
Most of the architectural argument in agentic AI security right now is about where the control point sits. In-line proxies, MCP gateways, endpoint agents, API integrations, and SaaS audit logs each stake a claim on that position, with different tradeoffs around latency, coverage, and deployment friction.
On August 31, 2026, Gartner analysts Mark Wah, Tarun Rohilla, and David Senf published their latest research report: Emerging Tech: Provider Strategy Trends: Advancing Agentic AI Security Adoption. Opsin is named as an Example Vendor in that research that provides AI security capabilities.
Gartner writes that "AI security has evolved beyond basic prompt injection blocking for non-agentic AI chatbots and AI assistant implementations." Our view of what that evolution demands is narrower than the architecture debate suggests. Agentic AI security depends less on where a control sits than on what it understands about the agent it governs. An enforcement decision made without identity, data, and behavioral context is a guess with latency risks attached.
Agentic AI security is the practice of securing AI agents that plan, invoke tools, and take actions across enterprise systems, distinct from screening the prompts and responses of a chatbot. An assistant that answers a question exposes data, while an agent provisioned with tool access, an identity, and a goal takes actions that compound across systems, each one carrying the permissions of whatever identity provisioned it.
According to Gartner: "AI security has evolved beyond basic prompt injection blocking for non-agentic AI chatbots and AI assistant implementations."
The deployment curve has already turned. Enterprises are running Copilot, ChatGPT Enterprise, Claude, and Gemini in production, and employees are building agents on top of them faster than security teams can inventory. We believe the security question has shifted from whether a model can be talked into saying something it should not, to what an agent is permitted to do, what it is actually doing, and whether anyone can tell the difference.
According to Gartner, ”As enterprise AI evolves, the gap between out-of-band visibility and in-line threat prevention leaves agentic execution risks unblocked. Product leaders must deliver in-line control options, which are critical to securing the market.” Three things stood out to us.
In our opinion, this highlights the limitations of traditional security tools with fragmented signals vs the new agentic security model offering agent visibility, intent, context, and behavior monitoring.
In our view, it also highlights the growing attack surface being created by employee agent builders, many of whom lack the technical background to add necessary guardrails that mitigate risk.
In our opinion, the research draws a hard line between out-of-band approaches, meaning API integrations, agentless collection, and SaaS audit logs, and in-line approaches that sit in the request path. Out-of-band architectures map inventory, track permission drift, and detect violations without adding latency. They do not intercept. In-line architectures intercept, and they carry latency and deployment friction in exchange.
We believe the practical implication for CISOs is that these should be evaluated as two separate line items rather than as competing answers to one requirement, and that the sequence matters. Enforcement without an accurate picture of identity, data, and behavior produces confident decisions about the wrong things.
Gartner states that: "By 2028, over 30% of enterprise AI agent interactions will execute locally on employee endpoints via agent skills instructions or computer-using agent interfaces, bypassing traditional network and cloud-native proxies."
In our view, the mechanism is already visible in enterprise environments observed by Opsin. For example, a developer installs a coding agent that lives in a terminal, then connects it to a local Model Context Protocol (MCP) server. That server holds a token to a repository, a ticketing system, or a reporting database. The agent plans a change, invokes a shell command, and writes. None of that traverses a corporate proxy, and little of it lands in an audit log a security team can reconstruct afterward.
The same pattern runs in the business, where an analyst builds an agent on a sanctioned platform, points it at a CRM connector and a shared drive, and schedules it as a non-human identity with standing access and no offboarding attached.
We believe the practical implication for CISOs is that all non-human identities attached to sanctioned AI must be inventoried and mapped to a human owner with data access and permissions scoped. Every identity should also have an expiration date because standing access with no offboarding turns into orphaned agents with lasting exposure potential.
As Gartner notes in the report: "The universal baseline relies on automation and posture, where agentic security operations and AI security posture management (AISPM) remain the foundation across all tracked industries."
AI security posture management means continuously mapping AI assets, the identities attached to them, the data they can reach, and the configuration governing all three.
To us, the word that has to change is static. A CSPM finding is true or false at the moment you evaluate it. An agent finding is a distribution over time, because an agent can hold exactly the permissions it was granted on day one and still be doing something the organization never sanctioned.
We believe the practical implication for CISOs will be that agent governance must include attaching agents to their stated purpose the moment access is granted. Without it, behavioral drift becomes undetectable by design.
In our opinion, this is an important lens in a market where it’s increasingly difficult to distinguish between capabilities of agentic security vendors.
To us, a consistent theme throughout the report is that traditional security tools are structurally unable to observe what now carries the risk. The exposure in agentic deployments sits in the relationship between an agent, the identity permissions it assumes, and the data those permissions can reach. We believe vendors that offer agent context, intent, and behavioral monitoring are better positioned to support secure enterprise-scale AI adoption.
Most regulated buyers reach first for the controls they already own, and they are right to. Secure service edge, CASB, and DLP are mature, audited, already budgeted, and they do real work on AI traffic. What they inspect is a channel, but, in our experience, an AI interaction is not usefully modeled as a channel. The risk is in the join between an identity, a permission, and a model that can traverse both.
For example, in one Opsin enterprise customer Copilot deployment, Copilot inherits the permissions of the invoking user, so a legacy SharePoint site with broken permission inheritance can surface a compensation file to an employee who would never have located that site by browsing. No pattern fired, no network-layer policy was violated, and the data was technically authorized while being practically exposed.
This is where agentic AI security and enterprise data governance stop being separate programs. The AI layer does not create new permissions. It makes existing permission debt reachable at conversational speed.
In our view, enterprise AI decisions depend on context the traffic layer never had, which is why identity and data governance are becoming inputs to AI security rather than programs that run beside it.
Opsin is named as an Example Vendor in Gartner: Emerging Tech: Provider Strategy Trends: Advancing Agentic AI Security Adoption
We believe the inclusion reflects where we have chosen to build: a dynamic contextual layer that connects identity, data, and model behavior for sanctioned enterprise AI. We help organizations see, understand, and prioritize the agentic risk that matters most.
We believe this focus aligns to the new paradigm shift Gartner highlights in the report. As enterprises scale agentic AI, they need governance that understands an agent’s full context to classify and control business risk.
In our view, four principles we identified in the research reflect Opsin’s approach. We expect each to matter more as enterprises continue to scale agentic AI.
By helping teams classify risk with full context, Opsin enables organizations to scale agent adoption without increasing risk.
In our opinion, Gartner Emerging Tech: Provider Strategy Trends: Advancing Agentic AI Security Adoption report marks an important shift in the enterprise security model. Agent intent and context are critical inputs for agentic governance.
The workforce is building agents with enterprise permissions, data access, and connected tools faster than security can track. Opsin’s is purpose-built for an agentic focused security model, surfacing agent context that helps teams prioritize risk while governing agents and agent-builders across the workforce.
Gartner clients can access the full report here: Emerging Tech: Provider Strategy Trends: Advancing Agentic AI Security Adoption
Gartner, Emerging Tech: Provider Strategy Trends Advancing Agentic AI Security Adoption, 31 August 2026.
GARTNER is a trademark of Gartner, Inc. and/or its affiliates. Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.
Most of the architectural argument in agentic AI security right now is about where the control point sits. In-line proxies, MCP gateways, endpoint agents, API integrations, and SaaS audit logs each stake a claim on that position, with different tradeoffs around latency, coverage, and deployment friction.
On August 31, 2026, Gartner analysts Mark Wah, Tarun Rohilla, and David Senf published their latest research report: Emerging Tech: Provider Strategy Trends: Advancing Agentic AI Security Adoption. Opsin is named as an Example Vendor in that research that provides AI security capabilities.
Gartner writes that "AI security has evolved beyond basic prompt injection blocking for non-agentic AI chatbots and AI assistant implementations." Our view of what that evolution demands is narrower than the architecture debate suggests. Agentic AI security depends less on where a control sits than on what it understands about the agent it governs. An enforcement decision made without identity, data, and behavioral context is a guess with latency risks attached.
Agentic AI security is the practice of securing AI agents that plan, invoke tools, and take actions across enterprise systems, distinct from screening the prompts and responses of a chatbot. An assistant that answers a question exposes data, while an agent provisioned with tool access, an identity, and a goal takes actions that compound across systems, each one carrying the permissions of whatever identity provisioned it.
According to Gartner: "AI security has evolved beyond basic prompt injection blocking for non-agentic AI chatbots and AI assistant implementations."
The deployment curve has already turned. Enterprises are running Copilot, ChatGPT Enterprise, Claude, and Gemini in production, and employees are building agents on top of them faster than security teams can inventory. We believe the security question has shifted from whether a model can be talked into saying something it should not, to what an agent is permitted to do, what it is actually doing, and whether anyone can tell the difference.
According to Gartner, ”As enterprise AI evolves, the gap between out-of-band visibility and in-line threat prevention leaves agentic execution risks unblocked. Product leaders must deliver in-line control options, which are critical to securing the market.” Three things stood out to us.
In our opinion, this highlights the limitations of traditional security tools with fragmented signals vs the new agentic security model offering agent visibility, intent, context, and behavior monitoring.
In our view, it also highlights the growing attack surface being created by employee agent builders, many of whom lack the technical background to add necessary guardrails that mitigate risk.
In our opinion, the research draws a hard line between out-of-band approaches, meaning API integrations, agentless collection, and SaaS audit logs, and in-line approaches that sit in the request path. Out-of-band architectures map inventory, track permission drift, and detect violations without adding latency. They do not intercept. In-line architectures intercept, and they carry latency and deployment friction in exchange.
We believe the practical implication for CISOs is that these should be evaluated as two separate line items rather than as competing answers to one requirement, and that the sequence matters. Enforcement without an accurate picture of identity, data, and behavior produces confident decisions about the wrong things.
Gartner states that: "By 2028, over 30% of enterprise AI agent interactions will execute locally on employee endpoints via agent skills instructions or computer-using agent interfaces, bypassing traditional network and cloud-native proxies."
In our view, the mechanism is already visible in enterprise environments observed by Opsin. For example, a developer installs a coding agent that lives in a terminal, then connects it to a local Model Context Protocol (MCP) server. That server holds a token to a repository, a ticketing system, or a reporting database. The agent plans a change, invokes a shell command, and writes. None of that traverses a corporate proxy, and little of it lands in an audit log a security team can reconstruct afterward.
The same pattern runs in the business, where an analyst builds an agent on a sanctioned platform, points it at a CRM connector and a shared drive, and schedules it as a non-human identity with standing access and no offboarding attached.
We believe the practical implication for CISOs is that all non-human identities attached to sanctioned AI must be inventoried and mapped to a human owner with data access and permissions scoped. Every identity should also have an expiration date because standing access with no offboarding turns into orphaned agents with lasting exposure potential.
As Gartner notes in the report: "The universal baseline relies on automation and posture, where agentic security operations and AI security posture management (AISPM) remain the foundation across all tracked industries."
AI security posture management means continuously mapping AI assets, the identities attached to them, the data they can reach, and the configuration governing all three.
To us, the word that has to change is static. A CSPM finding is true or false at the moment you evaluate it. An agent finding is a distribution over time, because an agent can hold exactly the permissions it was granted on day one and still be doing something the organization never sanctioned.
We believe the practical implication for CISOs will be that agent governance must include attaching agents to their stated purpose the moment access is granted. Without it, behavioral drift becomes undetectable by design.
In our opinion, this is an important lens in a market where it’s increasingly difficult to distinguish between capabilities of agentic security vendors.
To us, a consistent theme throughout the report is that traditional security tools are structurally unable to observe what now carries the risk. The exposure in agentic deployments sits in the relationship between an agent, the identity permissions it assumes, and the data those permissions can reach. We believe vendors that offer agent context, intent, and behavioral monitoring are better positioned to support secure enterprise-scale AI adoption.
Most regulated buyers reach first for the controls they already own, and they are right to. Secure service edge, CASB, and DLP are mature, audited, already budgeted, and they do real work on AI traffic. What they inspect is a channel, but, in our experience, an AI interaction is not usefully modeled as a channel. The risk is in the join between an identity, a permission, and a model that can traverse both.
For example, in one Opsin enterprise customer Copilot deployment, Copilot inherits the permissions of the invoking user, so a legacy SharePoint site with broken permission inheritance can surface a compensation file to an employee who would never have located that site by browsing. No pattern fired, no network-layer policy was violated, and the data was technically authorized while being practically exposed.
This is where agentic AI security and enterprise data governance stop being separate programs. The AI layer does not create new permissions. It makes existing permission debt reachable at conversational speed.
In our view, enterprise AI decisions depend on context the traffic layer never had, which is why identity and data governance are becoming inputs to AI security rather than programs that run beside it.
Opsin is named as an Example Vendor in Gartner: Emerging Tech: Provider Strategy Trends: Advancing Agentic AI Security Adoption
We believe the inclusion reflects where we have chosen to build: a dynamic contextual layer that connects identity, data, and model behavior for sanctioned enterprise AI. We help organizations see, understand, and prioritize the agentic risk that matters most.
We believe this focus aligns to the new paradigm shift Gartner highlights in the report. As enterprises scale agentic AI, they need governance that understands an agent’s full context to classify and control business risk.
In our view, four principles we identified in the research reflect Opsin’s approach. We expect each to matter more as enterprises continue to scale agentic AI.
By helping teams classify risk with full context, Opsin enables organizations to scale agent adoption without increasing risk.
In our opinion, Gartner Emerging Tech: Provider Strategy Trends: Advancing Agentic AI Security Adoption report marks an important shift in the enterprise security model. Agent intent and context are critical inputs for agentic governance.
The workforce is building agents with enterprise permissions, data access, and connected tools faster than security can track. Opsin’s is purpose-built for an agentic focused security model, surfacing agent context that helps teams prioritize risk while governing agents and agent-builders across the workforce.
Gartner clients can access the full report here: Emerging Tech: Provider Strategy Trends: Advancing Agentic AI Security Adoption
Gartner, Emerging Tech: Provider Strategy Trends Advancing Agentic AI Security Adoption, 31 August 2026.
GARTNER is a trademark of Gartner, Inc. and/or its affiliates. Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.