Gartner warns against using probabilistic agents for agentic AI security
Gartner analyst Craig Porter advises that using probabilistic AI agents to secure other agents creates significant enterprise security risks. Instead, organizations should prioritize deterministic runtime controls, verifiable identities, and strict API monitoring to manage the security of agentic AI systems.
Key Takeaways
- Probabilistic LLMs lack the repeatable rules necessary for enforcing deterministic security boundaries or automated remediation.
- Agent sprawl introduces operational complexity, increased token consumption, and higher latency across enterprise workflows.
- Gartner recommends prioritizing visibility of sanctioned and shadow AI agents before implementing autonomous defensive layers.
- Effective containment requires strict API monitoring and runtime policy checks to limit an agent's authority to specific account IDs or records.
Why It Matters
The shift toward autonomous agents in streaming infrastructure increases the risk of automated decisions causing real-world operational failures. Relying on probabilistic models for defense creates an unpredictable security layer that may fail to distinguish between legitimate high-bandwidth traffic and malicious prompt injections. As streaming platforms integrate more AI-enabled tools via the Model Context Protocol, the focus must shift from model-based monitoring to rigid, identity-aware authorization. This ensures that automation does not bypass existing governance or create unmanageable technical debt through agent sprawl. Watch for the Gartner IT Symposium/Xpo in November for updated frameworks on balancing agentic autonomy with deterministic safety guardrails.
Additional Context
The telecom industry is rapidly deploying agentic AI across network operations, creating the same security governance challenges Gartner identifies. In June 2026, Ericsson launched its AI in RAN commercial software subscription claiming up to 20% higher downlink throughput across more than 15 live deployments, while Verizon disclosed that its 60,000-site vRAN is now applying agentic AI to planned configuration changes and service assurance. Verizon publicly called for industry-wide interoperability standards for agentic systems, highlighting the absence of any standardized protocol for agentic command, control, and assurance across multi-vendor networks. That gap directly mirrors the security concern Gartner raises: without deterministic identity and authorization layers, autonomous agents operating across vendor boundaries lack verifiable trust boundaries.
Nokia has moved aggressively to position its agentic AI stack as a unified control plane, raising questions about vendor lock-in and security governance at scale. At DTW Ignite in June 2026, Nokia announced partnerships with AWS and Databricks to build data, cloud, and control layers for autonomous networks, extending its Autonomous Network Fabric as an operating system spanning radio, core, transport, and service domains. Nokia claims operators using its autonomous networks portfolio are achieving automation rates above 90 percent and service interruption periods of one minute per year or fewer. The TM Forum's Autonomous Networks L4/5 roadmap and the 3GPP 6G standardization process will need to incorporate agentic AI interoperability as a core requirement, yet no framework currently exists to enforce deterministic security policies across these multi-agent architectures.
The architectural divergence between Ericsson and Nokia on AI-RAN further complicates the security picture for agentic systems in telecom. Nokia's entire RAN strategy is now built on its partnership with Nvidia, with all Layer 1 functions designed to run on Nvidia GPUs via CUDA, while Ericsson keeps only the FEC function on the GPU and runs all other L1 software on the CPU. This means security controls for agentic AI must account for fundamentally different compute substrates depending on the vendor. Nokia also secured NTT Docomo as a customer for its agentic AI platform at DTW Ignite, signaling that tier-one operators are already committing to agentic architectures before industry-wide security standards mature. For streaming infrastructure operators evaluating similar agentic deployments, the telecom experience underscores Gartner's recommendation that must precede probabilistic agent-based monitoring.
Read full article at computerweekly.com
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source