Securing agentic AI is still about getting the basics right

TL;DR AI
2 min readKey summary
Sam Curry told RSAC 2026 that securing agentic AI requires reinforcing basic security tenets like identity and workload protection.
He urged use of workload identity standards such as SPIFFE and SPIRE and recommended gateways, brokers, and provisioning controls to limit agent sprawl.
Curry said zero trust segmentation, least privilege, and authentication techniques like mTLS and HTTP signing help contain agent risk.
He warned that predictable automation can be exploited by intelligent adversaries and that some defenses will need agent-assisted human oversight.



