* [![perspectives](https://origin-www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2025/02/prespective-icon.png)](https://origin-www.paloaltonetworks.com.au/perspectives)
* Securing AI Agents: Building the Landing Gear While Flying the Plane

English

* [English](https://develop.paloaltonetworks.com/perspectives/securing-ai-agents-building-the-landing-gear-while-flying-the-plane)
* [Français (French)](https://www.paloaltonetworks.fr/perspectives/securing-ai-agents-building-the-landing-gear-while-flying-the-plane/)
* [日本語 (Japanese)](https://www.paloaltonetworks.jp/perspectives/securing-ai-agents-building-the-landing-gear-while-flying-the-plane/)
* [简体中文 (Chinese -Simplified)](https://www.paloaltonetworks.cn/perspectives/securing-ai-agents-building-the-landing-gear-while-flying-the-plane/)
* [繁體中文 (Chinese -Traditional)](https://www.paloaltonetworks.tw/perspectives/securing-ai-agents-building-the-landing-gear-while-flying-the-plane/)
* [Deutsch (German)](https://www.paloaltonetworks.de/perspectives/securing-ai-agents-building-the-landing-gear-while-flying-the-plane/)
* [한국어 (Korean)](https://www.paloaltonetworks.co.kr/perspectives/securing-ai-agents-building-the-landing-gear-while-flying-the-plane/)
* [Español (Spanish)](https://www.paloaltonetworks.es/perspectives/securing-ai-agents-building-the-landing-gear-while-flying-the-plane/)

# Securing AI Agents: Building the Landing Gear While Flying the Plane

![Securing AI Agents: Building the Landing Gear While Flying the Plane](https://origin-www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2025/06/securing-ai-agents-featured.jpg)  
**By [Dr. Nicole Nichols](https://origin-www.paloaltonetworks.com.au/perspectives/author/dr-nicole-nichols/ "Posts by Dr. Nicole Nichols")** | **7 min read** |  
![share icon](https://paloaltonetworks.com/content/dam/pan/en_US/cxo-perspectives/images/cxo-share.svg)

* LinkedIn button ![linkedin-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-linkedin.svg)
* Twitter share button ![twitter-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-twitter-x-black.svg)
* \[Email share button ![email-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-email.svg)\](mailto:?subject=Securing AI Agents: Building the Landing Gear While Flying the Plane\&body=Check out this article https%3A%2F%2Forigin-www.paloaltonetworks.com.au%2Fperspectives%2Fsecuring-ai-agents-building-the-landing-gear-while-flying-the-plane%2F "Share in Email")
* ![copy-icon](https://origin-www.paloaltonetworks.com.au/perspectives/wp-content/themes/csp2025/dist/images/icons/icon-share.svg)
  [](https://origin-www.paloaltonetworks.com.au/perspectives/securing-ai-agents-building-the-landing-gear-while-flying-the-plane/?pdf=download&lg=en&_wpnonce=83197ae001 "Click here to download") MEET THE AUTHOR  
  ![](https://origin-www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2025/06/nicole-nichols.jpg)  
  Nicole Nichols is a Distinguished Engineer in Machine Learning Security at Palo Alto Networks. She previously held senior roles at Apple, Microsoft and has contributed to both academia and industry advancements in adversarial machine learning and security. She has published at numerous ACM, IEEE, and CVPR workshops, and was co-chair of ICML-ML4Cyber workshop. She has a PhD in Electrical Engineering from the University of Washington....

[Learn more](https://origin-www.paloaltonetworks.com.au/perspectives/author/dr-nicole-nichols/)

## IN THIS ARTICLE

When I began working on autonomous cyber agents in 2020, the timeline for real-world deployment was still measured in decades. At the time, these systems were seen as long-range bets --- interesting but still mostly niche improvements for any near-term application.

Then, something changed.

While generative AI (GenAI) wasn't one, singular event, it unleashed an ongoing cascade of advances that are, to this day, causing development timelines to collapse at a continuously accelerating rate. This isn't just a case of moving the goal; the GenAI-driven wave is relentlessly bulldozing old benchmarks and redefining the frontier of what's possible, faster than we've ever experienced before. Capabilities once reserved for long-term research are now being integrated into live environments with astonishing speed.

Startlingly, but not surprisingly, agentic systems are being embedded in countless locations --- company workflows, decision-making pipelines and even critical infrastructure --- often before we've established how to govern or secure them. The year 2020 seems a lifetime ago considering we're no longer preparing for the arrival of agentic AI but responding to its continued and rapid evolution.

## A Paper for a Moving Target

The workshop report I've co-authored, *[Achieving a Secure AI Agent Ecosystem](https://www.schmidtsciences.org/wp-content/uploads/2025/06/Achieving_a_Secure_AI_Agent_Ecosystem-3.pdf)* , is the product of a cross-institutional effort to make sense of this acceleration. Developed in partnership with [RAND](https://www.rand.org/), [Schmidt Sciences](https://www.schmidtsciences.org/), and leading minds in agentic AI from across industry, academia, and government, the paper doesn't offer silver bullets but rather a different way to think about and approach agentic AI.

The crux of the paper outlines three foundational security pillars for AI agents and suggests where our current assumptions --- and infrastructure --- might falter as these systems evolve. Beyond simply acknowledging current realities, this argues for a profound mindset shift: We must recognize that the age of agentic systems is already upon us. Consequently, securing these systems is not a problem for tomorrow. It's an urgent challenge today that's intensified by the relentless pace of innovation, expanding scale, uneven risks for early adopters and the stark asymmetry between attack capabilities and defense goals.

One of the challenges in securing AI agents is that these systems don't look or behave like traditional software. They are dynamic, evolving and increasingly capable of executing decisions with minimal oversight. Some are purpose-built to automate tasks like scheduling or sorting email; others are inching toward fully autonomous action in high-stakes environments. In either case, the frameworks we use to secure traditional applications aren't enough. We are encountering problems that aren't merely variations on known vulnerabilities but are fundamentally new. The attack surface has shifted.

## Three Pillars for AI Agent Security

This mindset shift is why the security landscape has been organized around three core concerns:

* **Protecting AI agents from third-party compromise:** How to safeguard the AI agents themselves from being taken over or manipulated by external attackers.
* **Protecting users and organizations from the agents themselves:** How to ensure that the AI agents, even when operating as intended or if they malfunction, do not harm their users or the organizations they serve.
* **Protecting critical systems from malicious agents:** How to defend essential infrastructure and systems against AI agents that are intentionally designed and deployed to cause harm.

These categories are not static --- they are points along a spectrum of capability and threat maturity. Today, most organizations that deploy agents are dealing with the first two concerns. But the third --- malicious, autonomous adversaries --- looms large. Nation-states were among the first to invest in autonomous cyber agents.^1^ They may not be alone for long.

Navigating this new era of potent, widespread autonomous threats, therefore, demands far more than incremental refinements to existing defenses. It requires a foundational shift in how our expert communities must collaborate and innovate on security.

Historically, AI researchers and cybersecurity professionals often operated on parallel tracks, holding different assumptions about risk and architecture. Yet, the complex frontier of agentic AI security demands their unified effort, as neither community can tackle these immense challenges in isolation --- making deep, sustained collaboration paramount. And while universal protocols and comprehensive best practices for this entire field are still maturing, the notion that effective turnkey products for securing agents are scarce is, frankly, becoming outdated. [Sophisticated, deployable solutions](https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security) are now offering vital, specialized protection for critical agentic systems, signaling tangible progress. This further underscores the urgent need for adaptive, multilayered security strategies --- spanning model provenance, robust containment and resilient human-in-the-loop controls --- all evolving as rapidly as the agents themselves.

## Interventions Within Reach

While robust and evolving product solutions are increasingly crucial in mitigating the immediate operational risks posed by agentic AI, achieving comprehensive, long-term security also necessitates dedicated industry-wide investment in foundational capabilities and shared understanding. Several such key directions, complementing product innovation, are well within our collective reach and warrant-focused effort.

For instance, a kind of "agent bill of materials," modeled after the "software bill of materials," is envisioned to provide visibility into an agent's components like its model, training data, tools and memory. However, its functional viability currently faces hurdles, such as the lack of a common system for model identifiers, which is crucial for such transparency.

Additionally, standardized, predeployment test beds could allow for scalable, scenario-based evaluations before agents are released into production environments. And communication protocols like MCP (Model Context Protocol) and A2A (Agent-to-Agent) are emerging, but few have [security baked in from the start](https://unit42.paloaltonetworks.com/agentic-ai-threats/). However, even when security measures are integrated from the outset, the prevalence of "unknown unknowns" in these novel agentic systems means these protocols will require rigorous and continuous assessment to maintain their integrity and safety.

One approach our paper attempts to navigate is the critical challenge that an agent's memory, while essential for it to learn, improve, and crucially avoid repeating past mistakes, is also a significant vulnerability that can be targeted for malicious tampering. The strategy involves using "clone-on-launch" or task-specific agent instances. In this model, agents designed for particular operational duties or limited-duration interactions treat their *active working memory* as ephemeral. Once their specific task or session is complete, these instances can be retired, with new operations handled by fresh instances that are initialized from a secure, trusted baseline.

This practice aims to significantly reduce the risk of *persistent* memory corruption or the lingering effects of tampering that might occur within a single session. It is paramount, however, that such a system is meticulously architected to ensure an agent's core foundational knowledge and long-term learned lessons are securely maintained, protected against tampering, and effectively and safely accessible to inform these more transient operational instances. While managing operational states in this manner is not a comprehensive solution to all memory-related threats, it represents the kind of creative, systems-level thinking required for advancing agent security and robust containment.

## A Call for Shared Commitment

Ultimately, securing agentic AI will not come from any single breakthrough but from a sustained, multistakeholder effort. These include researchers, policymakers, practitioners and industry leaders working together across disciplines. The threats are both technological and foundational. We are trying to secure systems that we do not yet fully understand. But if there's one thing the last few years have made clear, it's this: Waiting to act until the picture is complete means acting too late.

The evolution of agentic AI means our industry is developing critical safeguards concurrently with its widespread adoption. This simultaneous development isn't inherently a crisis, but a clear call for collective responsibility. Our success in this endeavor hinges on a shared industry commitment to building these foundational elements with transparency, rigorous standards and a unified vision for a trustworthy AI ecosystem.

Read the full paper: *[Achieving a Secure AI Agent Ecosystem](https://www.schmidtsciences.org/wp-content/uploads/2025/06/Achieving_a_Secure_AI_Agent_Ecosystem-3.pdf)*.

*** ** * ** ***

^1^[*Autonomous Cyber Defence Phase II*](https://cetas.turing.ac.uk/publications/autonomous-cyber-defence-autonomous-agents), Centre for Emerging Technology and Security, May 3, 2024.

* [AI](https://origin-www.paloaltonetworks.com.au/perspectives/all-articles/?cat=ai)
* [Business Transformation](https://origin-www.paloaltonetworks.com.au/perspectives/all-articles/?cat=business-transformation)
* [Staying Ahead of Evolving Threats](https://origin-www.paloaltonetworks.com.au/perspectives/all-articles/?cat=staying-ahead-of-evolving-threats)

## Related Content

![](https://origin-www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2026/03/Securing-the-Wrong-Layer-featured.jpg) BLOG

### Staying Ahead of Evolving Threats

**Cybersecurity in 2026: What we predicted, what surprised us, and what's next**

At Palo Alto Networks, we are privileged to sit at the intersection of cybe...

[Haider Pasha](https://origin-www.paloaltonetworks.com.au/perspectives/author/haider-pasha/ "Posts by Haider Pasha")
[](https://origin-www.paloaltonetworks.com.au/perspectives/cybersecurity-in-2026-what-we-predicted-what-surprised-us-and-whats-next/)  
![](https://origin-www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2026/03/Why-Cybersecurity-KPIs-Are-Changing-featured.jpg) BLOG

### AI

**Why Cybersecurity KPIs Are Changing (And What This Means for Security Leaders)**

True cyber resilience is impossible to achieve without strategic and tactic...

[Helmut Reisinger](https://origin-www.paloaltonetworks.com.au/perspectives/author/helmut-reisinger/ "Posts by Helmut Reisinger")
[](https://origin-www.paloaltonetworks.com.au/perspectives/why-cybersecurity-kpis-are-changing-and-what-this-means-for-security-leaders/)  
![](https://origin-www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2026/03/Weaponized-Intelligence-featured.jpg) BLOG

### AI

**Weaponized Intelligence**

We are building the foundation that makes defense possible....

[Nikesh Arora](https://origin-www.paloaltonetworks.com.au/perspectives/author/nikesh-arora/ "Posts by Nikesh Arora")
[](https://origin-www.paloaltonetworks.com.au/perspectives/weaponized-intelligence/)  
STAY CONNECTED

## Connect with our team today

Job Level  
Sign me up to receive news, product updates, sales outreach, event information and special offers about Palo Alto Networks and its partners.  
By submitting this form, I understand my personal data will be processed in accordance with Palo Alto Networks [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) and [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown).  
This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.
Reach out  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown)

* [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess?ts=markdown)

* [Incident Response](https://www.paloaltonetworks.com/unit42/respond?ts=markdown)

* [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform?ts=markdown)

* [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners?ts=markdown)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown)

* [Customers](https://www.paloaltonetworks.com/customers?ts=markdown)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown)

* [Communities](https://www.paloaltonetworks.com/communities?ts=markdown)

* [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance?ts=markdown)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown)

* [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown)

* [Documents](https://www.paloaltonetworks.com/legal?ts=markdown)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* AU  
  Select your language
