Treatmybrand


a Kainjoo SA Venture
Ch. du Vernay 14a
1196 Gland
+41.21.561.34.96
[email protected]

Support


Monday to Friday
8AM to 8PM
[email protected]
Back

New AI Agent Architectures Define Boundaries of Security Risks in Mixed Environments

As organizations rapidly adopt AI agents, security gaps are emerging—particularly where agent credentials and untrusted code coexist. Industry leaders at RSAC 2026 highlighted the urgent need to extend zero trust principles to AI systems. The common enterprise pattern bundles AI reasoning, execution, and credential storage in one container, which amplifies risk if compromised. CrowdStrike, Cisco, Microsoft, and Splunk executives all emphasized governance and continuous action verification rather than one-time authentication.

Two pioneering architectures show contrasting approaches: Anthropic’s Managed Agents separate reasoning (the brain) from execution (the hands) and isolate credentials externally, effectively shrinking the attack surface and improving performance. Nvidia’s NemoClaw keeps the agent monolithic but enforces strong layered isolation, intent verification, and real-time monitoring to limit damage and detect misuse quickly. Each design reflects trade-offs between security, complexity, and operational costs.

The key differentiator is credential proximity. Anthropic’s approach structurally removes credentials from risky environments, while Nvidia controls access through enforced policies inside the sandbox. Both address indirect prompt injection—the risk that malicious inputs manipulate agent behavior—only partially, indicating a critical area for future improvement. Comprehensive governance, credential isolation, session durability, observability, and roadmap tracking for injection attacks are emerging as the essential priorities for securing AI agents in enterprise environments.

Venturebeat
Venturebeat