Enterprise AI is moving from systems that produce answers to systems that carry out work. Agents retrieve information, interact with applications, and complete multi-step tasks with limited supervision. For many organizations, this is the point at which AI stops being a productivity tool and starts becoming part of the operating environment.

Frost & Sullivan has examined this shift from several angles, including how autonomy alters the enterprise risk profile and how identity is becoming the control plane for non-human actors. This article addresses a different and less examined question. Once an agent has been authorized, where does it actually operate, and is that environment secured?

To explore this, Frost & Sullivan spoke with Aayush Agarwal, Director of Product Management at Menlo Security. The analysis presented here is Frost & Sullivan’s own, but the discussion offered a valuable practitioner view from an organization working directly with enterprises on this problem. One observation framed the entire conversation: many organizations are concentrating on securing the model, while exposure is emerging in the workspace where agents do their work.

Three priorities follow from that shift.

  1. The Security Question Changes After Authorization

Identity governance for agents is now reasonably well understood. Agents authenticate, hold permissions, and can inherit, share, and delegate identities, which makes lifecycle control and accountability essential. Focusing on identity is not misplaced.

What receives less attention is what happens next.

As described during the discussion, identity is the front door, and agents are already living inside the building. Authorization establishes that an agent may act. It says very little about whether a specific action, taken in a specific context, is appropriate.

That gap matters because an agent can be fully authorized and still be steered somewhere unintended, either by manipulated input or by a task handed between agents. Agents can also work across one another and operate at machine speed, which compresses the window in which a human might notice that something has gone wrong.

The practical requirement is behavioral visibility during execution, rather than a permissions record captured at onboarding. For security leaders, the governing question moves from “is this agent authorized?” to “is this action consistent with what the business intended?”

  1. The Workspace Is Where Exposure Accumulates

Most AI security investment today targets the model layer, covering alignment, governance, and the safeguards applied to inputs and outputs. These remain necessary. They are not sufficient.

Agents do not operate inside the model. They operate through browsers, SaaS platforms, cloud services, and internal applications, which is where enterprise data actually sits and where business workflows are executed. The browser in particular has become a central point of enterprise activity, spanning SaaS and cloud applications, collaboration suites, AI tools, and access by contractors, vendors, and third parties.

Prompt injection makes the exposure concrete. The discussion characterized it as the control layer the AI era still lacks, comparable to what web application firewalls became for web traffic, and noted that agents are broadly susceptible because instructions can arrive disguised as ordinary content.

This also reframes the sanctioned versus shadow AI debate.

Unsanctioned tools remain a legitimate governance concern. However, approved agents hold genuine access to real data, carry real authority to act, and execute at machine speed. Manipulating a trusted agent may therefore carry greater consequence than an employee using an unapproved tool.

The conclusion for security architects is straightforward. The security boundary now extends to every surface through which an agent reads, retrieves, or acts. The workspace is no longer adjacent to AI security. It is part of it.

  1. Assurance Testing Does Not Cover Production Behavior

Pre-deployment testing establishes how an agent behaves under known conditions. It cannot enumerate the instructions, content, and edge cases that a live environment will present once agents interact with real users, applications, and data.

The point raised in the discussion was direct: red teaming captures the lab, while breaches happen in production. Everything of consequence happens at runtime, which means controls must operate where the work happens and must extend beyond identity to the applications themselves.

The second half of that argument is equally important. Detection and response alone are a poor fit for actors that can complete a sequence of actions in seconds. Preventive capability, applied at the point where an agent acts, becomes the difference between an incident avoided and an incident investigated.

For security leaders, this is an architectural decision rather than a tooling preference. Where an agent can act on real data at speed, the opportunity to intervene after the fact may simply not exist.

Key Actions for Technology and Security Leaders

Agentic AI adoption is still maturing, which makes this the right moment to establish the foundations.

  • Inventory the action surface, not just the access list. Record what each agent can create, modify, send, approve, or execute, rather than documenting data access alone.
  • Treat the workspace as in scope. Assess the browsers, applications, and data paths agents use, alongside model-layer and identity controls.
  • Add controls that operate during execution. Pair assurance testing and red teaming with preventive enforcement in production environments.
  • Bound the first deployments. Begin where intended outcomes and permitted actions can be defined precisely, then widen scope as governance matures.

Agents earn their value by acting. That is the source of the opportunity, and it is also the source of the risk.

Organizations will continue to secure models and govern identities, and both remain necessary. However, the decisive control point is shifting to where decisions become actions. Security must follow agents to that point, which is the workspace rather than the model.

About Kenny Yeo

Kenny Yeo currently leads Frost & Sullivan’s ICT practice across Asia Pacific. A current topic of interest is analysing AI transformation and its value impact on organizations. With more than 20 years of research, consulting, advisory, team management and business development experience, Kenny has expertise spanning AI, cyber security, IoT, smart retail, industrial and e-government.

Kenny Yeo

Kenny Yeo currently leads Frost & Sullivan’s ICT practice across Asia Pacific. A current topic of interest is analysing AI transformation and its value impact on organizations. With more than 20 years of research, consulting, advisory, team management and business development experience, Kenny has expertise spanning AI, cyber security, IoT, smart retail, industrial and e-government.

Your Transformational Growth Journey Starts Here

Share This