Core Memo

Memorandum

To
Anyone who needs the day in one page
Date
August 28, 2026

Memorandum

From
Delaney Sawyer via VentureBeat
Date
Filed
Business·5 min to read
Re

Nutanix outlines three-layer defense-in-depth model for agentic AI security

ReNutanix outlines three-layer defense-in-depth model for agentic AI security

As enterprises move autonomous AI agents into production, Nutanix argues that application-level controls are insufficient and proposes a three-layer defense-in-depth architecture covering infrastructure, network, and control plane to manage the distinct risks of agentic systems.

Chinese hackers target NASA and key US agencies, DOJ alleges

Enterprises moving autonomous AI agents from experimentation into production face a new category of risk that traditional application-level security controls were never designed to contain, according to Nutanix. The company argues that treating agentic AI security as a single problem produces incomplete architectures, and instead advocates for a defense-in-depth model spanning three distinct layers: infrastructure, network, and control plane.

Oscar Wahlberg, senior director of product management at Nutanix, said the core challenge is that guardrails designed to catch malicious prompts will not stop an agent from hallucinating and taking unintended actions. He cited examples such as an agent accidentally deleting databases or leaking sensitive data using credentials it was granted for a different purpose. Once an agentic system receives execution privileges across the data center, the security posture must scale across infrastructure, storage, compute, networking, and a governing control plane, with each layer addressing a distinct category of risk rather than duplicating the same controls.

The infrastructure layer establishes a root of trust that answers who is operating in the environment. Before an organization can trust what an agent does, it must trust the integrity of the environment where the agent runs. This layer relies on technologies such as platform attestation, confidential computing, and secure boot, alongside controls that prevent unauthorized access within and beyond a server. For regulated industries like financial services, this layer isolates AI production workloads so neither the agent nor the environment can operate outside its assigned scope, mitigating risks including model and runtime tampering, supply chain compromise, and unauthorized access to sensitive workloads.

The network layer governs how AI agents communicate. When agents begin interacting with other agents, APIs, applications, and enterprise systems, they generate a level of concurrency and dynamic communication that traditional static network configurations were not designed to handle. An agent configured to call APIs, query data sources, and spin up additional agents without constraint creates a sprawling web of east-west traffic that can mask lateral movement or data exfiltration. Wahlberg said AI agents should be treated as a new class of network identity, with agents only able to talk to other agents or data sources where explicitly allowed, moving away from rigid static rules toward dynamic policy enforcement.

Nutanix's solution includes Agent Gateway, part of its Agentic AI offering, which provides a unified governed layer for cost control and governance. The gateway is coupled with zero trust segmentation and integrates with networking vendors, including its integration into the Cisco Secure AI Factory. The network layer governs lateral movement, data exfiltration, and gates the agent's network interactions, with access blocked by default and scalable interaction monitoring. Nutanix's software integration with Cisco UCS servers and Cisco AI PODs delivers the turnkey physical infrastructure the AI factory runs on.

The control plane layer serves as the central point for managing agent permissions, tool access, resource consumption, and runtime visibility. Wahlberg emphasized the importance of having a single place where policies can be enforced consistently rather than reinvented for every agent. Agent Gateway acts as a universal endpoint for different models and tools, allowing IT teams to configure agents to talk to a single control point. This layer enables administrators to observe, audit, and control access to models and MCP tools, protecting data and gating privileged access. It is designed to mitigate risks such as privilege misuse, runaway agents, unauthorized tool usage, data leakage, and excessive model consumption that can lead to increased token usage when agents get stuck in runtime loops.

Nutanix argues that no single security control or vendor can provide this protection on its own. Defense-in-depth depends on the layers working together, with zero trust segmentation as a guiding principle. By dividing responsibilities across the stack, organizations can create a secure framework that improves their overall posture, turning the principle of defense-in-depth into a practical security framework for autonomous agents.

Delaney Sawyer

Author

Society Reporter

Delaney Sawyer covers public affairs, politics, business, culture and daily news for Core Memo. The role focuses on verification, context, and clear explanations for readers.

Encl.More under Business