Hat 2026, announcing its Cortex AI Gateway alongside the Natoma MCP gateway it acquired in May. Snowflake’s Agent Identity feature is now generally available, giving security teams session-specific data access policies and dedicated agent tracking in audit views. The integration partners – Okta, SailPoint, Saviynt – signal that agent identity is being wired into existing enterprise IAM, not built as a separate silo.
Palo Alto Networks launched Prisma AIRS 3.0 in March with an explicit framing: moving enterprises “from simply observing AI interactions to safely authorizing autonomous execution.” The platform includes an AI Agent Gateway for governing tool calls, Agent Identity Security for assigning governed identities, and Agent Runtime Security for real-time protection against tool misuse and adversarial instructions. CrowdStrike followed in September with Falcon Guardian, its AI Detection and Response product, which treats the endpoint as the epicenter for agent security – discovery, runtime visibility, access controls, and detection all at the execution layer.
DigitalOcean is approaching the same problem from a different angle. Its Agent Droplets, launched in public preview in September, bundle built-in observability into every pricing tier – $50 per month for solo developers, $200 for teams – rather than gating it behind enterprise contracts. The Action Gateway provides a governed MCP endpoint with access to more than 16,000 tools across 500-plus providers, with credentials brokered outside the agent. It is a bet that execution-layer security should be infrastructure-default, not premium-add-on.
The standards side is still catching up. NIST issued a Request for Information on AI agent security in January 2026 and published a concept paper through the National Cybersecurity Center of Excellence in February, exploring runtime constraints, continuous behavior monitoring, and context-aware authorization. But the formal SP 800-53 overlays for agent scenarios remain in development with no firm publication date. Right now, vendor innovation is outpacing the frameworks meant to govern it.
The numbers that matter most: 88% of organizations report confirmed or suspected AI agent security incidents, according to industry surveys. Yet only about 22% treat agents as independent identity-bearing entities with scoped access and audit trails. That gap – between how often things go wrong and how seriously organizations are taking agent identity – is the core operational risk.
Put plainly: the vendors that will help enterprises move agents from pilot to production are the ones gating execution, not just generation. The question for anyone deploying these systems is not whether the model is safe enough. It is whether the agent can only do what it is supposed to do – and whether you can see what it actually did.
