Agentic AI creates a clear security problem. Unlike standard AI tools, autonomous agents can access systems, retrieve data and carry out actions without constant human control.
Semnet argues that AI agents need several layers of protection because no single security control is likely to be enough. An agent may have valid credentials and approved access, yet still make a damaging decision because it has been manipulated, given bad information or allowed to act too broadly.
The first layer is AI monitoring. Security tools can track prompts, outputs, retrieved information, APIs and system activity. They can look for prompt injection, compromised data, information leakage and unusual behaviour. That provides an early warning system, but it does not remove the underlying risk.
AI security tools can miss attacks. They can also incorrectly flag legitimate activity. More importantly, an AI agent does not need to be hacked to make the wrong decision. Semnet therefore sees access control as the next layer.
Privileged access management can limit which systems an AI agent can reach, what it can do once connected and how long its permissions remain active. Higher-risk actions can also require additional approval. This changes the risk profile. If an AI agent is manipulated, its ability to cause damage can still be restricted.
Semnet points to two approaches already developing in the market. Palo Alto Networks, Idira and CyberArk represent a model based on identity, temporary permissions and zero standing privilege. F5 AI Security, Delinea and StrongDM represent an approach focused on controlling privileged activity as it happens.
Recent acquisitions show how quickly these areas are converging. Palo Alto Networks completed its acquisition of CyberArk in February 2026 and introduced Idira in May 2026. F5 completed its acquisition of CalypsoAI in September 2025. Delinea completed its acquisition of StrongDM in March 2026.
AI security, identity management and privileged access are becoming more closely connected. Semnet adds a third layer around the data itself.
An AI agent may need access to a database without needing access to every piece of readable information inside it. Separating system access from data access can reduce the amount of sensitive information exposed if another control fails.
Vaultrex is designed to control access to protected data using asymmetric and threshold-based key controls, selective decryption and a separation between database access and access to plaintext information.
GSTechnologies plc (LON:GST) is a global technology company listed on the Main Market of the London Stock Exchange under the ticker, GST. The group operates three core businesses across blockchain payments and financial services, forex, as well as cryptoasset exchange. The group has operations in the UK, Lithuania, Singapore, and Australia.






































