An autonomous AI agent does not need to defeat an authentication system to cause serious damage. It can authenticate successfully, use a credential the enterprise deliberately granted it, and then make an unreliable decision that deletes a database or exposes sensitive data. For technology leaders moving agents into production, that shifts the security question from whether the model can reject malicious input to how far a legitimately authorized agent can act when its judgment fails.
The dangerous agent may already have legitimate credentials
Model guardrails address only part of that production problem because autonomous agents can turn model decisions into actions. Oscar Wahlberg, senior director of product management at Nutanix, gives a concrete failure case: “The guardrails to catch a malicious prompt won’t stop an agent from hallucinating and doing something it never should have done, like accidentally deleting databases or leaking sensitive data with a credential it was granted but then uses for something entirely different.” Nutanix sells infrastructure and governance technology for these deployments, so it benefits commercially when enterprises adopt the architecture Wahlberg describes.
The valid credential in Wahlberg’s example shifts the problem from authentication to authorization during execution. “That’s the central problem as enterprises move autonomous agents out of experimentation and into production,” Wahlberg says. A production design consequently has to contain activity across infrastructure, storage, compute and networking while a governing control plane determines what agents can access and consume.
Those parts of the stack answer different questions because each enforces a different kind of boundary. Infrastructure establishes whether an agent and its execution environment are trustworthy, networking restricts which systems and other agents it may communicate with, and the control plane governs permissions, tools, resources and behavior during execution. Containment depends on all three because a valid identity says little about whether the next action is appropriate.
Defense in depth gives each layer a different job
Once valid credentials are part of the threat model, defense in depth means placing each security responsibility where the architecture can enforce it. Hardware-rooted mechanisms can establish execution integrity, network controls can govern communication paths, and centralized runtime controls can govern actions and consumption. Repeating one generic security model at every level would leave some decisions without an effective enforcement point.
The value of that separation becomes clear when a responsibility is placed in the wrong layer. Application software cannot provide hardware-level assurance about the environment in which it executes, while static legacy network rules struggle with agents whose relationships change as they act. “By failing to assign specific responsibilities to the appropriate layers, enterprises end up with blind spots in governance,” Wahlberg says.
Those blind spots can also become operational constraints because security policy affects what an agent can accomplish. A rigid architecture may restrict an agent so heavily that it cannot carry out its intended work, while permissive rules can leave paths for unsafe actions. Stretching one approach across the full AI stack can create governance blind spots, performance penalties and operational friction.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.
Infrastructure establishes trust in the agent and its execution environment
The first specialized responsibility sits below the agent itself: establishing a root of trust, a basis for verifying the identity and integrity of the environment where execution occurs. Before higher-level policy can safely permit an operation, the system needs confidence about who is operating and whether the environment has been altered. When an agent requests an operation, verification includes checking that the request came from the legitimate agent rather than an impersonator.
That root of trust depends on mechanisms addressing different parts of execution integrity. Hardware-rooted attestation provides evidence about the platform’s state, confidential computing protects workloads and data during processing, and secure boot verifies the integrity of software loaded as a system starts. Controls within and beyond individual servers then protect against unauthorized access, together addressing risks such as tampered models or runtimes, compromised software supply chains and unauthorized access to sensitive AI workloads.
That separation becomes especially important when production AI requires strict isolation. In financial services, for example, an organization may need to isolate AI production workloads so both the agent and its execution environment remain within their assigned scope. An application-level permission cannot establish the trustworthiness of the underlying runtime, so infrastructure mechanisms supply lower-level assurance before higher-level controls evaluate what the agent may do.
Intel’s role in the Nutanix, Cisco and Intel implementation sits primarily at this infrastructure layer. Intel provides compute for agentic workloads along with hardware-rooted trust and confidential computing, while its accelerators are intended to reduce costs, giving Intel a commercial interest in adoption of that compute architecture. Intel Xeon 6 processors include built-in AMX, an acceleration capability used here to speed AI inference without requiring exclusive dependence on expensive GPUs.
Compute performance and execution trust therefore meet at the same layer while addressing separate production requirements. The processor has to run inference efficiently, while the platform has to establish enough integrity for higher-level controls to rely on the identity and execution context they receive. Once that foundation is trusted, the next boundary concerns where the agent can communicate.
Networking must treat the agent as an identity
A trusted agent creates a new containment problem as soon as it starts communicating. Autonomous agents can communicate concurrently with other agents, APIs, applications and enterprise systems; an agent may call APIs, query data and create additional agents as it works. Those actions produce changing east-west traffic, meaning communication among systems inside an environment, where lateral movement and data exfiltration can resemble legitimate agent activity.
Because that traffic follows the agent’s work, the network needs an identity and policy model built around the agent itself. “We should treat AI agents as a new class of network identity, and make sure that an agent can only talk to other agents or data sources where it’s explicitly allowed to do so,” Wahlberg says. With access blocked by default, an enterprise can authorize the specific relationships an agent needs and monitor those interactions at scale.
Agent identity also changes how those relationships must be enforced as execution proceeds. “That means moving away from rigid static rules toward dynamic policy enforcement,” Wahlberg says. An autonomous environment can create new communication relationships during execution, so policy has to keep pace while continuing to gate access according to identity and authorization.
Static legacy configurations create two failure modes under those conditions because they cannot easily adapt to changing workflows. Tight rules can overconstrain agent activity until the system cannot operate as designed, while broad exceptions can open communication paths that allow lateral movement or data leakage. Zero trust segmentation addresses that tension by requiring explicit authorization for individual relationships instead of granting broad network reach.
For the Nutanix implementation, part of that responsibility falls to Flow, the company’s microsegmentation capability, together with agents grounded in zero trust segmentation and integrations with networking vendors. Microsegmentation divides workloads into narrowly controlled communication domains so administrators can restrict interactions inside an environment. Nutanix also integrates with Cisco Secure AI Factory, connecting its commercially offered software to Cisco’s networking and infrastructure stack.
Cisco supplies the secure networking role in the three-company architecture by governing communication between agents and enterprise tools, and Cisco likewise has a commercial stake in adoption of this joint design. This layer decides whether one identity may reach another endpoint and under what policy, even when both sides run in trusted infrastructure. Once the connection is permitted, however, the system still needs to decide what the agent may do through it.
The control plane governs what a trusted, connected agent can do
That next decision belongs to the control plane, which centralizes agent permissions, tool access, resource consumption and runtime visibility. An agent can be legitimate, execute in an attested environment and communicate across an explicitly authorized path while still invoking the wrong tool or consuming excessive resources. Central policy becomes more important as deployments multiply because otherwise teams must recreate those controls separately for each agent.
Nutanix presents Agent Gateway, part of Nutanix Agentic AI, as its implementation of that control-plane role. The gateway provides a common governed point across models and tools and manages interactions among agents, models, data sources and enterprise applications. “Agent Gateway acts as a universal endpoint for different models and tools, so an IT team can configure their agents to talk to this single control point,” Wahlberg says.
That common endpoint gives administrators one place to observe and enforce runtime decisions. They can audit activity, control model access, manage access to Model Context Protocol (MCP) tools, protect data and gate privileged operations. MCP tools are capabilities exposed through the Model Context Protocol for models or agents to invoke, so controlling them matters because a tool call can turn an AI decision into an operation against enterprise resources.
The same runtime view connects security policy with cost management because undesirable behavior can affect both at once. The system can address privilege misuse, unauthorized tools, data leakage and runaway behavior while tracking excessive model consumption. If an agent becomes stuck in a loop, repeated model calls can drive token consumption upward, making the loop both an operational security concern and a spending problem.
Those overlapping concerns expose behavior that narrower controls see only in part. An enterprise might protect model output while sensitive information still passes improperly between agents because communication occurs outside that output boundary. A network policy can likewise authorize legitimate model connections while an agent repeatedly makes the same permitted call, so runtime visibility is needed to identify the resulting token consumption.
For Wahlberg, that requirement makes governance an active runtime function that continues throughout execution. Nutanix positions its software platform and central control plane as a way to reduce architectural silos while enforcing permissions, providing visibility and governing costs, a framing aligned with its commercial interest in selling those capabilities. Consistent runtime policy matters particularly when agents can change what they call and consume during a task.
The control plane’s work continues after initial deployment into “Day 2” operations, which Wahlberg says require continuous observability and strict token governance as agents operate in production. Those controls make ongoing behavior and resource consumption part of the same management problem as deployment. The boundary consequently covers the decisions an agent makes throughout post-deployment operation.
That continuing responsibility also links security to the practical choices that determine whether an AI system works in production. “Apart from model and tool selection, governing the agent deployments and their access to models and business tools in a tightly integrated full stack platform will be important for the success of AI projects,” Wahlberg says. Deployment governance therefore determines which business capabilities an autonomous system can exercise after its model has produced a decision.
Each layer provides a separate containment boundary
Centralized runtime decisions still depend on the boundaries established below them. A control plane cannot establish hardware-rooted integrity for an execution environment or independently provide network isolation against lateral movement, while trusted hardware and segmented networks do not decide which MCP tool an agent may invoke. They also do not expose the control-plane behavior of a token-consuming runtime loop.
Those separate responsibilities provide fallback containment when an earlier protection fails. If a threat passes model-level filtering, hardware-rooted mechanisms can still protect execution integrity, network isolation can restrict reachable destinations, and agent-layer access controls can restrict available operations. Defense in depth works because failure in one category leaves enforcement mechanisms in the other categories available.
The paired failure cases make the separation concrete. Protecting model output can coexist with agent-to-agent data leakage because output controls and communication controls observe different behavior. Securing network access can likewise coexist with excessive token consumption because the network may permit legitimate connections while the agent repeatedly executes an authorized model call.
Nutanix, Cisco and Intel present their partnership as an implementation of these complementary responsibilities in an enterprise-grade AI Cloud, and all three companies have a commercial interest in adoption of the resulting stack. Intel supplies compute plus hardware-rooted trust and confidential computing; Cisco supplies a secure fabric for communications; and Nutanix supplies the software platform and central control plane for permissions, visibility and cost governance. Their product roles map to separate enforcement responsibilities within the layered design.
The integration continues into the underlying AI-factory infrastructure, connecting those responsibilities around the same workloads. Nutanix integrates into Cisco Secure AI Factory, while Nutanix software runs with Cisco UCS servers and Cisco AI PODs to provide the compute, storage and networking infrastructure on which the AI factory operates. The implementation shows how the infrastructure, network and runtime-control layers can retain distinct enforcement mechanisms in a cross-vendor stack.
Scaling agents makes runtime governance an architecture decision
Once those controls have to cover many deployments, per-agent management becomes a scaling problem. Wahlberg describes organizations progressing from a handful of AI use cases to “thousands of agents” operating autonomously to drive the business. His scenario makes the architectural consequence clear: constructing identity, access and consumption policy separately for every agent becomes increasingly difficult as the population grows.
At that scale, technology leaders need centralized governance capable of managing agent identities, tool permissions and token budgets in real time. Consistency becomes the key architectural property because each added agent needs to enter the same runtime policy framework. The control plane consequently becomes part of the scaling architecture, extending the governance model already used during deployment into ongoing autonomous operation.
That centralized model also has to work across the different technology stacks common in enterprises. “You can’t build an AI system without getting into a lot of complex decisions,” Wahlberg says. Those decisions cross models, tools, compute, networks and existing business applications, so the governance layer has to coordinate policy across the environments involved in a task.
The same complexity leads Wahlberg to a multi-vendor requirement for that layer: “And you need a control plane that talks across multiple vendors and infrastructures to help you solve for those defense-in-depth strategies.” Nutanix benefits commercially from a requirement that favors a cross-environment control plane, so technology leaders should read that recommendation in the context of the company’s role in the implementation. The architectural requirement itself is concrete: policy has to follow agents across the environments where they execute while infrastructure and networking continue to enforce their own boundaries.
Commercial roles shape the implementation case
The Nutanix, Cisco and Intel design is a vendor-backed implementation of the layered architecture, with each participant supplying technology for its assigned responsibility. Wahlberg’s interpretation comes from his role at Nutanix, whose Agent Gateway, Flow and broader software platform occupy central positions in the design he describes. Cisco and Intel also benefit when enterprises adopt the networking, server and compute components assigned to them.
Those incentives matter when evaluating the claims because architectural reasoning and product positioning appear together in the same implementation. Wahlberg’s database-deletion example identifies the underlying risk: an agent can hold a valid credential and still take a damaging action. The vendor stack then applies separate enforcement boundaries to execution trust, communication and runtime permissions so a legitimately authenticated agent does not receive unlimited freedom merely because authentication succeeded.
In conclusion
For technology leaders, the production risk from autonomous agents is not limited to unauthorized access. An agent can authenticate correctly, operate inside trusted infrastructure and still make a damaging decision with permissions the enterprise deliberately granted. That makes the scope of legitimate agent activity an architecture and governance issue, not simply an authentication problem.
As deployments grow, enterprises will need distinct controls for execution trust, network communication and runtime behavior. Central governance can coordinate permissions, tool access, observability and resource consumption, but it does not replace infrastructure assurance or network containment. Each layer has to provide an independent boundary when another control fails.
The executive decision is therefore less about selecting a single security product than defining where trust begins and where authority ends. Before scaling autonomous agents, organizations should be able to establish an agent’s identity and execution integrity, restrict what it can reach, govern what it can do after connecting and observe those decisions continuously. Without those boundaries, adding more agents also expands the consequences of a valid credential used in the wrong way.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.


