Where AI Security Stops and Agent Security Starts
Prompt injection, jailbreaking, and data leakage defined the first wave of AI security, and that work hasn't become obsolete. But an LLM gateway that sees a prompt and its completion has no visibility into the tool call, credential, or downstream steps that completion triggers. The same injection that produces a misleading chatbot response can, against an agent with tool access, exfiltrate data or trigger cascading system failures.
Not every agent risk is a manipulation story, either. Some of the most damaging incidents involve no injection and no attacker at all: an agent given a legitimate task improvises its way into unauthorized action while solving a problem no one anticipated. A security posture built only to catch manipulation misses this category entirely, because there's nothing to catch.
This Is Not a Vendor Distinction
OWASP's Top 10 for Agentic Applications exists alongside, not instead of, its LLM Top 10, with entries like Tool Misuse, Identity & Privilege Abuse, and Memory & Context Poisoning that have no expression at the model layer. MITRE ATLAS added agent-specific adversary techniques in its first 2026 update. NIST's Control Overlays project scopes agentic use cases separately from its generative AI assistant overlay.
AIUC-1, an AI agent certification standard with more than 100 Fortune 500 CISOs contributing, has published crosswalks to ISO 42001, NIST AI RMF, and the EU AI Act.
What Makes Agents Unique
An LLM alone is stateless, text in and text out. An agent acts with enterprise credentials across trust boundaries, invokes live APIs and databases, persists memory across sessions, and often operates with limited human review.
Risk shows up in three distinct forms that require different defenses: external (an adversary manipulates the agent), insider (someone hands the agent access it shouldn't have), and autonomous (the agent reasons its way into a bad action with no manipulation at all). Every deployed agent carries all three, whether an organization has named them or not.
Industry Momentum Demands Attention Now
Gartner projects 33% of enterprise software will include agentic AI by 2028, up from under 1% in 2024. The White House's 2026 National Cybersecurity Strategy is the first U.S. strategy to explicitly prioritize agentic AI security.
Vendors who actively co-author standards like OWASP Agentic AI and publish original agent-specific research, rather than just referencing them, deserve more weight in an evaluation.