The Exploding Attack Surface of Agentic AI | F5 and WWT
By F5 DevCentral Community
Key Concepts
- Agentic AI: AI architectures where multiple autonomous agents interact to perform complex tasks, significantly expanding the attack surface.
- Non-Human Identities: The shift in identity governance where machine/AI identities are treated with the same security characteristics and roles as human identities.
- Shadow AI: The unauthorized use of AI tools and SaaS services by employees within an organization.
- Digital Sovereignty: The requirement for data and AI workloads to remain within specific geographic boundaries, often complicating infrastructure deployment.
- Deterministic vs. Non-Deterministic Systems: The transition from traditional, predictable software to AI models that can "hallucinate" or evolve, requiring new ethical and behavioral controls.
- Zero Trust for AI: Applying strict, continuous verification to AI agents and their interactions within an architecture.
1. The Evolution of AI Security and Architecture
The conversation highlights a critical shift in how enterprises deploy AI. Initially, AI was siloed within data science teams in isolated environments. Now, as organizations seek ROI, they are integrating AI into core business workflows. This transition has moved the industry from "single-shot" AI models to complex Agentic AI architectures, where dozens of models may interact simultaneously.
- Expanded Attack Surface: With agentic architectures, security can no longer rely on a single "moat." Security must be ubiquitous, covering the application level, identity level, and the interactions between agents.
- Identity Governance: Istvan notes that identity providers are pivoting to treat non-human identities with the same rigor as human identities. This requires granular role-based access control (RBAC) for every agent.
2. Digital Sovereignty and Infrastructure
Enterprises are facing significant challenges regarding where AI workloads can reside.
- Geographic Limitations: Customers often struggle to secure the necessary hardware (GPUs) in specific regions (e.g., Ireland vs. US East) due to supply chain constraints and sovereign data requirements.
- Hardware Strategy: While many organizations aim for large-scale GPU-based deployments, Istvan emphasizes that "one size does not fit all." Not every use case requires a GPU; some tasks (like batch processing or report summarization) can be handled by smaller, local models.
- Scaling Methodology: The recommended approach is to validate an architecture on smaller, non-GPU hardware first, then scale out to high-performance infrastructure once the workflow is proven.
3. Governance and "Shadow AI"
A major concern for CIOs is Shadow AI—employees using unauthorized SaaS AI tools.
- Visibility: Organizations cannot secure what they cannot see. Istvan suggests scanning software repositories (like GitHub) to identify libraries connecting to third-party AI systems.
- Center of Excellence (CoE): Successful organizations are establishing AI governance CoEs to set policies, evaluate risks, and provide sanctioned pathways for innovation.
- KPI-Driven Innovation: Rather than top-down mandates, successful companies encourage teams to build one or two projects with specific KPIs, allowing for "novel ideas" in areas like SOC automation or service desk operations.
4. The "Unknown Unknowns" of AI Security
Traditional security tools (firewalls, load balancers, DDoS protection) remain essential, but they are insufficient for AI.
- Ethical and Behavioral Controls: Security teams must now account for the "non-deterministic" nature of AI. Unlike traditional code, AI can drift or hallucinate.
- Operational Roles: There is a new requirement for governance roles focused on the "intentions" of AI models, ensuring they remain beneficial and within ethical guardrails.
5. Notable Quotes
- "We’ve gone from being able to put one guardrail in place and be able to protect your model, now we have to think of agentic architectures where there could be 100 different models talking to one another." — Istvan Burko
- "It’s almost like it’s zero trust of an agentic identity." — Chase (F5)
- "The rate of innovation at the moment... we saw virtual machine sprawl, we’re going to see agent sprawl." — Istvan Burko
Synthesis and Conclusion
The transition to AI-driven enterprise operations requires a fundamental shift in security and infrastructure strategy. Organizations must move away from monolithic, "one-size-fits-all" approaches toward a flexible, governance-first model. By treating AI agents as distinct identities, implementing visibility into shadow AI, and balancing the need for high-performance GPU clusters with smaller, efficient local models, enterprises can mitigate the risks of agent sprawl and non-deterministic behavior. The ultimate takeaway is that while the "rate of innovation" is accelerating at a pace similar to the early days of cloud computing, the security framework must evolve from static policy enforcement to dynamic, intent-based governance.
Chat with this Video
AI-PoweredLoad the transcript when you're ready to chat so the initial page stays lighter.
Related Videos

The After Show: The Barefoot Witness
ABC News

Middle East: Deep mistrust clouds US-Iran negotiations • FRANCE 24 English
FRANCE 24 English

The AVWAP Setup Every Swing Trader Should Master | Brian Shannon, 35+ years Trading
TraderLion

S$4,000 for a 1945 Singapore map? You’ll find it at this quaint shop in Bras Basah
CNA

Trump’s 3,711 Trades Point to Several Stock-Market Strategies
Bloomberg Television

Top five wild lefty lunacy moments in the United States
Sky News Australia

Iran's revenge mission? ‘NO ONE CAN PROTECT YOU!’: IRGC-linked plot targeting Ivanka Trump exposed
The Economic Times