Zenity Blog
Coalition Chaos


Coalition Chaos
I've tracked eighteen initiatives across a dozen countries, five months, and several issues being worked seven...

A Safer Future with Agents
We built agents to act on their own. We're somehow surprised when they do. Two weeks ago, OpenAI ran a cyber eval...

Seeing Thousands of Real Incidents Means I Have No Choice But to Share What I Know
The Sentence I Cannot Stop Thinking About A few years ago, I was sitting across from a security leader at a large...

What Auditors and Regulators Are Starting to Ask About AI Agents
The regulatory landscape for agentic AI is moving faster than most compliance programs are tracking. CISOs who...

Governance and Security Are Different Problems: Agentic AI Is Exposing the Gap Between Them
Many organizations still use the terms AI governance and AI security interchangeably. While they are closely related,...

Beyond Authorization: Why Intent-Aware Detection Is the New Control Plane for Agentic AI
Identity tells us an agent is allowed to act, intent tells us why it is acting. In an agentic world, only one of...

Least Privilege Isn't Enough for AI Agents. You Need Least Agency.
Least privilege is foundational. It's been a core security principle for decades, and it's no less relevant in...

Risk Discussed, Security Defined: AI Agent Security Summit On-Demand
Almost two weeks have passed since the 2026 AI Agent Security Summit wrapped at the Commonwealth Club in San Francisco,...

Automation, Intent, and Ownership: What to Learn from the AI Agent Security Summit
When the AI Agent Security Summit launched in San Francisco last October, agent-based threats had already escalated...

Five Signals, One Answer: Why Single-Signal AI Security Always Fails
The security industry hasn’t been wrong about agentic AI risk. It’s been incomplete. There’s no shortage of single-signal...

Allowed Is Not Aligned: Why Retrofitted Tools Can’t Secure AI Agents
Gartner® named Zenity the Company to Beat in AI Agent Governance on April 17, 2026. That recognition, grounded...

AI Risk Is Not Uniform: The Case for Archetype-Aware Enterprise Security
Every conversation I have with security leaders about enterprise AI security eventually arrives at the same place:...

Your AI Agent Inventory Is Incomplete. Here's What That Means for Risk.
Some organizations still treat agentic AI as a future problem. Something to plan for. Something on the horizon....

Here's what's waiting for you in San Francisco at The AI Agent Security Summit
May 27, 2026. Commonwealth Club. It’s going to be epic. Last October was our biggest summit yet. But this one...

The Authorization Trap: Why Your IAM Controls Don't Cover AI Agent Risk
If there's one idea that shaped RSA 2026, it was identity. Vendor booths, keynotes, conversations. All roads led...

What 500+ Industry Experts Told Us About Securing Autonomous AI: A Policy Roadmap
When the US Center for AI Standards and Innovation (CAISI) asked for public input on securing agentic AI systems,...

The AI Agent Security Summit Returns to San Francisco: Meet the First Speakers
Since our last AI Agent Security Summit in 2025, the conversation around agentic AI security has shifted considerably,...

Agents Need Boundaries. The Market Is Starting to Agree.
Gartner published the inaugural Hype Cycle for Agentic AI last week (and yes, we’re included in two subcategories...

After RSA, Here Is What Comprehensive Agentic AI Security Actually Looks Like
The hype is deafening, the booths were packed, but most of what the industry is calling "agentic AI security" is...

Identity Isn’t Enough: Why AI Agent Security Requires Runtime Context
Conversations at RSA 2026 circled back to the same topic: identity is the foundation of AI agent security. While...

The Floor Was Selling AI. The Hallways Were Asking for Help.
One man’s perspective on RSA 2026 and what the AI agent security market actually looks like up close. Every year...

Build for Tomorrow, Today: Deploying Agentic AI Under EU and UK Regulations
Organisations deploying agents face a challenge: the predominant AI frameworks most organisations rely on do not...

Context Engineering Is Security Engineering. RSA 2026 Made the Case.
The Model Isn't the Problem Anymore Cisco polled its major enterprise customers before RSA 2026 and found something...

RSA and DC Dispatches: Agentic AI Security Is the Story, Government Policy Needs to Catch Up
Fresh off two weeks of back-to-back meetings in Washington, DC, and on the floor/in the wings of the RSA Conference,...
Secure Your Agents
We’d love to chat with you about how your team can secure and govern AI Agents everywhere.
Get a Demo