Opsin named in 2026 Gartner® Emerging Tech: Provider Strategy Trends Advancing Agentic AI Security Adoption

Industry Insights
News

Key Takeaways

Agentic AI security has moved past prompt filtering to governing the actions agents take.
Gartner predicts by 2028, “over 30% of enterprise AI agent interactions will execute locally on employee endpoints via agent skills instructions or computer-using agent interfaces, bypassing traditional network and cloud-native proxies."
Detection is expected to shift from static pattern matching to continuous validation of agent behavior.
Inherited permissions, not external attackers, drive most of the AI exposure Opsin finds in enterprise environments.
Opsin is named as an Example Vendor that provides AI security capabilities

Most of the architectural argument in agentic AI security right now is about where the control point sits. In-line proxies, MCP gateways, endpoint agents, API integrations, and SaaS audit logs each stake a claim on that position, with different tradeoffs around latency, coverage, and deployment friction. 

On August 31, 2026, Gartner analysts Mark Wah, Tarun Rohilla, and David Senf published their latest research report: Emerging Tech: Provider Strategy Trends: Advancing Agentic AI Security Adoption. Opsin is named as an Example Vendor in that research that provides AI security capabilities. 

Gartner writes that "AI security has evolved beyond basic prompt injection blocking for non-agentic AI chatbots and AI assistant implementations." Our view of what that evolution demands is narrower than the architecture debate suggests. Agentic AI security depends less on where a control sits than on what it understands about the agent it governs. An enforcement decision made without identity, data, and behavioral context is a guess with latency risks attached.

What Is Agentic AI Security and Why It Matters Now

Agentic AI security is the practice of securing AI agents that plan, invoke tools, and take actions across enterprise systems, distinct from screening the prompts and responses of a chatbot. An assistant that answers a question exposes data, while an agent provisioned with tool access, an identity, and a goal takes actions that compound across systems, each one carrying the permissions of whatever identity provisioned it.

According to Gartner: "AI security has evolved beyond basic prompt injection blocking for non-agentic AI chatbots and AI assistant implementations."

The deployment curve has already turned. Enterprises are running Copilot, ChatGPT Enterprise, Claude, and Gemini in production, and employees are building agents on top of them faster than security teams can inventory. We believe the security question has shifted from whether a model can be talked into saying something it should not, to what an agent is permitted to do, what it is actually doing, and whether anyone can tell the difference.

What's New to us from the Gartner® Provider Strategy Trends: Advancing Agentic AI Security Adoption Report

According to Gartner, ”As enterprise AI evolves, the gap between out-of-band visibility and in-line threat prevention leaves agentic execution risks unblocked. Product leaders must deliver in-line control options, which are critical to securing the market.”  Three things stood out to us. 

  1. The research separates architectures that deliver visibility from architectures that deliver prevention, treating that as a consequence of the deployment model rather than a feature gap. 
  2. The report forecasts that agent execution is migrating onto employee endpoints, outside the paths most enterprise security tooling is built to observe. 
  3. The report surfaces a greater emphasis on intent and behavioral validation as the direction detection engines need to move, which is a meaningfully different claim from the pattern matching most AI security tools ship today.

In our opinion, this highlights the limitations of traditional security tools with fragmented signals vs the new agentic security model offering agent visibility, intent, context, and behavior monitoring.  

In our view, it also highlights the growing attack surface being created by employee agent builders, many of whom lack the technical background to add necessary guardrails that mitigate risk. 

Our Key Findings: Agent Execution Is Outrunning the Network Perimeter

1. Visibility Architectures and Prevention Architectures Are Not the Same Thing

In our opinion, the research draws a hard line between out-of-band approaches, meaning API integrations, agentless collection, and SaaS audit logs, and in-line approaches that sit in the request path. Out-of-band architectures map inventory, track permission drift, and detect violations without adding latency. They do not intercept. In-line architectures intercept, and they carry latency and deployment friction in exchange.

We believe the practical implication for CISOs is that these should be evaluated as two separate line items rather than as competing answers to one requirement, and that the sequence matters. Enforcement without an accurate picture of identity, data, and behavior produces confident decisions about the wrong things.

2. Agent Execution Is Moving to the Employee Endpoint

Gartner states that: "By 2028, over 30% of enterprise AI agent interactions will execute locally on employee endpoints via agent skills instructions or computer-using agent interfaces, bypassing traditional network and cloud-native proxies."

In our view, the mechanism is already visible in enterprise environments observed by Opsin. For example, a developer installs a coding agent that lives in a terminal, then connects it to a local Model Context Protocol (MCP) server. That server holds a token to a repository, a ticketing system, or a reporting database. The agent plans a change, invokes a shell command, and writes. None of that traverses a corporate proxy, and little of it lands in an audit log a security team can reconstruct afterward. 

The same pattern runs in the business, where an analyst builds an agent on a sanctioned platform, points it at a CRM connector and a shared drive, and schedules it as a non-human identity with standing access and no offboarding attached.

We believe the practical implication for CISOs is that all non-human identities attached to sanctioned AI must be inventoried and mapped to a human owner with data access and permissions scoped. Every identity should also have an expiration date because standing access with no offboarding turns into orphaned agents with lasting exposure potential.

3. Posture and Automation Remain the Universal Baseline

As Gartner notes in the report: "The universal baseline relies on automation and posture, where agentic security operations and AI security posture management (AISPM) remain the foundation across all tracked industries."

AI security posture management means continuously mapping AI assets, the identities attached to them, the data they can reach, and the configuration governing all three. 

To us, the word that has to change is static. A CSPM finding is true or false at the moment you evaluate it. An agent finding is a distribution over time, because an agent can hold exactly the permissions it was granted on day one and still be doing something the organization never sanctioned.

We believe the practical implication for CISOs will be that agent governance must include attaching agents to their stated purpose the moment access is granted. Without it, behavioral drift becomes undetectable by design. 

How, in our opinion, Gartner Evaluates Emerging Tech Providers in Agentic AI Security

In our opinion, this is an important lens in a market where it’s increasingly difficult to distinguish between capabilities of agentic security vendors.

To us, a consistent theme throughout the report is that traditional security tools are structurally unable to observe what now carries the risk. The exposure in agentic deployments sits in the relationship between an agent, the identity permissions it assumes, and the data those permissions can reach. We believe vendors that offer agent context, intent, and behavioral monitoring are better positioned to support secure enterprise-scale AI adoption. 

Where Agentic AI Security and Enterprise Data Governance Converge

Most regulated buyers reach first for the controls they already own, and they are right to. Secure service edge, CASB, and DLP are mature, audited, already budgeted, and they do real work on AI traffic. What they inspect is a channel, but, in our experience, an AI interaction is not usefully modeled as a channel. The risk is in the join between an identity, a permission, and a model that can traverse both.

For example, in one Opsin enterprise customer Copilot deployment, Copilot inherits the permissions of the invoking user, so a legacy SharePoint site with broken permission inheritance can surface a compensation file to an employee who would never have located that site by browsing. No pattern fired, no network-layer policy was violated, and the data was technically authorized while being practically exposed. 

This is where agentic AI security and enterprise data governance stop being separate programs. The AI layer does not create new permissions. It makes existing permission debt reachable at conversational speed.

In our view, enterprise AI decisions depend on context the traffic layer never had, which is why identity and data governance are becoming inputs to AI security rather than programs that run beside it.

Opsin's Inclusion in the Gartner Report

Opsin is named as an Example Vendor in Gartner: Emerging Tech: Provider Strategy Trends: Advancing Agentic AI Security Adoption

We believe the inclusion reflects where we have chosen to build: a dynamic contextual layer that connects identity, data, and model behavior for sanctioned enterprise AI. We help organizations see, understand, and prioritize the agentic risk that matters most. 

We believe this focus aligns to the new paradigm shift Gartner highlights in the report. As enterprises scale agentic AI, they need governance that understands an agent’s full context to  classify and control business risk.

How We Believe Opsin Aligns with the Gartner AI Security Trends Analysis

In our view, four principles we identified in the research reflect Opsin’s approach. We expect each to matter more as enterprises continue to scale agentic AI. 

  • Posture and control are two halves of one architecture | Opsin surfaces the contextual layer. Enforcement decisions made without it are a guess.
  • Intent has to be measured continuously | Behavior only means something against what an agent was originally intended to do.
  • Quantify exposure before governing | Simulated real user queries give security teams a baseline within 24 hours.
  • Seek framework-agnostic coverage | Most enterprise environments sanction multiple tools (Copilot, ChatGPT Enterprise, Claude, and Gemini) 

By helping teams classify risk with full context, Opsin enables organizations to scale agent adoption without increasing risk. 

Conclusion

In our opinion, Gartner Emerging Tech: Provider Strategy Trends: Advancing Agentic AI Security Adoption report marks an important shift in the enterprise security model. Agent intent and context are critical inputs for agentic governance.

The workforce is building agents with enterprise permissions, data access, and connected tools faster than security can track. Opsin’s is purpose-built for an agentic focused security model,  surfacing agent context that helps teams prioritize risk while governing agents and agent-builders across the workforce.

Gartner clients can access the full report here: Emerging Tech: Provider Strategy Trends: Advancing Agentic AI Security Adoption

Interested in seeing Opsin in action? 

Get a Demo

Gartner, Emerging Tech: Provider Strategy Trends Advancing Agentic AI Security Adoption, 31 August 2026. 

GARTNER is a trademark of Gartner, Inc. and/or its affiliates. Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.

Table of Contents

LinkedIn Bio >

FAQ

No items found.
About the Author
Oz Wasserman
Oz Wasserman is the Co-Founder and CPO of Opsin, with over 15 years of cybersecurity experience focused on security engineering, data security, governance, and product development. He has held key roles at Abnormal Security, FireEye, and Reco.AI, and has a strong background in security engineering from his military service.
LinkedIn Bio >

Opsin named in 2026 Gartner® Emerging Tech: Provider Strategy Trends Advancing Agentic AI Security Adoption

Most of the architectural argument in agentic AI security right now is about where the control point sits. In-line proxies, MCP gateways, endpoint agents, API integrations, and SaaS audit logs each stake a claim on that position, with different tradeoffs around latency, coverage, and deployment friction. 

On August 31, 2026, Gartner analysts Mark Wah, Tarun Rohilla, and David Senf published their latest research report: Emerging Tech: Provider Strategy Trends: Advancing Agentic AI Security Adoption. Opsin is named as an Example Vendor in that research that provides AI security capabilities. 

Gartner writes that "AI security has evolved beyond basic prompt injection blocking for non-agentic AI chatbots and AI assistant implementations." Our view of what that evolution demands is narrower than the architecture debate suggests. Agentic AI security depends less on where a control sits than on what it understands about the agent it governs. An enforcement decision made without identity, data, and behavioral context is a guess with latency risks attached.

What Is Agentic AI Security and Why It Matters Now

Agentic AI security is the practice of securing AI agents that plan, invoke tools, and take actions across enterprise systems, distinct from screening the prompts and responses of a chatbot. An assistant that answers a question exposes data, while an agent provisioned with tool access, an identity, and a goal takes actions that compound across systems, each one carrying the permissions of whatever identity provisioned it.

According to Gartner: "AI security has evolved beyond basic prompt injection blocking for non-agentic AI chatbots and AI assistant implementations."

The deployment curve has already turned. Enterprises are running Copilot, ChatGPT Enterprise, Claude, and Gemini in production, and employees are building agents on top of them faster than security teams can inventory. We believe the security question has shifted from whether a model can be talked into saying something it should not, to what an agent is permitted to do, what it is actually doing, and whether anyone can tell the difference.

What's New to us from the Gartner® Provider Strategy Trends: Advancing Agentic AI Security Adoption Report

According to Gartner, ”As enterprise AI evolves, the gap between out-of-band visibility and in-line threat prevention leaves agentic execution risks unblocked. Product leaders must deliver in-line control options, which are critical to securing the market.”  Three things stood out to us. 

  1. The research separates architectures that deliver visibility from architectures that deliver prevention, treating that as a consequence of the deployment model rather than a feature gap. 
  2. The report forecasts that agent execution is migrating onto employee endpoints, outside the paths most enterprise security tooling is built to observe. 
  3. The report surfaces a greater emphasis on intent and behavioral validation as the direction detection engines need to move, which is a meaningfully different claim from the pattern matching most AI security tools ship today.

In our opinion, this highlights the limitations of traditional security tools with fragmented signals vs the new agentic security model offering agent visibility, intent, context, and behavior monitoring.  

In our view, it also highlights the growing attack surface being created by employee agent builders, many of whom lack the technical background to add necessary guardrails that mitigate risk. 

Our Key Findings: Agent Execution Is Outrunning the Network Perimeter

1. Visibility Architectures and Prevention Architectures Are Not the Same Thing

In our opinion, the research draws a hard line between out-of-band approaches, meaning API integrations, agentless collection, and SaaS audit logs, and in-line approaches that sit in the request path. Out-of-band architectures map inventory, track permission drift, and detect violations without adding latency. They do not intercept. In-line architectures intercept, and they carry latency and deployment friction in exchange.

We believe the practical implication for CISOs is that these should be evaluated as two separate line items rather than as competing answers to one requirement, and that the sequence matters. Enforcement without an accurate picture of identity, data, and behavior produces confident decisions about the wrong things.

2. Agent Execution Is Moving to the Employee Endpoint

Gartner states that: "By 2028, over 30% of enterprise AI agent interactions will execute locally on employee endpoints via agent skills instructions or computer-using agent interfaces, bypassing traditional network and cloud-native proxies."

In our view, the mechanism is already visible in enterprise environments observed by Opsin. For example, a developer installs a coding agent that lives in a terminal, then connects it to a local Model Context Protocol (MCP) server. That server holds a token to a repository, a ticketing system, or a reporting database. The agent plans a change, invokes a shell command, and writes. None of that traverses a corporate proxy, and little of it lands in an audit log a security team can reconstruct afterward. 

The same pattern runs in the business, where an analyst builds an agent on a sanctioned platform, points it at a CRM connector and a shared drive, and schedules it as a non-human identity with standing access and no offboarding attached.

We believe the practical implication for CISOs is that all non-human identities attached to sanctioned AI must be inventoried and mapped to a human owner with data access and permissions scoped. Every identity should also have an expiration date because standing access with no offboarding turns into orphaned agents with lasting exposure potential.

3. Posture and Automation Remain the Universal Baseline

As Gartner notes in the report: "The universal baseline relies on automation and posture, where agentic security operations and AI security posture management (AISPM) remain the foundation across all tracked industries."

AI security posture management means continuously mapping AI assets, the identities attached to them, the data they can reach, and the configuration governing all three. 

To us, the word that has to change is static. A CSPM finding is true or false at the moment you evaluate it. An agent finding is a distribution over time, because an agent can hold exactly the permissions it was granted on day one and still be doing something the organization never sanctioned.

We believe the practical implication for CISOs will be that agent governance must include attaching agents to their stated purpose the moment access is granted. Without it, behavioral drift becomes undetectable by design. 

How, in our opinion, Gartner Evaluates Emerging Tech Providers in Agentic AI Security

In our opinion, this is an important lens in a market where it’s increasingly difficult to distinguish between capabilities of agentic security vendors.

To us, a consistent theme throughout the report is that traditional security tools are structurally unable to observe what now carries the risk. The exposure in agentic deployments sits in the relationship between an agent, the identity permissions it assumes, and the data those permissions can reach. We believe vendors that offer agent context, intent, and behavioral monitoring are better positioned to support secure enterprise-scale AI adoption. 

Where Agentic AI Security and Enterprise Data Governance Converge

Most regulated buyers reach first for the controls they already own, and they are right to. Secure service edge, CASB, and DLP are mature, audited, already budgeted, and they do real work on AI traffic. What they inspect is a channel, but, in our experience, an AI interaction is not usefully modeled as a channel. The risk is in the join between an identity, a permission, and a model that can traverse both.

For example, in one Opsin enterprise customer Copilot deployment, Copilot inherits the permissions of the invoking user, so a legacy SharePoint site with broken permission inheritance can surface a compensation file to an employee who would never have located that site by browsing. No pattern fired, no network-layer policy was violated, and the data was technically authorized while being practically exposed. 

This is where agentic AI security and enterprise data governance stop being separate programs. The AI layer does not create new permissions. It makes existing permission debt reachable at conversational speed.

In our view, enterprise AI decisions depend on context the traffic layer never had, which is why identity and data governance are becoming inputs to AI security rather than programs that run beside it.

Opsin's Inclusion in the Gartner Report

Opsin is named as an Example Vendor in Gartner: Emerging Tech: Provider Strategy Trends: Advancing Agentic AI Security Adoption

We believe the inclusion reflects where we have chosen to build: a dynamic contextual layer that connects identity, data, and model behavior for sanctioned enterprise AI. We help organizations see, understand, and prioritize the agentic risk that matters most. 

We believe this focus aligns to the new paradigm shift Gartner highlights in the report. As enterprises scale agentic AI, they need governance that understands an agent’s full context to  classify and control business risk.

How We Believe Opsin Aligns with the Gartner AI Security Trends Analysis

In our view, four principles we identified in the research reflect Opsin’s approach. We expect each to matter more as enterprises continue to scale agentic AI. 

  • Posture and control are two halves of one architecture | Opsin surfaces the contextual layer. Enforcement decisions made without it are a guess.
  • Intent has to be measured continuously | Behavior only means something against what an agent was originally intended to do.
  • Quantify exposure before governing | Simulated real user queries give security teams a baseline within 24 hours.
  • Seek framework-agnostic coverage | Most enterprise environments sanction multiple tools (Copilot, ChatGPT Enterprise, Claude, and Gemini) 

By helping teams classify risk with full context, Opsin enables organizations to scale agent adoption without increasing risk. 

Conclusion

In our opinion, Gartner Emerging Tech: Provider Strategy Trends: Advancing Agentic AI Security Adoption report marks an important shift in the enterprise security model. Agent intent and context are critical inputs for agentic governance.

The workforce is building agents with enterprise permissions, data access, and connected tools faster than security can track. Opsin’s is purpose-built for an agentic focused security model,  surfacing agent context that helps teams prioritize risk while governing agents and agent-builders across the workforce.

Gartner clients can access the full report here: Emerging Tech: Provider Strategy Trends: Advancing Agentic AI Security Adoption

Interested in seeing Opsin in action? 

Get a Demo

Gartner, Emerging Tech: Provider Strategy Trends Advancing Agentic AI Security Adoption, 31 August 2026. 

GARTNER is a trademark of Gartner, Inc. and/or its affiliates. Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.

Your Name*
Job Title*
Business Email*
Your copy
is ready!
Please check for errors and try again.

Turn workforce AI sprawl into risk clarity

See every agent, what it can reach, and what to fix.
Get a demo →