AI Security Is an Engineering Problem: Solving It at Every Layer of the Agent Stack
Synopsis
This article argues that AI security should be treated as an engineering problem requiring defined security requirements, enforceable controls, named owners, and evidence that protections work, and proposes that security depends on the full agent stack (models, harnesses, runtime environments) working together, introducing NVIDIA OpenShell as an open source secure runtime with integrations across Open Secure AI Alliance partners, along with defensive tool examples such as CrowdStrike SafeMind, Palo Alto Networks Prisma AIRS, Capital One VulnHunter, and ReversingLabs Spectra Assure, while emphasizing open sharing of failure evidence and verification methods to shift advantage toward defenders.
Interpretation
Frames AI security as an engineering problem requiring defined security requirements, enforceable controls, named owners, and evidence that protections work. Maps enduring security responsibilities (establish identity, control access, limit exposure, verify protections) onto the new operating conditions of AI agents, stressing that security boundaries must hold even when an agent makes the wrong decision. This is an opinion piece illustrated with a customer-record scenario showing that network policy should block unauthorized data transfer and protected logs should capture tool calls and authorization decisions; no experimental data or quantitative results are provided.
Security depends on the full agent stack, with models, harnesses, and runtime environments each carrying security responsibilities that require controls across layers. Treats AI agents as an extension of existing application dependencies (code, data, identities, services, infrastructure) and argues the runtime environment must install limits on files, network destinations, and processes independently of the agent's reasoning. Primarily scenario reasoning and architectural description, without measured cross-layer control effectiveness.
Introduces NVIDIA OpenShell as an open source secure runtime with ecosystem integrations and lists defensive tool examples. OpenShell enforces policies outside the agent's reach and provides sandboxed execution; Cisco DefenseClaw adds a governance layer, JFrog integrates with OpenShell to scan and verify agent skills and enforce skill access policies; CrowdStrike SafeMind tests and strengthens defenses through repeated attack simulations, Palo Alto Networks Prisma AIRS provides continuous red teaming, Capital One VulnHunter addresses AI-powered code security, and ReversingLabs Spectra Assure analyzes software packages for malware and tampering. Product and project descriptions without independent evaluation or comparative data.
Engineering teams need evidence of security, including pre-deployment testing, a named owner's decision, failure reproduction and fix verification, and converting findings into repeatable tests. Specifies testing scope as blocking attempts to obtain credentials beyond an agent's scope, send sensitive data to unauthorized destinations, change permissions, or interfere with monitoring, and requires repeating tests after material changes to models, tools, or workflows. Primarily process recommendations and example tools, without test pass rates or fix effectiveness data.
Perspective
This article is aimed at engineering and security teams deploying AI agents, and applies to organizations seeking to operationalize established security principles across the agent stack; its recommendations center on engineering processes, runtime controls, and testing evidence, making it a useful reference framework for defining security requirements and selecting tools.
The article does not provide quantitative test results, independent evaluations, or failure case data, so readers may wonder about evidence of these controls' effectiveness in real deployments; additionally, details of the mentioned tools and alliance integrations are limited, and their actual coverage and maturity warrant further exploration.
