Why AI Security Has to Live at the Decision Point

Portrait of Dina Durutlic
Dina Durutlic
Cover Image

Key takeaways

  • Zenity is expanding its AI Security and Governance Platform with three integrated pillars, Surface, Enforce, and Protect, built to work as one continuous loop.
  • The threat model for AI agents isn’t just a malicious prompt from an external attacker, or oversharing from an internal employee. It’s an agent’s own autonomy reasoning its way into a decision nobody would have signed off on.
  • Security has to operate at the decision point, the exact moment where an agent’s context and intent converge, just before it acts, rather than only at certain layers (input, output, model, data, access, etc.)
  • With this expansion, exposure findings ship with a fix, enforcement holds consistently across every environment, and every investigation feeds directly back into policy so the platform gets sharper with every cycle.

For the past couple of years, most of the industry’s attention has gone toward agents that respond to a single prompt. They ask a question, get an answer, and move on. Enterprises are now deploying long-horizon agents; autonomous systems that execute extended, multi-step tasks across hours or days, without a human checking in on every step. These agents plan, reason, and improvise their way toward a goal, and that changes what security has to protect against.

This is the guiding principle that continues to fuel Zenity’s investment and development. The Zenity AI Security and Governance Platform is built to meet agents at the exact point they decide to act.

The Shift to Long-Horizon Agents

Most AI security conversations still assume a request-and-respond model. An agent gets an instruction, produces an output, and a human reviews it. Long-horizon agents break that assumption. They hold state across many steps, call tools, touch data, and take actions on their own timeline. A single task might involve dozens of decisions before a person ever sees the result.

That’s an impactful shift for security and risk teams. Controls built for point-in-time inspection, a single prompt in, a single response out, weren’t designed for a system that continues to work an hour, or a day, later. The attack surface isn’t just what an agent was told to do. It’s everything the agent decides to do along the way.

Security Belongs at the Decision Point

It’s easy to frame AI risk as a story about bad actors. An attacker creates a malicious prompt, or an employee gives an agent an instruction it shouldn’t follow. But knowing what we know today, it would be naive to still believe that those are the only threat models. Those scenarios are still relevant, but they miss a big source of exposure.

An agent can cause real damage with no malicious input at all. It has a goal, reasons through a path to get there, improvises when the initial route is blocked, and takes an action that creates harm, not because it was told to, but because the action looked reasonable given its context in that moment. No attacker, no violation, and maybe even no alert. Just an autonomous system doing what autonomous systems do, finding a way.

This is a different category of risk; this is the risk we’ve been talking about here at Zenity for a while. While other elements of AI are important, the most critical risk comes from how the organizations leverage AI, and what those agents decide to do. If the risk comes from the agent’s own reasoning, then the place to intervene isn’t the various layers to the agent (think input, output, data, access, etc.). It’s at the decision point, the exact moment where an agent’s context and its intent meet, just before it acts.

Expanding the Zenity Platform

That’s the claim driving the latest expansion of the Zenity AI Security and Governance Platform. We’ve built three platform pillars, Surface, Enforce, and Protect, to work as a single system, each one carrying forward what the last learned about an agent, so control follows all the way from configuration to the moment it acts.

  • Surface finds what’s running, what it can reach, and what’s exploitable before anything gets enforced or investigated.
    • AI Observability: Continuously discovers agents across the modern environment, and maps the data and systems each touches.
    • AI Security Posture Management (AISPM): Checks agent configuration and permissions before runtime, catching vulnerabilities before the agent acts.
    • AI Exposure Management: Validates which attack paths are reachable, accurately prioritizes risk, and provides suggested remediation steps that can be immediately applied.
  • Enforce steers agents in real time, holding the line with runtime boundaries.
    • Runtime Boundaries: Reviews each agent action in real time and decides in the moment whether it proceeds, gets blocked, or triggers a shutdown, applying one consistent standard everywhere the agent runs.
    • Agentic Identity: Ties an agent's identity, pulled from providers like Okta and Microsoft Entra, to what it's actually doing at runtime, so having the right permissions doesn't become a blind spot.
    • MCP Security: Extends the same enforcement standard to every tool an agent connects to over MCP.
  • Protect watches agents as they operate and maps against frameworks like OWASP and MITRE ATLAS, building the evidence trail for anything that gets through.
  • Guardian Agents span the platform, learning from every action, decision, and investigation to move at the speed of AI, and support the continuous loop.

Together, the three pillars form a feedback loop instead of a chain. Surface tells Enforce where real exposure lives, Enforce holds the line at runtime, and Protect investigates what gets through, handing the learnings back to Surface and Enforce. Each cycle leaves the next decision better informed than the last.

What This Means for Security Teams

For teams running Zenity, the loop isn’t just a diagram. Work that used to sit in separate tools, and often separate teams, now happens inside one continuous cycle, with each stage picking up where the last left off:

  • Inventory becomes actionable. You get more than a list of agents. Surface shows what each one can reach, what data it touches, and where the risk and exposure are.
  • Exposure comes with a fix, not just a finding. AI Exposure Management doesn’t stop at a risk score. It ships a fix ready to apply directly in Runtime Boundaries, so remediation doesn’t wait on a separate ticket.
  • Enforcement holds regardless of platform. One boundary, defined once, applies consistently whether the agent runs in a SaaS tool, a homegrown build, or on an endpoint.
  • Every incident sharpens the next decision. When teams investigate an event, the finding doesn’t dead-end in a report. It feeds directly back into the policy and boundaries that Surface and Enforce apply going forward.

Bringing Security to the Decision Point

Agents are only going to get more capable and more autonomous, and the risk that comes from their own decision-making will grow right alongside them. That’s exactly why Surface, Enforce, and Protect exist as one platform. Giving security and risk teams control at one point that matters the most, the moment an agent decides.

This expansion is live today across the Zenity AI Security and Governance Platform. If you’re running agents that plan, reason, and act without a human in the loop at every step. The decision point is where your security program needs to be too.

Get a demo to see the the Zenity platform working as one loop.

All Articles

Secure Your Agents

We’d love to chat with you about how your team can secure and govern AI Agents everywhere.

Get a Demo