The three layers of agentic AI security: A defense-in-depth architecture for autonomous agents

Presented by Nutanix


Are you ready to dive into the world of autonomous systems that can reason, make decisions, and take actions on their own? Oscar Wahlberg, senior director of product management at Nutanix, highlights the complexities and risks associated with this cutting-edge technology.

As enterprises transition from experimenting with autonomous agents to integrating them into their production environments, a new set of challenges arises. Traditional application-level controls are not sufficient to contain the risks posed by autonomous systems. Wahlberg emphasizes the importance of building a comprehensive defense-in-depth architecture that spans across infrastructure, storage, compute, networking, and a governing control plane.

Dividing responsibilities across different layers and implementing zero trust segmentation can significantly enhance the security posture of organizations. Wahlberg outlines three key layers in this security framework: infrastructure layer, network layer, and control plane layer.

Infrastructure layer: Establishing trust where AI agents run

The infrastructure layer focuses on establishing a root of trust to verify the legitimacy of agents operating in the environment. Technologies such as platform attestation, confidential computing, and secure boot play a crucial role in ensuring the integrity of the environment where agents run. This layer is essential for preventing unauthorized access, isolating AI workloads, and mitigating risks such as model tampering and supply chain compromise.

Network layer: Governing how AI agents communicate

The network layer is responsible for governing the communication between AI agents, APIs, applications, and enterprise systems. Dynamic policy enforcement and zero trust segmentation are key components of this layer to manage the complex interactions and prevent data exfiltration or lateral movement. Nutanix’s Agent Gateway provides a unified, governed layer to control interactions across agents, models, and data sources.

Control plane layer: Governing what AI agents are permitted to do

The control plane serves as the central point for managing agent permissions, tool access, resource consumption, and runtime visibility. It ensures consistent enforcement of policies and helps mitigate risks such as privilege misuse, unauthorized tool usage, and excessive model consumption. By treating governance as a runtime control system, organizations can enhance the security and efficiency of their autonomous agents.

Wahlberg warns against adopting a one-size-fits-all security approach for agentic AI environments. Enterprises must tailor security measures to each layer of the AI stack to avoid blind spots and performance penalties. A collaborative effort between Intel, Cisco, and Nutanix demonstrates how a layered architecture can create a well-governed AI Cloud solution that scales securely.

For organizations venturing into the realm of AI, building a centralized governance layer is crucial for managing agent identities, tool permissions, and token budgets effectively. This control point acts as the backbone for scaling AI projects safely and efficiently in the long run.

Explore the Nutanix Agentic AI solution here.


Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact sales@venturebeat.com.

Leave a Reply

Your email address will not be published. Required fields are marked *