Skip to content
Blue-toned overhead view of a busy table with multiple laptops, hands typing, and various tech devices.

Your AI Security Vendor Cannot Answer These Questions - And That Is the Problem

aizome5 min read

Something is shifting in how enterprises evaluate AI agent security vendors.

Twelve months ago, the conversations were broad. What do you cover? What does the dashboard look like? Can you show me a demo?

Now the questions are specific. And the vendors that cannot answer them are getting cut from the shortlist faster than anyone expected.

Here is what those conversations actually sound like - and what the questions reveal about where the real gaps are.

“Show me every co-working agent in our environment. Not the ones IT approved. All of them.”

This is where most evaluations end before they begin.

Co-working agents - the agents your workforce builds and runs alongside their daily work, connected to Salesforce, SAP, Workday, and every other system employees touch - are invisible to platforms built for cloud infrastructure or managed endpoints. Discovery tools that scan your cloud environment find the agents your engineering team deployed. They won’t find the agent your procurement manager built six months ago, connected to your ERP through an MCP server running on her laptop, still running under her credentials after she moved to a different role.

The CIO who asks this question already knows the answer is going to be uncomfortable. They are not asking to be surprised. They are asking because they need to know whether the vendor in front of them can actually see the problem they are trying to solve - or only the version of it that is easy to demo.

“What is the difference between what our agents are permitted to do and what they are actually doing right now?”

This is the intent question. And most vendors do not have a clean answer.

Access governance tells you what an agent is permitted to do. Intent-based access control tells you what it is doing right now - and whether that matches the purpose it was built for. The gap between those two things is where operational risk accumulates quietly, without triggering a single alert.

An agent built to summarize support tickets starts accessing customer records outside its scope. An agent built to process invoices starts reaching into financial systems it was never meant to touch. Each step is technically within permitted access. The cumulative effect is an agent operating well outside its mandate.

The CISO asking this question has usually already seen something like this happen. They are not evaluating a feature. They are evaluating whether the vendor understands the failure mode - and whether their platform catches it before the damage is visible, not after.

“Is your detection built for how agents actually behave - or did you adapt it from something else?”

Endpoint detection looks for known attack patterns and behavioral anomalies relative to human baselines. Network detection looks at traffic. Neither was designed for the way agents actually fail.

Agent-native threat detection centers on the agent as the unit of analysis. It measures how an agent chains tool calls, how its resource consumption shifts, how its instruction patterns evolve over time, how its data access expands beyond its original scope. It detects drift from the agent’s own behavioral baseline - not from a generalized model of what normal looks like across your environment.

The vendor that adapted their existing detection engine to cover agents will tell you it works. The question is: what does your detection miss when an agent gradually expands its behavior across six dimensions at once, and no single action crosses a threshold? That is the scenario that catches enterprises off guard. That is what agent-native detection was built for.

“If our CFO asks next quarter what we spent on AI agents and who authorized each one - how fast can you produce that answer?”

This is not a security question. It is an AI governance question. And it belongs in the CIO conversation, not just the CISO conversation.

AI governance is the accountability layer that sits above security controls - the infrastructure that makes AI agent deployment explainable to the board, defensible to regulators, and attributable when something goes wrong. Token consumption attributed to specific agents and owners. Cost breakdowns by department, by use case, by individual agent. An audit trail that answers the board’s questions in minutes, not after a three-month reconstruction exercise.

The vendors who treat this as a reporting feature are missing the point. AI governance is the reason the program exists at all. The CIO who cannot answer the CFO’s question about AI spend is the CIO who loses the ability to expand the program. Governance is what keeps the budget open.

“Was this platform built for AI agents from the start - or did you extend something that already existed?”

Architectural starting point matters more than most enterprises realize until they are in production at scale.

An AI-native platform starts with the agent as the unit of governance - assigns identity at the agent level, measures intent at the agent level, detects deviation at the agent level. A platform retrofitted from legacy identity or NHI frameworks starts with a model built for a different class of actor and tries to extend it to cover agents.

The gap appears when co-working agents don’t behave like the actors the platform was designed for. When the identity model doesn’t account for agents operating under human-proximate permissions. When the detection model does not catch the failure patterns specific to how agents drift. When the governance layer cannot attribute cost and accountability the way a board question actually requires.

The honest version of this question is: where does your model break down? Every platform has an edge. AI-native platforms have different edges than those adapted from somewhere else. Knowing which one you are buying matters.

The questions are the shortlist

The enterprises getting this right are not waiting for a framework to tell them what to ask. They are walking into evaluations with specific, operational questions, and cutting vendors who cannot answer them cleanly.

The vocabulary Gartner is using to classify this space reflects where the market has actually arrived: co-working agents as the highest-risk actor class, intent-based access control as the standard of coverage, agent-native detection as the architectural bar, AI governance as the business accountability layer, and AI-native as the signal that a platform was built for this problem from the start.

Those are not marketing terms. They are the questions your next evaluation should be built around.

See how aizome answers all five. aizome.ai

aizome

Related content

The latest news, technologies, and resources from our team.

  • Five Questions Every CIO Should Be Able to Answer About Their AI Agents

    Your Finance team built an AI agent last Tuesday. It is connected to SAP. HR has one connected to Workday. Sales built three connected to Salesforce. None of them went through IT. None of them have a governed identity. And nobody is watching what they are actually doing. This is a CIO problem. Because when the board asks - which AI agents are connected to our critical systems, what are they costing us, and who is accountable - the answer has to come from you. Most CIOs cannot answer those questions today. Not because they are not paying attention. Because the infrastructure to answer them does not exist in their current stack.

    aizome

  • The Enterprise AI Agent Revolution Is Here - My CYBER.SEC.CON Reflection

    Someone walked up to our booth and asked: “So what do you do - is this like a guardrails thing?” It is a reasonable question. Most of what people have heard about AI security has been about guardrails - content filters, output moderation, prompt sanitization. The assumption baked into that question is that the risk lives at the language layer. That assumption is no longer the right one. And the gap between where most people think the risk is and where it actually is - that is where the incidents are happening.

    Amir Ofek

    Amir Ofek

  • The Problem Has Moved From Prompt Hygiene to Access Architecture

    The conversation about AI agent security has been dominated by the wrong question. For the last two years, most of the energy in this space has gone into making AI agents say the right things. Guardrails. Output filters. Prompt sanitization. The implicit assumption is that the risk lives at the language layer. That assumption is now definitively wrong. The problem has moved from prompt hygiene to access architecture. The risk is not what agents say. It is what they do - with authorized access, through legitimate tool calls, in ways that no output filter was designed to evaluate.

    Chen Pipek, CPO & Co-founder aizome

    Chen Pipek

  • When a Support Ticket Emails Your Customer Database

    Support teams do something no other department does on purpose. They let strangers write directly into their systems. Customers paste logs, forward email threads, attach files, and describe problems in whatever words they have. An AI agent can turn that pile into a clean morning queue summary. It can also read it as instructions. We built a complete indirect prompt-injection chain using Salesforce and Claude Desktop. An outsider filed a plausible billing ticket through a public support form. Later, an employee asked Claude to summarize the day’s queue. Claude read the ticket, followed a short routing block buried inside it, exported 25 Accounts, 25 Contacts, and 25 Cases, and mailed the package to an external address.

    aizome Research Labs

  • AI Agent Security Isn’t Too Complex to Start. You’re Just Missing the Map.

    AI agent security doesn’t have to be overwhelming. Instead of chasing every new acronym or vendor category, start with three simple questions that cut through the noise. This practical framework helps CISOs prioritize discovery, identity, and runtime governance in the right order, so you can build an AI agent security strategy that actually works.

    Chen Pipek, CPO & Co-founder aizome

    Chen Pipek

Subscribe to the Aizome newsletter

Occasional, substance-first notes on making enterprise AI agents accountable. No spam; unsubscribe anytime.

We use your email only to send you our newsletter. See our privacy policy for how we handle your data. You can unsubscribe at any time.