Within a matter of days we’ve seen OpenAI confirm that one of its evaluation models escaped its testing environment and compromised Hugging Face’s infrastructure, prompting Microsoft’s Mustafa Suleyman to describe the incident as a “warning shot” for cybersecurity. At almost the same time, Microsoft unveiled Project Perception and its new cyber-specific AI models, while NVIDIA, Microsoft, IBM, CrowdStrike and more than 30 other organisations announced the Open Secure AI Alliance to accelerate open AI security tooling.
Salt Security has been arguing for some time that organisations need to distinguish between AI security and agentic security because every autonomous action an AI agent performs is ultimately executed through APIs. As enterprises deploy more AI agents, protecting the model itself is only one part of the challenge. Understanding what those agents are authorised to do, which systems they can access, and whether those actions remain within policy is becoming equally important.
CEO and Co-Founder of Salt Security, Roey Eliyahu, offers some commentary on this below that might be useful:
This week feels like the point where the industry acknowledged that agentic security deserves to be treated as its own discipline. We have seen an AI model escape a controlled evaluation environment and interact with external infrastructure. We have seen one of the world’s largest technology companies describe that incident as a warning shot. We have also seen competitors and partners come together to launch dedicated initiatives focused specifically on securing AI systems.
These are huge steps in the evolution of agentic security. For the last few years, most organisations have approached AI security through the lens of protecting the model. That remains important, but autonomous agents introduce a completely different challenge. An AI agent is making decisions, invoking APIs, authenticating to business systems, accessing sensitive data and taking actions on behalf of users. Every one of those actions has security implications that extend far beyond the model itself.
The key to agentic security therefore becomes what happens after the model decides to act? Which APIs can it call? Which identities is it using? Which systems can it modify? Can those actions be monitored, governed and stopped if something unexpected happens? Those are the questions that define agentic security.
The announcements we’ve seen this week demonstrate that the industry is beginning to recognise this distinction. Better models, safer training techniques and open collaboration are all valuable developments, but they do not provide runtime governance. Organisations still need visibility into the action layer where AI agents interact with enterprise infrastructure. That is where business risk exists, because that is where autonomous decisions become real-world actions.
Every major enterprise AI deployment is built on APIs. They are the execution layer for agentic AI. If organisations cannot see and control how agents use those APIs, they are effectively handing autonomous software the keys to critical business systems without knowing what it is capable of doing. The future of cybersecurity will be determined as much by governing those actions as by securing the models that generate them.






