
Securing AI Agents: Governance and Infrastructure

The report argues that AI agents have shifted the enterprise security model because they are not passive information retrievers: they are granted the ability to read email, query databases, and trigger API calls, which means they can act on the world. That capability creates new attack surfaces and makes traditional security tools insufficient on their own. According to the State of AI infrastructure report, 79% of tech leaders cite security, governance, or operations as their most significant challenge when scaling inference. The threat surface expands beyond ordinary data access to include tool poisoning and indirect prompt injection, where an attacker hijacks an agent’s logic through the data it processes. Legacy security was not built for these automated threats, and managing dynamic agent permissions becomes a major operational problem.
The article positions governance as a driver of innovation rather than a blocker. Agents need both access and guardrails, but 35% of senior IT decision makers say insufficient security for multi-system access is a primary issue preventing agentic deployment. The traditional goal of preventing breaches is also no longer enough; security leaders are shifting their focus to verifying provenance in order to guard against misuse, including indirect prompt injection. At the same time, defenders must protect the network layer and the model itself, not just manage identity and access.
To address these problems, the source advocates moving from a pure blocking mindset to managing risk on integrated, full-stack cloud platforms. 69% of surveyed executives rate a full-stack platform as a critical requirement, and 80% say data compliance is the primary factor behind that choice. The article names the Secure AI Framework and the Gemini Enterprise Agent Platform as examples of the direction, and it outlines three areas of risk management: secure-by-default design, where security is embedded into AI development processes to proactively guard against threats such as prompt injection; agent governance and oversight, using purpose-built permission and identity management to control agent interactions and expose blind spots; and human-in-the-loop controls, which enforce rules that flag when an agent requires human approval before proceeding with a critical action.
A modern governance foundation, the report asserts, allows organizations to deploy agents confidently on sensitive business workloads without having to lock down the system in a way that defeats autonomous agents. The closing point is that agentic-era leaders are architected to use security as a launchpad, enabling secure innovation and faster scaling.


