What the agent security market watches, and what it still can't see
Each agent security category extends the layer it was already built to watch. A side-by-side look at what each one sees, and where agent risk actually builds up.
At RSA Conference 2026, most of the agent security launches were about identity: proving who an agent is, where it came from, and which credentials it carries. Gateway vendors, meanwhile, inspect the traffic an agent sends across the network boundary, and model platforms govern the tools and connectors it has been configured to reach. Each group has extended the layer its platform already watched. That’s a sensible way for a market to form, and it says nothing bad about anyone’s engineering.
Agent risk builds up somewhere else, though. It lives in the order of what an agent does once it’s running: the tool it calls, the file it opens next, the request it sends after that. A credential check happens once, at the door, and a gateway sees one request at a time. Neither was built to notice a run of ordinary-looking actions that add up to something nobody signed off on.
Most organizations are already running into this. A Cloud Security Alliance and Aembit survey found that 68% of organizations can’t tell human activity from agent activity in their own logs, and Gravitee’s 2026 State of AI Agent Security report found that only 47.1% of deployed agents are actively monitored or secured at all.
This market assessment puts the approaches side by side, from identity-first access management and perimeter inspection to threat-modeling frameworks like CSA MAESTRO and the spreadsheet inventory most teams begin with, and is specific about where each one stops. It treats the controls you already run as necessary and incomplete, and gives you a way to see which layers of your agent estate they cover.
What you will take away
- A map of how the agent security market has organized itself, with each approach placed by what it treats as the thing to control and what it actually records
- A side-by-side table of what each category sees and what it misses
- Why tools, prompts and permissions that change in production undo a review done at design time
- The architectural difference between enforcing at an external boundary and enforcing inside the agent’s own execution
- Five questions to put to any vendor that says it reports on agent behavior