Guide · Checked against vendor sites, September 2026
What is AI agent security?
The verdict
AI agent security is the set of controls that let an organization see which AI agents are running, decide what each one may do, stop actions that break policy, and keep a record of who did what. It matters because agents act with a person's access: they run commands, read files, call APIs and use credentials.
Part of the University: Basics track
Why is AI agent security different from securing a chatbot?
A chatbot answers. An agent acts. Coding agents such as Claude Code, Codex and Cursor can run shell commands, install packages, edit files and call cloud CLIs. Through MCP servers they reach calendars, databases, ticketing systems and internal APIs. Every one of those actions runs with the permissions of the person who started the agent, often on their own laptop. The risk moves from what the model says to what the agent does.
What should an AI agent security program cover?
See
Discover the agent, its MCP servers, tools and credentials
Decide
Evaluate the action before it runs, with context
Allow or block
Allow, ask the user, or deny
- See. An inventory of agents, coding assistants, MCP servers, extensions and the credentials they can reach, on every device.
- Decide. An evaluation of each action before it runs, using context: who started the agent, what it did earlier in the session, what data it touched.
- Allow or block. A response that fits the risk: allow, ask the user, warn, mask data, or deny.
- Log. A record that separates what a person did from what an agent did on their behalf, from prompt to system action.
Where do agents run, and where should controls sit?
Agents run in three places: on employee devices (coding agents, desktop assistants, browser AI), inside SaaS platforms (Microsoft 365 Copilot, Salesforce Agentforce, ServiceNow) and in applications a company builds. Endpoint tools such as Bay, Koi and Bloom Security focus on the first. Platforms such as Noma Security, Zenity and Onyx Security cover all three to different depths. Data-first tools such as Harmonic Security and Prompt Security start from employee AI use and extend to agents.
Is AI agent security only a security purchase?
Increasingly not. The same controls decide how fast a company can say yes to AI tools. A CIO who can see every agent and set per-action rules can approve coding agents for a whole engineering team instead of a pilot group. That is why several vendors in this guide sell to both security leaders and IT leaders.
What are the related terms?
- MCP security: controls on the servers that connect agents to tools and data (MCP security).
- Shadow AI: AI tools in use without approval (Shadow AI).
- AI-SPM: AI security posture management, finding misconfigurations and excessive permissions.
- AIDR: AI detection and response at runtime.
Frequently asked questions
What is the difference between AI security and AI agent security?
AI security covers models, data and AI applications broadly. AI agent security focuses on agents that take actions, and on controlling those actions.
Does EDR cover AI agents?
EDR watches processes and files. It sees a trusted application running, not whether a specific agent tool call should be allowed. See AI agent security and EDR (/guide/ai-agent-security-and-edr).