Agentic AI Demands We Rearchitect Our Cybersecurity Infrastructure 

A few weeks ago in Bloomberg I argued that today’s cybersecurity infrastructure is not just vulnerable to AI, but architecturally incapable of securing agentic AI systems themselves, or defending IT infrastructure generally against adversarial AI. If you took that as a hint that something new was coming from Gradient in the AI space, you were right.

It’s been nearly a year since we’ve said much publicly. Here’s what we’ve been building, and why now.

Starting some time last year, we embarked on a Skunkworks style project to explore how Gradient’s core technology could be applied to secure agentic AI systems. Our initial motivation was simple: we already knew that conventional identity and authentication (IAM) systems were heavily strained, if not already broken, handling human users. Under the new demands of agentic AI, today’s IAM systems collapse entirely.

For the last eight years, Gradient has been building an attestation-driven, hardware-anchored identity framework — battle-tested in production for over two years securing human users, devices, and APIs. While we did not build Gradient’s platform with agentic AI in mind, as enterprises began deploying agents, it became clear that what we’d already built is precisely what securing agentic AI demands. Extended to support AI agents, the result is what we call a Trust Control Plane for Agentic AI.

This is Not Just a Cybersecurity Problem

Nearly two-thirds of enterprises now cite security and risk as the top barrier to fully scaling agentic AI.[1] What this means for your company: your ability to realize the benefits of AI, and ability to secure against the new challenges introduced by agentic AI, both demand a redesign of the security architecture itself.

[1] McKinsey & Company, “The State of AI trust in 2026: Shifting to the agentic era” (McKinsey Technology & AI / QuantumBlack, 2026); nearly two-thirds of respondents cite security and risk as the top barrier to fully scaling agentic AI.

Adversarial AI Fundamentally Shifts Risk Equation

We’ve seen a marked shift in perception of risk in the last few months. In April, Mythos demonstrated two novel capabilities that fundamentally shift the risk equation:

  • First, the ability of adversarial AI to discover and exploit previously unknown vulnerabilities, including composing complex multi-step attacks on a vastly compressed timeline.
  • Second, the newly demonstrated behavior of advanced AI to act beyond its intended scope – to “go rogue.” Primarily driven by the first of these, we’ve seen a sudden awareness by executives and company boards that the need for a solution to secure agentic AI is not just a matter of convenience (e.g., making it easier to deploy and govern agentic systems), but now represents existential risk.

While efforts like Project Glasswing that leverage advanced AI models to identify and mitigate vulnerabilities on a faster timescale are sensible, they are not enough. Using AI to counter AI is still a fundamentally asymmetric battle that favors the adversary, and amounts to an extension of the “Detection and Response” arms race that has been failing us for the last 15 years.

This asymmetry is not hypothetical. This week’s disclosure that Hugging Face was breached by an AI-driven adversary — even while running frontier models in a defensive role — is exactly the failure mode we mean: using AI to defend against AI is a race that structurally favors the attacker, and will continue to be exploited.

We’ve built the solution to enable secure agentic AI – and to protect against adversarial AI.

The starting point for the solution – whether considering human or AI adversary – is to prevent the attacker from being able to establish persistence in the first place. This is what Gradient’s user-facing authentication solution already does today. Now, we’re extending this capability to secure agentic AI systems themselves.

Next week, we’ll be sharing Gradient’s solution for agentic AI, a new category of tooling that we call a Trust Control Plane for agentic AI.

Gradient Trust Control Plane for Agentic AI realizes what NSA and Anthropic specify

Gradient’s view of what the core problems are, and capabilities a solution must have to secure agentic AI are no longer ours alone. This Spring, leaders in the cybersecurity and agentic AI space converged on the same view.

First, NSA and the rest of the Five Eyes released their “Careful Adoption of Agentic AI Services” brief specifying that each agent carry a verified, cryptographically anchored identity with short-lived credentials. Explicitly, NSA says to “require agents to perform cryptographic attestation where agents must prove that they are running expected and unmodified code,” and “continuously verify identity and authorization at runtime using a centralized policy decision point for each request.” To our knowledge, Gradient is the only platform that provides these capabilities today.

Shortly thereafter, Anthropic released their own “Zero Trust for AI Agents,” whitepaper describing their view of best practice security frameworks for deploying autonomous AI agents in the enterprise. Across all identity and privilege areas, Gradient realizes or exceeds the top “Advanced” tier of maturity.

Explicitly: Anthropic advises use of hardware-anchored agent identities, just-in-time privilege, and continuous validation at every access. Anthropic’s own assessment of the JIT control: “very powerful, and not easily implemented.” We’ve implemented both, and more.

Establishing Common Understanding of the Problem

Ahead of launch, we believe it’s critical to go beyond sound bites – AI leaders must have a common understanding of the core problems with securing agentic AI today. For too long, the cybersecurity sector has launched products marketing-first. The cracks are forming in this strategy, just as they are in the capabilities of the legacy tools being marketed.

Beginning in this post, I’ll outline (1) the core capabilities that a Trust Control Plane provides, and begin to sketch out the two top level categories of risk introduced by agentic AI.

In a follow-on post, I’ll expand on the risk aspect to give (2) a first principles view of the problems to overcome in securing agentic AI – and where current tools fail. And finally (3) from this objective foundation, my goal is to not just declare, but to convince you that Gradient’s Trust Control Plane is the solution.

Gradient Trust Control Plane for Agentic AI – Capabilities Overview

First, what is it? “Trust Control Plane” isn’t marketing spin. It’s a reflection of the fact that no current cybersecurity category (or group of categories) has the attributes needed to realize secure agentic AI. These core attributes are the ability to:

  1.  Orchestrate the complete AI agent lifecycle, from verified integrity at initial agent compilation, to provisioning of cryptographically bound, attested agent identity and capabilities (similar to permissions, but broader), to governance of agent behavior at every step, to end of life cleanup. This governance must also include the human owner dynamic. If a human owner provisions an agent with capabilities, that agent spawns sub-agents with those capabilities, and then the human owner is terminated – the agent and sub-agents must be terminated, too. And this carry-through of termination must be achievable on agentic timescales. Gradient aims to deliver this.
  2. Maintain provenance from human owner, to agent, to sub agent, to interactions with third party services. This and (#3) below together are required to meet liability requirements to be able to make use of agents in financial transactions, for example. Until your legal counsel is comfortable that your governance and controls ensure that an agent will perform exactly the actions that a human owner specifies, it can’t be used meaningfully for commerce. Gradient aims to deliver this.
  3. Cryptographically enforce ephemeral lifetime identity and capabilities that are verified at every step. Having an identity and properly scoped is meaningless if it isn’t unforgeable, universally enforced, and reflective of real-time permissions status. Today’s identity and authorization tooling operates on time scales orders of magnitude slower than the speed of agents. What this means is that agents remain valid for far longer than they need to be, with broader permissions than necessary. And this is the exploit surface that makes agents so problematic.

In short, we must ensure at every agent interaction that the agent is who it says it is, that it is unmodified from initial provisioning, and that the capabilities it asserts match what it was granted by its owner, or if those have changed, what real-time permissions status is. This enforcement must extend from internal tooling to interaction with third party services.

Upon launch, we will be selectively opening up access to the platform beyond the current cohort of first users – better described as development partners – with first priority given to organizations in critical infrastructure sectors like finance, healthcare, defense, and parts of the tech sector itself, where exploit of the vulnerabilities we’re addressing will be most catastrophic. If that’s you, we’d love to hear from you – send a note to secureai@gradient.tech to start the conversation.

Two Categories of Risk from Agentic AI

I’ll expand on this in the next post, but we see the new risks from agentic AI as two-fold:

  1. Adversarial AI Outpaces Current Cybersecurity Defenses on Initial Access

This category is what seems to be getting the most attention: the ability of advanced AI to exploit vulnerabilities to breach networks.

Update: Yesterday’s disclosure by Hugging Face is further proof that this concern is real and must be mitigated, expediently.

Following the release of Anthropic’s Mythos Red Team disclosure, for example, the focus of concern has been on Mythos’ ability to exploit previously undiscovered vulnerabilities, to chain together multi-step attacks, and to more efficiently leverage “N-Day” vulnerabilities – those that are disclosed but may not be fully patched in the wild yet.

While the actual classes of exploits aren’t new, what is novel here is that:

(a) Adversarial AI compresses the time to initial breach, doing so much faster than conventional Detection and Response (EDR, XDR) can match. As we’ve already said, applying AI to this arms race is not sufficient and we believe untenable, as it’s inherently asymmetric in favor of the attacker.

(b) Adversarial AI lowers the cost of a complete systematic exploration of a company’s vulnerabilities. Today, we often see that enterprises will accept majority, but not complete coverage of a deployment of phishing resistant authentication – say 70-90%. This might have provided an adequate threshold of risk mitigation in face of human attackers. With AI, this number must be 100%. What this means for companies: your user-facing authentication strategy must be able to get you to 100% coverage. Most solutions can’t. Gradient achieves this today. Our Trust Control Plane extends this coverage to agents, too.

  1. Agentic AI “Goes Rogue”

We aren’t suggesting you should be concerned about your agents achieving sentience and turning on us all, Terminator-style. (If you are, we can solve this, too.) By “going rogue” we mean an agent that acts beyond its prompted intent. This is arguably the most consequential risk category in terms of shifting your risk dynamic beyond acceptable limits, because the liability of your agents’ actions falls directly on you.

The example we hear the most about is from Anthropic’s own Mythos red team report disclosing an agent that, during internal testing, acted outside the scope of its instructions: it broke out of its test sandbox, obtained access to the public internet with privileges it hadn’t been granted, and published what it had done — unprompted, and without anyone asking it to do so.

This should be unsettling for a reason beyond “AI could attack us”: it means a model with comparable capability, running inside your own environment for entirely legitimate purposes, is capable of the same kind of un-scoped, self-directed action.

We do not think that the risk gets solved by making agents “better behaved” – that’s a model alignment question for the frontier model teams.

As we will describe in a subsequent post, Gradient’s solution is to cryptographically bind an agent’s capabilities (permissions) to the agent, and enforce these permissions at every interaction with ephemeral credentials.

As validation of this approach, we point to Anthropic’s “Zero Trust for AI Agents” that similarly highlights agents acting beyond their intended scope as a central risk to mitigate, and argues it must be contained by bounding authority — least agency, deny-by-default, blast-radius limits — rather than prevented.

More to follow soon – we’re thrilled to finally be able to share Gradient’s Trust Control Plane publicly – and we welcome critical feedback from the community. Our goal foremost it to deliver maximum positive impact to the world, by securing the world’s infrastructure against these new risks.