P0 Security CEO Warns AI Gateways Fail Agentic AI
Shashwat Sehgal argues that AI gateways cannot secure agentic AI because they ignore identity and authorization risks during autonomous business actions.
CEO and co-founder of P0 Security Shashwat Sehgal argues that AI gateways are insufficient for securing agentic AI. He asserts that while these gateways can govern model interactions, prompts, and data movement, they fail to manage the subsequent actions agents execute across a business environment.
Sehgal highlights a critical gap in identity and authorization, specifically citing the risk of Excessive Agency. This term, defined by OWASP, describes scenarios where AI systems cause damage because they possess too much autonomy or unsafe access to tools. He warns that without proper controls, overprivileged agents can cause consequential damage to production environments.
To mitigate these risks, Sehgal maintains that security teams must implement identity-centric controls. These systems should track the original initiator of a task, the delegated authority, and the specific business purpose to ensure agents do not operate with unsafe levels of access.