There are two narratives competing for attention, and budget, today. The first says AI attackers are coming and nothing will stop them. The second says the answer is simple: buy an AI agent, point it at your environment, and let it watch and act on your behalf. Both stories are loud. Both are incomplete. And both skip past the truth security teams already know: faster decisions are not better decisions unless they are grounded in complete context and governed by clear guardrails.
Frontier AI and AI agents have expanded the attack surface and accelerated compromise. That part is new and real. However, the disciplines that best address this new reality are not new: visibility before action, verification before trust, context before control, and containment before compromise.
The network remains an immutable source of truth. It’s the volume, speed, and scale that has changed.
A Bigger Attack Surface, Moving Faster
The attack surface has been expanding faster than most teams can track for years. Enterprise networks now combine traditional IT with IoT sensors, operational technology that touches the physical world, and medical devices that cannot tolerate disruption. Attackers deliberately cross between these domains, using one to reach another, and the unmanaged assets that rarely show up in endpoint tools are exactly where they look first.
You can’t secure what you can’t see, and attackers know precisely where you aren’t looking.
Frontier AI adds pressure on top of that reality. AI agents are now appearing on both sides of the fight. In September 2026, Anthropic reported disrupting malicious Claude activity that included AI-supported reconnaissance, phishing infrastructure, credential harvesting, lateral movement, and malware changes to evade detection. The point is not that every attack is now fully autonomous. It is that attackers are already using agentic workflows to compress the time between discovery, adaptation, and action.
So, volume, speed, and scale have new meanings. But notice what hasn’t changed. A faster, more automated attack still needs a device to land on, a path to move through, and a target worth reaching.
Which is why network security fundamentals hold, and why they matter more now, not less.
Not All Truths Are Created Equal
Here’s one way to think about an AI agent, on either side of the fight. The model at its core is a brain in a jar. It’s an extraordinary reasoner, but on its own it has no memory, no eyes, and no hands. It only sees and touches your environment through the context and tools it’s given. A brilliant brain reasoning over a blank or incomplete picture doesn’t produce brilliant decisions. It produces confident, but incomplete and inaccurate, ones.
This is the part the market conversation tends to skip: every tool, every AI agent, and every autonomous decision is only as reliable as the context it can see. Partial visibility creates partial protection. If entire classes of assets are missing from the system’s view, the AI agent may still act quickly and confidently, but it is acting on an incomplete picture. That is not governed autonomy. It is fast, efficient guessing with real-world consequences.
Consider a real example. A U.S. energy company asked a simple question: how big is my attack surface? Its agent-based tools, Windows Defender and CrowdStrike, saw 50,000 assets. Two years of stitching together 32 separate security and IT tools brought that picture to roughly 198,500. Deployed without agents in a matter of weeks, Forescout found 235,671 total assets. That is a 15% visibility gap over every other tool combined — and an 80% gap over the agent-based view alone.
Now picture an AI agent making containment decisions from that agent-based or combined inventory. It would be reasoning over roughly one asset in five, blind to the rest, and acting confidently on the fraction it happened to see.
The gap is not a reporting issue. It is a cybersecurity risk, and in the agentic era, it becomes agentic risk.
This is why universal visibility is no longer a nice-to-have. It is a foundational requirement for agentic security. Security systems can only make trustworthy decisions when they have complete context across the environment.
That requirement has a name, Universal Zero Trust Network Access. Unlike traditional Zero Turst approaches focused on remote users and managed endpoints, UZTNA provides identification and classification of every asset type, managed and unmanaged, across IT, OT, IoT, and IoMT.
The more autonomous the response, the more the consequence of incomplete context grows. Discovering a device isn’t the same as knowing what it is, what vulnerabilities it has, what depends on it, and what happens if you disrupt it. The difference between isolating a spare workstation and quarantining an infusion pump or a production controller is exactly the context an AI agent cannot generate on its own.
That context holds true whether the agent belongs to your adversary or your defense team.
So where does the complete picture come from with the volume, speed, and scale required for agentic security? It comes from the network.
The network is not only where security teams find the truth. It is also where they act on it. The same fabric that identifies a device and shows what it can reach is where teams enforce access, segment traffic, and contain movement.
The network is both the source of truth and the point of control.
Go deeper: Explore Forescout’s Frontier AI Readiness Center.
The Fundamentals, with the Stakes Turned Up
This does not call for a new framework. It calls for familiar network security disciplines, applied with universal urgency:
- Know what you have. You can’t secure what you can’t see, and neither can your AI agents. Complete, trusted asset intelligence across IT, OT, IoT, and IoMT is the context layer for agentic security.
- Understand your risk. Severity alone is noise. Exposure, reachability, and operational impact are the signals that turn AI-agent guesswork into trustworthy assessment.
- Control network access. Continuous verification for every asset, at every control point, helps keep the picture AI agents act on trustworthy.
- Limit movement and communication. Segmentation limits the blast radius of an attack and reduces the impact of an autonomous action that gets it wrong.
- Automate response and govern continuously. Autonomous action needs a policy-based safety net and a human accountable for irreversible calls, so a fast decision does not become an unrecoverable one.
These five disciplines form the operational foundation for cyber resilience in the agentic era.
The Ground Your Agent Stands On
You do not beat AI with AI alone. You also do not reduce risk by pretending AI is not already changing the fight. The practical position is calmer and more durable: as tools become smarter and more agentic, they depend even more on disciplined security fundamentals and a network that can see, understand, and control every connected asset. That is not a retreat from agentic security. It is what makes autonomous response safe enough to trust.
And when you’re ready for the operational playbook, the five steps that turn the network into the source of truth and control your AI agents can rely on, read our ebook: Five Steps to Smarter Network Security in an AI-Driven Era.