Endpoint security doesn’t solve agent security. Security incumbents and new startups with $100M+ seed rounds are burning millions of dollars on marketing, claiming they do AIDR but, in reality, are just doing basic DLP…cough, CrowdStrike, cough…pardon me, the air is just super polluted with marketing bullsh*t.

Agents have evolved beyond the endpoint. We need to start thinking of how agents will operate as Von Neumann probes. “WTF is a Von Neumann probe,” you ask? Great question. It’s a hypothetical spacecraft capable of self-replication. It travels to distant star systems, uses local raw materials from moons or asteroids to build factories, and then creates copies of itself which launch to other star systems. Rinse and repeat, and you have exponential exploration capabilities.

slides glasses up noise…super nerdy, I know. But it’s how agents are shaping up today. They start in one place, like your laptop, and spin up subagents or transfer tasks across your endpoint, frontier lab infrastructure, SaaS applications, hyperscalers…literally everywhere an agent is supported.

The agent “perimeter” is no longer a perimeter. It’s a hyper-connected network of agents that collaborate to execute tasks.

This isn’t science fiction. It’s happening today. The V1 agent harnesses had the run-time environments sit in one place. Your endpoint. You launched your coding harness like Claude Code or the Cowork desktop app, and the agent spun up, communicated to the frontier lab-hosted model, used some MCPs to access other data and sources, and executed tasks. The agent sat in one place. But as with all things AI, just as we get used to a certain way of working, it all shifts.

In July 2026, Anthropic switched things up with Cowork so that, by default, everything would run on Anthropic’s infrastructure. You spin up Cowork locally on the desktop (or now through a web browser), and the agent materializes in Anthropic’s execution environment. It’s not a far cry from Anthropic’s Managed Agents, which run agent workloads on their infrastructure. I snagged this graphic from a recent Anthropic webinar on Cowork Security, which provides a good visual breakdown of how the local version worked and how the new remote version works.

This distributed model presents very real security challenges. You’re not just charged with defending agents running on an endpoint. Your scope includes defending connected agents that are collaborating across multiple environments, some of which you likely don’t have any visibility into, let alone control over...at least in your current state, because everyone is trying to figure out what they need to be doing.

There’s good news, though! Say what you might about Anthropic, but they innovate, and others copy. They launched their Compliance API in August 2025 to give insights into prompts, but the data was incomplete. Then, in January 2026, Anthropic launched Cowork with no visibility until OpenTelemetry support arrived in April 2026, but even then, that support was incomplete. Finally, in August 2026, they merged Cowork and some Code telemetry (not all) into the Compliance API, so you can get most of the data in one spot.

It still isn’t a straight shot for organizations, especially those with smaller security teams. So, there’s still more work to do to make this easier for teams, but it is trending in the right direction. And other AI providers are following suit. Because let’s not forget that if you get visibility into one of your agent harnesses, you can bet that there are others in your environment. In 12 months, I believe that agent visibility will be streamlined.

That still leaves one itty-bitty problem that’s actually quite large…what do you do with the data? I get asked all the time, “What do I do with the data once I have it?”

Just when we thought gaining visibility was hard, we learned the real challenge. Doing something useful with the data. This is where I see everything fall short. Agent logging is a double-edged sword. You get good telemetry, but your existing tools don’t help you create effective detections, let alone analyze it in a way that doesn’t make you want to stick forks in your eyes. Most companies start with popping it into a SIEM or custom solution and doing the following:

  1. Set up signature detections: Easy to do until you realize how much security noise agents create. Clear-text secrets are an everyday, every-hour, every-minute occurrence with agents. It’s a true positive detection, but it's a widely accepted practice today (albeit a risk).

  2. Throw it into an LLM: A favorite of every open-source AIDR tool. It’s decent for triaging those false positives from signatures and can also identify some interesting security findings. Then the token cost starts adding up because the amount of data agents spit out is a whole other thing, and you notice latency tick up. LLMs are a detection feature, but they’re not a detection solution.

You can check off some boxes here for low-hanging fruit and take it up a notch looking for destructive tool commands. A good starting point, as was antivirus when endpoints first started taking off. But there’s a reason why AV went to the wayside. It sucked.

It’s still early for agents to cause material harm to a business at a scale similar to ransomware. But we are seeing security incidents involving agents happen today. Whether that’s insider threats using agents to accomplish their goals or agents going rogue and causing data leakage or production outages.

Detection is cool, but what about prevention? The shift is starting to happen here too, but it’s early. Blocking with agents has long been handled by intercepting traffic. For chatbots, this was intercepting the prompt and response and forcing a check. For coding agents, this was through agent hooks. This is a forced pause to do a check before an action can proceed. This can happen before or after a prompt, a tool call, or a sub-agent run (among many others). Not much innovation has happened because the use cases have been minimal and basic (e.g., DLP and destructive tool commands).

I’ll credit Microsoft with the early win here when they announced real-time runtime threat detection for Copilot Studio in September 2025, where you could ping a third-party tool to verify a prompt and response. Well, Anthropic is FINALLY following suit with Inference hooks, which entered beta in August 2026. Here’s a visual of how it works:

As with most things in agent security, it still requires a lot of work to get this working properly, and a block is only as effective as the detection engine instructing it what to block. But it’s the infrastructure to enable blocking across products that is the real win here. Expect these types of features to expand to other platforms.

As you can see, agent security is an interstellar journey that’s already launched. Agents are growing exponentially, and security is still catching up (as it always does). Here’s your checklist to launch your agent detection and response capabilities:

  1. Understand what agents are in use and where they’re operating. Don’t just think one step. Where can those agents spin up other agents or run tasks? Build a solid understanding of this, as it helps in the next step.

  2. Gain visibility into all areas agents are operating. Don’t assume the endpoint is where your agents are running. You may think that, but you’re already late to the party. Make sure you understand the gaps in coverage, because you are bound to have some.

  3. Evolve your detection approach to agents. Your SIEM won’t cut it. Your EDR won’t cut it. The fancy new endpoint security tool that’s claiming to do agent security won’t cut it. Agents are operating in ways that existing detection logic is not effectively built to handle. You need a detection engine that incorporates anomaly and behavioral detections, spanning the entire agent lifecycle.

  4. Enhance your prevention capabilities. Understand what is possible, and start tuning blocks based on the detections that concern you most. At this stage, it’s not a one-and-done. Ease into it, monitor for employee impact (spoiler: when done well, employees won’t notice), and tune to your risk tolerance.

If you need a launch partner on your journey, Evoke’s ship is fueled, and we’re ready to chat when you are.

Reply

Avatar

or to participate