Agentic AI blows up the attack surface as security moves into the infrastructure layer

Agentic AI blows up the attack surface as security moves into the infrastructure layer

The important shift here is not simply “more AI means more risk.” It is that agentic AI changes the unit of security management from relatively stable applications to short-lived components, service-to-service calls and rapidly changing infrastructure state. That makes traditional control points less effective unless identity, segmentation and telemetry are tied directly to the execution environment.

For architects, moving enforcement closer to the hypervisor or infrastructure layer can reduce east-west inspection bottlenecks, but it also raises design questions the source only hints at. Security teams need consistent policy semantics across virtual machines, Kubernetes clusters and API gateways; otherwise they may gain throughput while increasing operational fragmentation. In mixed estates, the challenge is not just scale, but whether infrastructure-native controls can follow workloads across private cloud, multiple clusters and different runtime models without creating blind spots.

There is also an operational consequence to “real-time visibility” for transient agents and Model Context Protocol services: discovery alone is insufficient unless it is connected to inventory, authorization and automated quarantine workflows. If an enterprise cannot answer which agents are approved, what data they can reach and which lateral paths they create, then zero-trust language quickly becomes aspirational.

Practically, IT leaders should treat agentic AI security as a control-plane problem as much as a network problem. Near-term priorities include:

  • mapping east-west dependencies between AI services, APIs and data stores;
  • standardizing workload identity and policy enforcement across VM and container environments;
  • defining response playbooks for unauthorized or shadow AI components;
  • testing the latency impact of inspection at production traffic levels, not lab assumptions.

The main risk is not only attack-surface growth, but deploying AI faster than the infrastructure can express and enforce trust boundaries.


 

 

The enterprise attack surface is expanding rapidly as agentic AI brings a constantly shifting cloud infrastructure into play.

That pace is pushing security decisions down toward the virtualization layer, where policy can be enforced without slowing traffic. Perimeter defenses alone no longer hold, and enterprises that delay a broader lateral security program risk falling behind increasingly automated attacks, according to Umesh Mahajan (pictured), vice president and general manager of the Application Networking and Security Division at Broadcom Inc.

“This is the time where you can’t put off security any longer,” Mahajan said. “‘Oh, I got a perimeter firewall. I’m good.’ No, no, no – not good. It can be bypassed. Now the security gurus or experts are saying, ‘No, you can’t take two years, three years. You have to deploy lateral security.’”

Mahajan spoke with theCUBE’s John Furrier at VMware Explore 2026, during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. They discussed agentic AI’s effect on the enterprise attack surface, zero-trust enforcement and API protection for Kubernetes workloads. (* Disclosure below.)

Building zero trust into cloud infrastructure

Enterprises have often bought security tools piecemeal over the years, and the seams between them are where attackers operate. Broadcom’s answer is an integrated software stack in which the elements share context, delivered through its vDefend and Avi Load Balancer product lines, Mahajan explained.

“Our customers have bought multiple security products. They can’t put it together,” he said. “It’s like buying Swiss cheese. Yeah, you have pieces of security, but you have plenty of holes which people can drive through.”

Scale is the other constraint, Mahajan noted. AI workloads generate heavy east-west traffic and punish any inspection step that adds delay, which is why the company has pushed enforcement into the hypervisor rather than a separate appliance tier, part of a wider update to VMware’s security portfolio for AI-era threats. That includes firewalling and intrusion detection and prevention, with the company aiming to handle security processing at high throughput while keeping latency low.

“We are doing 75 terabits per vCenter cluster for firewalling. We are doing 17 terabits for IDS IPS, and the other aspect is also latency,” Mahajan said. “Because in AI workloads, latency matters, so our security is done at the hypervisor level.”

In other words, Broadcom is pushing security enforcement into the hypervisor to inspect traffic at scale without introducing the latency of sending it through separate security appliances. But protecting those workloads also requires visibility into what is running, Mahajan noted. Agents and Model Context Protocol services are transient, so administrators need a real-time picture of what is authorized and what is shadow IT before they can quarantine anything, and that visibility work is now landing alongside Original Postrivate-cloud-vmware-explore-thecube-vmwareexplore/" shape="rect">private cloud modernization programs. Bolting protection on later, once the cloud infrastructure is already carrying production AI traffic, is the failure mode executives are trying to avoid.

“It has to be at the infrastructure level; it has to be at scale,” he said. “Otherwise, when are you going to do it? Two years from now, by that time you’ll be compromised.”

Here’s the complete video interview, part of SiliconANGLE’s and theCUBE’s coverage of VMware Explore 2026:

[link VIDEO]

(* Disclosure: TheCUBE is a paid media partner for the VMware Explore 2026 event. Neither Broadcom, the sponsor of theCUBE’s event coverage, nor other sponsors have editorial control over content on theCUBE or SiliconANGLE.)

 

Agentic AI blows up the attack surface as security moves into the infrastructure layer

Enjoyed this article? Sign up for our newsletter to receive regular insights and stay connected.

Leave a Reply