Bonfy Blog

AI Agents Won’t Secure Agentic AI: Why the Real Control Point Is the Data Layer

Written by Gidi Cohen | 7/23/26 3:45 PM

In a recent Gartner article “AI Agents Are Insufficient to Secure Agentic AI Today,” it states that you cannot secure autonomous AI by simply adding another AI agent on top, because current “agents securing agents” approaches are still mostly monitoring and limited blocking, not true autonomous remediation.

Our position is even more pointed: the real security problem is not just the agent, but how sensitive data moves through the agent’s reasoning, tool use, and output paths in real time.

The core shift

Agentic AI changes the security model because software is no longer just processing inputs and returning outputs; it’s making decisions and taking actions across multiple systems. That breaks the old assumption that a human is always the clear decision-maker or the only entity whose intent matters. Bonfy believes that once agents can read, transform, and share data on their own, security has to move from passive observation to active, inline control.

Gartner arrives at a similar conclusion from a different angle. Its guidance emphasizes deterministic runtime controls, least privilege, identity, and staged maturity rather than trusting a probabilistic model to enforce high-stakes outcomes. Bonfy agrees with that direction, but we frame the issue around content, context, and execution rather than only identity and policy.

Why “agents securing agents” falls short

The appeal of agentic security is obvious: if agents are creating the risk, why not use agents to stop it?

The problem, as Gartner notes in its article, is that most current solutions still provide only partial enforcement, and probabilistic systems are a poor fit for deterministic security outcomes like blocking a dangerous action or preventing unauthorized access.

Bonfy’s view is that this creates a second layer of opacity, where one black box is tasked with interpreting another black box.

That approach also risks multiplying complexity. Gartner warns that adding more agents can create sprawl, latency, cost, and a wider attack surface. Bonfy echoes that concern by arguing security teams should not bolt on yet another point product but instead embed control into the workflow where the data is actually being used.

Bonfy’s POV

Our primary message in this is that security must follow the data. In our model, the meaningful control point is not just the app boundary, the endpoint, or the agent wrapper, but the moment data is read, reasoned over, transformed, or shared by an agent. That is why we describe agentic AI as a “data layer” problem as much as an identity or application problem.

Since day one, we’ve repeated that traditional tools are structurally limited here. Endpoint DLP, CASB, browser controls, and static permissions can help, but they do not reliably understand what happens inside an agent’s reasoning loop or across MCP servers, APIs, and downstream tools. In our opinion, the system needs contextual awareness that can answer: is this content safe to use, safe to share, and safe to act on right now?

How Bonfy approaches it

Bonfy’s approach is built around three layers of control. First, it constrains what data is available to the agent through contextual labeling and grounding, so the agent starts with less unnecessary exposure. Second, it adds an inline decision layer, including our own MCP-based control path, so an agent can ask whether a specific use is safe before taking action. Third, it inspects the output before it lands in email, chat, dashboards, or portals, so risky content can be blocked, redacted, or routed differently.

This matters because the biggest failures in agentic AI often happen in motion, not at rest. Our blog “What’s Missing Between Detection and Control” says the gap is not the lack of signals, but the lack of influence over the outcome while the workflow is still unfolding. That is a fundamentally different posture from after-the-fact logging or alerting.

Where Gartner and Bonfy align

There is strong overlap between the two views. Gartner wants deterministic controls first, then more autonomous capabilities later, while we wants real-time, execution-aware governance that works with the data itself. Both reject the idea that you can safely delegate high-risk enforcement to a probabilistic model alone.

The practical difference is emphasis. Gartner centers the conversation on identity, access, policy, and runtime containment. Bonfy centers the conversation on content, context, and multi-channel data movement across agents, tools, and business systems. Put together, they point to the same operational truth: secure agentic AI by combining strong controls with inline intelligence, not by chasing fully autonomous defense too early.

The business implication

For CISOs, the takeaway is not to slow down AI adoption, but to secure it in the right order. Start with inventory, shadow AI discovery, least privilege, and hard runtime limits on high-risk flows, exactly as Gartner advises. Then layer in Bonfy-style content-aware controls so security can follow sensitive data as it moves through agentic workflows.

That gives enterprises a more realistic path: one that reduces exposure without pretending today’s agent defenders are mature enough to run the whole show. In our terms, the winning strategy is to make agents first-class entities in the risk model and put the intelligence where it belongs, on the data being read, composed, and shared.

Interested in a call with a member of our team? Click here.