row zero

Zero trust expands as AI agents demand action-level security controls

At RSAC 2026, industry leaders converged on a critical issue: the need for enhanced security in AI agents.

4 min readVentureBeat
Zero trust expands as AI agents demand action-level security controls

The industry converged on a problem at RSAC this year, and then two vendors shipped answers that could not be more philosophically different. That divergence is the story worth paying attention to, because it frames the real decision security teams will make for the next decade. The consensus among the keynotes was correct: zero trust for AI agents is no longer theoretical. But consensus on the problem is where agreement ends. Anthropic and Nvidia have both shipped architectures that meaningfully reduce risk, and they reduce it in different ways with different costs. The gap between them is not a technical nuance. It is a governance choice, and most organizations are not equipped to make it yet.

The monolithic agent is the default, and it is a liability. When a model reasons, calls tools, and executes code inside one process with credentials sitting in the same environment, you have built a single point of failure that is trivially exploitable. The data from the CSA and Aembit survey is damning: 43 percent use shared service accounts, 52 percent rely on workload identities, and 68 percent cannot distinguish agent activity from human activity. No one owns the access. That is not a security problem waiting to happen. It is a breach already in progress for most enterprises, and they just have not noticed because the logs cannot tell them. The fact that average breakout time has dropped to 29 minutes, with the fastest observed at 27 seconds, should end any debate about whether this matters. It does.

Anthropic's approach is the stronger architectural answer because it removes credentials from the blast radius entirely. Splitting the brain from the hands, with a session log outside both, is not just clever design. It structurally eliminates single-hop exfiltration. A compromised sandbox yields nothing an attacker can reuse. That is the bar every security team should hold vendors to. Nvidia's NemoClaw takes a different route, constraining the blast radius and monitoring everything inside it. That is better than the monolithic default, and the intent verification layer is a serious step forward. But the credential proximity gap is real. When messaging tokens are injected as environment variables into the same sandbox where generated code runs, indirect prompt injection sits next to execution with nothing structural between them. Anthropic's design does not fully solve indirect injection either, but it limits the damage to influencing reasoning. Nvidia's design allows injected context to sit beside both reasoning and execution. That is the widest gap between the two, and it is the one that should shape procurement decisions.

The practical takeaway for security leaders is not to wait for a perfect architecture, because one does not exist. It is to audit every deployed agent for the monolithic pattern and flag any agent holding credentials in its execution environment. Require credential isolation in RFPs, and ask vendors to specify whether that isolation is structural or policy-gated. Test session recovery before production, because a sandbox that dies mid-task without a durable session log is a data-loss risk that compounds with task duration. Staff for the observability model you choose, because Anthropic's console tracing and Nvidia's operator-in-the-loop TUI have very different staffing math. And track indirect prompt injection roadmaps, because neither architecture fully resolves that vector. The 65-point gap between deployment velocity and security approval is where the next class of breaches will start. The vendors have shown the direction. The question is whether your organization is ready to choose one and commit to the trade-offs, because the monolithic default is no longer a defensible option.

From VentureBeat

Four separate RSAC 2026 keynotes arrived at the same conclusion without coordinating. Microsoft's Vasu Jakkal told attendees that zero trust must extend to AI. Cisco's Jeetu Patel called for a shift from access control to action control, saying in an exclusive interview with VentureBeat that agents behave "more like teenagers, supremely intelligent, but with no fear of consequence." CrowdStrike's George Kurtz identified AI governance as the biggest gap in enterprise technology. Splunk's John Morgan called for an agentic trust and governance model. Four companies. Four stages. One problem.

Read the original at VentureBeat