NOTE · 17 SEPTEMBER 2026
Seven myths about AI agent security, and what the facts say
The verdict
The most common mistakes are assuming EDR already covers agents, that a network gateway sees every MCP call, and that blocking AI tools removes the risk. Public sources say otherwise: EDR sees a trusted process, local MCP servers talk to agents on the same machine, and blocked tools tend to move to personal devices. Each myth below links to a page with the detail.
Common assumptions about AI agents on employee devices, each checked against a public source.
By Best AI Security editors · 17 September 2026 · 4 min read
- Basics
Myth: EDR already covers AI agents
EDR watches processes, files and network connections for malware and intrusion. When a coding agent runs a shell command, EDR sees a trusted, signed application doing something ordinary. The question an agent control answers is different: should this agent, started by this person, in this session, run this command? That is why the tools on this site work alongside EDR, and why several, including Bay and Noma Security, say they deploy through it. See AI agent security and EDR.
Myth: an MCP gateway sees every tool call
A gateway sees traffic routed through it. A local MCP server launched by the agent on the same laptop talks to it over stdio, which never crosses the network. The MCP security best practices page says servers meant to run locally should use stdio or restrict HTTP access. Gateways suit remote servers; local servers need control on the device or inside the agent. See where AI agent controls sit.
Myth: blocking AI tools removes the risk
Blanket blocking tends to push use onto personal devices and out of view. Many AI tools run locally or talk to their providers over ordinary HTTPS, so network blocks miss them. The approach most tools on this site support is discovery first, then approve, approve with conditions, or block. See what is shadow AI.
Myth: prompt injection is a model problem that better models will fix
The damage comes from what an agent can do once it follows injected text. The OWASP GenAI Security Project's 2026 Top 10 for LLM Applications ranks Excessive Agency third, and Bay's research calls indirect prompt injection against trusted agents "an authorization problem disguised as a prompt problem." Limiting and checking actions still works when the model has been fooled. See indirect prompt injection and the action layer.
Myth: an acquired product only works inside its new owner's platform
It depends on the product. Palo Alto Networks says Koi remains available as a standalone offering as well as a Cortex XDR module. SentinelOne describes Prompt Security as built into the Singularity Platform. Ask each vendor directly what you can buy on its own. For buyers on other EDR platforms, that answer decides whether the product is an option at all.
Myth: "Not published" means the feature is missing
On this site it means the vendor's public pages did not describe the feature when we checked in September 2026. Several vendors publish little, including Bay and Bloom Security, and they score lower on some rows for that reason. Treat each gap as a question for a demo. See how to read vendor claims.
Myth: the MCP specification leaves security entirely to vendors
The specification sets several rules itself. MCP servers must only accept tokens issued for them and must not pass tokens through to upstream APIs. The tools page says there should always be a human in the loop with the ability to deny tool invocations, and asks clients to confirm sensitive operations, show tool inputs, validate results and log tool usage. The 2026-07-28 revision added stricter authorization checks. Vendors build on these rules; they do not replace them. See MCP security.
What should you take from this?
Related
Sources
- MCP Security Best Practices · Reviewed Sep 2026
- MCP tools specification · Reviewed Sep 2026
- OWASP GenAI Security Project, 1 Sep 2026 · Reviewed Sep 2026
- Bay, Ghostjacking · Reviewed Sep 2026
- Palo Alto Networks press, 14 Apr 2026 · Reviewed Sep 2026
- SentinelOne, Prompt Security · Reviewed Sep 2026