Inside the AI Agent Security Stack: What Founders Are Actually Building
Every vendor at RSA this year claimed to secure AI agents. Few meant the same thing by it. Talk to the founders actually building in this space and a clearer picture emerges: AI agent security isn't one category, it's a stack. Five layers, five different theories of the problem.
Identity: Treat the Agent as a New Kind of Identity
Most founders start here: an AI agent is a new identity type, not a service account with a new label. Itamar (Token Security): "An AI agent is non-deterministic. It pursues a goal. It's unpredictable. So you need to treat it differently." Risk scales with access, an agent wired into Salesforce and email carries more risk than one that isn't. Archit Lawkari (EOS, acquired by AppViewX days before RSA) applies zero trust logic, "identity is the parameter." Securing the model directly, he argues, is "somewhat of a futile task."
Inventory: You Can't Secure What You Haven't Found
Mike McKenna (Manifold Security) says most enterprises still can't answer basic questions: "What do I have, what's it made of, what's it connected to, how's that changing over time?" Adoption is outrunning security regardless, "the mandate has come down: thou shalt get AI done." His team is building attack-surface tooling designed for agents, not repurposed chatbot filters.
Governance: Explainability Over Blind Trust
Raj Rajamani (Jetstream Security) frames the unlock as explainability: understanding what a system is doing and capable of doing, not treating it as a black box. His platform includes a kill switch to halt agent action mid-investigation. His thesis: "Unless you trust AI, we will never be able to leverage the full potential of what it has to offer."
Guardrails: Built for Agents, Not Chatbots
Tyler and Sam (Overmind) argue oversized general models are themselves a liability: "Big, generalised models, overcapable, undersupervised." Their bet is scoped, specialised open-weight models that hallucinate less and outperform generalists on narrow tasks. Max Corbridge (Secure Agentics) says the threat side isn't slowing down either, nation-state AI-orchestrated attacks have gone from headline news to "just the standard state of affairs."
Training Data: The Foundational Layer
Andrew Shoker (Hardshell) argues the whole stack sits on unsecured ground: the sensitive, regulated data used to train and fine-tune models. His team modifies training data so it produces safer model weights without encoding raw sensitive data into the model. His analogy: "It's like the brakes on the car, you want to go quickly, but you have to do it safely."
What This Means for Hiring
No single hire covers this stack. Teams need identity and access engineers fluent in non-deterministic systems, data scientists who can build and evaluate specialised smaller models, platform engineers who build explainability and audit tooling, and data security specialists who understand training pipelines. On the commercial side, every founder here is selling to CISOs who don't yet fully trust the category, so GTM hires need real technical depth, not a generic security sales playbook.
Bottom Line
- AI agent security is fragmenting into five layers: identity, inventory, governance, guardrails, and data.
- The founders winning each layer can state precisely which problem they solve, and which they don't.
- Hiring into that nuance, rather than a generic "AI security" job description, is where a specialist search partner earns their keep.
Building out a team across the AI agent security stack? Talk to us about finding the identity, governance, and AI security talent to get there first.