The Board Room
RSAC 2026 declared non-human identity the next platform war — Google, Cisco
Your AI agent deployment and your security architecture are now the same problem, and both are behind.
Agent Security Infrastructure Doesn't Exist Yet
RSAC 2026 crystallized a new category: non-human identity governance. MCP lacks versioning or content hashing — tools can be silently rewritten between user consent and agent execution. An autonomous bot compromised 4 major projects' CI/CD simultaneously. Exploitation windows collapsed to sub-24 hours. AI is now generating novel exploits, not just accelerating known ones.
Enterprise SaaS Splits on AI Agent Access
Slack and Workday are restricting external AI agent access; GitHub and Figma embrace openness. Workday plans to charge for agent access — a new SaaS pricing paradigm. But Anthropic's computer-use Claude bypasses these restrictions entirely at the screen level, making MCP-level gatekeeping potentially futile within 18 months.
OpenAI's Distribution Thesis Gets a Death Certificate
Microsoft's Copilot has 15M paying seats on 450M — 3.3% penetration — proving distribution moats don't transfer to AI. OpenAI's response: hire Meta's ad chief (Dave Dugan), launch ads via Criteo ($50-100K packages), and consolidate into a superapp. ChatGPT's 900M WAU converts at only ~5% paid, forcing the ad pivot. The consumer AI battle is over: ChatGPT at 440M DAU vs. Copilot at 6M.
AI Coding's 25% Velocity Tax and Estimation Crisis
75% of developers say AI reduces toil, but teams spend 25% of their week fixing AI output — a net wash most leaders haven't measured. Node.js core contributors petitioned to ban LLM PRs. Addy Osmani coined 'comprehension debt' for the growing gap between shipped code and understood code. Planning horizons compressing from 3-week to 1-week windows.
AI Expands from Bits to Atoms
Liquid AI's STAR platform runs 1.2B parameters in 719MB on a phone at 70 tok/s — 63% less memory than Llama. Arena Physica claims 18,000x EM simulation speedups for defense electronics. Bezos raised $100B to buy and automate manufacturing companies. AI value creation is migrating from software productivity to physical-world infrastructure.
Your AI Agent Infrastructure Has No Security Foundation — RSAC 2026 Just Made That Official
The Category Just Crystallized
RSAC 2026 wasn't a trade show this week — it was a coordinated industry admission that agentic AI has outrun its governance infrastructure. Google, Cisco, Palo Alto Networks, and the Cloud Security Alliance simultaneously launched AI agent security products and frameworks. Cisco's Duo Agentic Identity treats AI agents as full identities with policy enforcement. Palo Alto's Prisma AIRS 3.0 unifies agent security across identity, posture, and runtime. The CSA launched an entire nonprofit — CSAI — for the 'agentic control plane.' When four players converge on the same problem in the same week, you're watching a market category crystallize.
Whoever owns your NHI governance layer will have a gravity pull on your broader security architecture. This is a platform decision masquerading as a security tool purchase.
The Protocol Layer Is Broken by Design
The most alarming finding: MCP — Anthropic's Model Context Protocol, increasingly the standard for connecting AI agents to tools — has no versioning, content hashing, or approval-time snapshots. A malicious MCP server can silently rewrite a tool's description and behavior between the moment a user approves it and the moment the agent executes it. Neither Datadog nor LangSmith can detect this because they record what was called, not whether it matched what was authorized. This creates direct compliance gaps under HIPAA, SOC 2, and EU AI Act Article 12.
Compounding this, XM Cyber mapped eight validated attack vectors in AWS Bedrock where a single over-privileged identity can hijack agents, strip guardrails, poison prompts, and exfiltrate data — all without triggering a redeployment. The cloud AI security conversation needs to shift urgently from model security to permissions and integration security.
Autonomous AI Bots Are Already Attacking Your Supply Chain
Step Security revealed that an AI bot ('hackerbot-claw') systematically compromised Trivy's CI/CD pipeline, stole Personal Access Tokens, and pushed malicious code to GitHub Actions, DockerHub images, and VS Code extensions — hitting Microsoft, DataDog, and CNCF projects simultaneously. Aqua Security detected the compromise and rotated secrets, but acknowledged the process 'wasn't atomic and attackers may have been privy to refreshed tokens.' The attack recurred on March 19 and March 22.
Separately, a former deputy national security advisor confirmed that AI crossed from accelerating known attacks to generating novel exploits in 2026 — new tactics and techniques that don't appear in any historical threat database. Sysdig's Langflow research showed a critical RCE was exploited within 25 hours of disclosure, with attackers building working exploits from the advisory description alone.
The Social Engineering Threat Model Inverted
Mandiant M-Trends data reveals a complete inversion: vishing now accounts for 11% of investigated incidents while email phishing collapsed from 22% (2022) to 6%. Organizations still over-indexed on email security are deploying capital against a shrinking threat. Meanwhile, a systemic Microsoft OAuth device authentication exploit is granting attackers 90-day persistent access that bypasses MFA entirely, with hundreds of businesses already compromised.
The connecting thread: your AI agent strategy and your security strategy must be unified under single executive governance this quarter. The NHI platform choice is being made now, and it will have the same gravity as your cloud platform choice had a decade ago.
The AI agent platform war is live — Anthropic ships desktop control in four weeks from acquisition, enterprise SaaS is splitting into open and closed camps on agent access, and OpenAI is pivoting to ads after Microsoft's 3.3% Copilot penetration proved distribution moats worthless in AI — but RSAC 2026 simultaneously revealed the security infrastructure doesn't exist: MCP has zero cryptographic integrity, autonomous bots are compromising enterprise CI/CD pipelines, and exploitation windows have collapsed to under 24 hours. The organizations that unify their agent strategy and security strategy under single governance this quarter will build the foundation; everyone else is building on sand.