Use Case
AI Security Microsegmentation: Protecting Your Network from Compromised AI Agents
Agentic AI tools are being deployed across your enterprise with file system, terminal, and network access. When compromised, they become machine-speed insider threats that move laterally faster than any human attacker. Elisity treats AI agents as a fourth identity type, alongside users, workloads, and devices, so least-privilege policy is enforced against the agent itself at the network access layer.
Challenges
Employees are installing AI coding assistants and autonomous agents on enterprise endpoints, often without IT approval. These tools operate with legitimate credentials and broad system privileges, which makes them indistinguishable from normal user activity. In July 2026, Anthropic disclosed that three of its own models reached the production infrastructure of three real organizations during security testing, and two of those organizations had not noticed. Traditional firewalls sit at the perimeter, not at the access layer where lateral movement begins. AI governance frameworks address the agent layer but leave the network infrastructure, where attacks actually propagate, unprotected.
Network Segmentation Without Compromise
Customer Spotlight
"Elisity provides technical distancing between devices to stop the spread and progression of a cyberattack. For impacted toxic assets, it also lets us excise them with surgical precision to preserve safe and effective technology-supported care continuity."
Main Line Health
Challenge
AI Agents Bypass Perimeter Security
Agentic AI tools operate from inside trusted endpoints with legitimate credentials. Firewalls are deployed at network boundaries, not at the access layer where devices connect, and lateral traffic between endpoints on the same segment never traverses a firewall. The FortiGate campaign disclosed in February 2026 is the pattern in miniature: more than 600 devices across 55 countries, reached through exposed management interfaces and weak, reused credentials rather than any software vulnerability.
Elisity Solution
Enforce at the Access Layer
Elisity enforces microsegmentation at the access layer, at the first hop where devices and workloads connect. Lateral traffic is controlled before it can traverse the network. No additional hardware is required, and policy is enforced through your existing Cisco, Arista, Juniper, and Aruba infrastructure, wired and wireless alike.
Challenge
VLANs Cannot Distinguish AI from Legitimate Traffic
A compromised AI agent uses the same credentials and network position as the employee who installed it. VLANs provide broadcast domain separation but do not prevent lateral movement within a segment, so an attacker who compromises one device can freely reach every other device in that VLAN. IBM’s Cost of a Data Breach Report 2026 found one in four malicious breaches are now AI-enabled, a 56% increase year over year.
Elisity Solution
Identity-Based Policy Groups
Elisity IdentityGraph verifies identity across Active Directory, CrowdStrike, ServiceNow CMDB, and more. Policy Groups enforce based on correlated identity, not network location, so devices on the same VLAN can have completely different access rights with no re-VLANing required. Any attribute held in IdentityGraph can have policy written against it and enforced on the network.
Challenge
Machine-Speed Attacks Outpace Human Response
AI agents probe every accessible resource continuously, without fatigue. In the GTG-1002 campaign Anthropic disclosed in November 2025, AI executed an estimated 80% to 90% of the tactical work against roughly 30 organizations, with human operators stepping in at only a handful of decision points. CrowdStrike puts average eCrime breakout time at 29 minutes. By the time an analyst responds, a compromised agent has already mapped everything it can reach.
Elisity Solution
Automatic Threat Reclassification
When CrowdStrike or SentinelOne detects anomalous behavior, Elisity IdentityGraph automatically reclassifies the device into a restricted Policy Group within seconds. The compromised endpoint is contained at the access layer before lateral movement begins, without waiting for anyone to open a ticket.
Challenge
Shadow AI: Unauthorized AI Agent Installation by Employees
Employees are installing AI coding assistants and autonomous agents without IT approval or security review. Unlike traditional shadow IT, these tools operate with file system access, terminal privileges, and autonomous network connectivity. HiddenLayer’s 2026 AI Threat Landscape Report found 76% of organizations now treat shadow AI as a definite or probable concern, up from 61% a year earlier, and Akeyless research from May 2026 found 67% of security leaders suspect AI agents have already accessed data they were not authorized to see. Security teams have no visibility into which agents are running or what they are reaching.
Elisity Solution
Identity-Aware Containment of Unauthorized AI Agents
Elisity classifies every device and workload on the network, including endpoints running unauthorized AI tools, without requiring software agents. When an unapproved AI agent initiates unexpected connections, dynamic policy restricts it to only authorized resources. Even an AI agent with full local system privileges cannot reach databases, servers, or segments it was never authorized to access.
For a deeper look at how AI agents change the lateral movement threat model and what to configure first, read our analysis of AI agent network security and microsegmentation.
Challenge
Containing the Machine Is Not the Same as Governing the Agent
One workstation can run several AI agents at once, each with a different job, different credentials, and a different blast radius. Treating the agent as a property of its host makes containment all or nothing: quarantine the machine and you quarantine the person using it and every other process on it. That is the right emergency response and the wrong steady state, and it is where most agent governance programs stall.
Solution
AI Agent as a Fourth Identity
Elisity treats AI agents as a fourth identity type, alongside users, workloads, and devices. Agents are identified from network behavior rather than an inventory, so sanctioned and shadow agents surface the same way. Each becomes a first-class identity in IdentityGraph with its own attributes, distinguishable from the host it runs on: a workstation running three agents is four identities, not one.
Because any attribute held in IdentityGraph can have policy enforced against it on the network, least-privilege policy applies to an AI agent exactly as it applies to an infusion pump or a contractor laptop. Enforcement was never coupled to what kind of thing the identity is.
Challenge
AI Agents Embedded in Malware: The Autonomous Trojan Threat
Autonomous AI agents are being embedded in software downloads and developer tools, functioning as intelligent trojans that adapt to the network they infiltrate, rewrite their own code to evade detection, and execute lateral movement on their own. Check Point Research’s VoidLink analysis documented an AI coding agent producing roughly 88,000 lines of working implant code in about a week, and Google’s threat intelligence team documented PROMPTFLUX, malware that rewrites itself between runs by calling a model API.
Elisity Solution
Network-Layer Defense Against AI-Powered Malware
Elisity neutralizes AI-embedded malware by enforcing identity-aware policy at the network access layer, the one layer an AI agent on an endpoint cannot circumvent. Even when a trojan evades endpoint detection, it cannot bypass network-level segmentation restricting which devices and segments that endpoint can reach. Elisity operates agentlessly, so there is no local software for malware to disable or evade.
Resources
Elisity Microsegmentation: Accelerate Zero Trust Security in Weeks, Not Years
Stop AI-Driven Lateral Movement Before It Starts
AI Security & Microsegmentation FAQs
Identity-based microsegmentation at the access layer. When an AI agent is compromised on an employee’s workstation, Elisity IdentityGraph prevents lateral movement to critical assets regardless of what credentials that agent has discovered. The workstation’s Policy Group membership, verified across multiple authoritative sources including CrowdStrike, ServiceNow CMDB, and Active Directory, determines what it can reach. Enforcement happens at the network access layer, blocking the traffic before it reaches critical infrastructure.
Yes. Elisity treats AI agents as a fourth identity type, alongside users, workloads, and devices. Agents are identified from network behavior rather than from an inventory, so sanctioned and shadow agents surface the same way, and each becomes a first-class identity in IdentityGraph with its own attributes, distinguishable from the host it runs on. A workstation running three agents is four identities, not one. Because any attribute held in IdentityGraph can have policy enforced against it on the network, least-privilege policy applies to an AI agent exactly as it applies to an infusion pump or a contractor laptop.
No. Zero training on customer data. Elisity uses private LLMs via AWS Bedrock in a single-tenant architecture. Your data is analyzed locally within your Cloud Control Center instance. It is never exported, shared, or used to train any model.
No. Elisity is human-in-the-loop by design. Administrators review evidence-backed suggestions from Elisity Intelligence. No autonomous classification or policy enforcement occurs without human approval, and every recommendation is auditable.
Three pillars for your compliance team: no model training on customer data, single-tenant isolation with full audit trails (SOC 2, GDPR, and HIPAA ready), and human approval required for all AI-driven policy changes. In May 2026, CISA, the NSA, and allied international agencies published joint guidance on agentic AI that tells organizations to align AI risk management with the cybersecurity frameworks they already run rather than standing up a parallel AI security program, which is exactly what extending existing segmentation controls to cover agents does.
Shadow AI refers to employees installing unauthorized AI tools, including coding assistants, autonomous agents, and generative AI applications, without IT approval or security review. These tools can access file systems, execute terminal commands, and open outbound network connections. Because they are unmanaged by definition, endpoint controls cannot reach them. Elisity discovers them by network behavior and enforces policy that restricts their communication to explicitly authorized resources, without requiring software on the device.
AI-embedded malware can adapt to network environments, rewrite its own code to evade detection, and make autonomous decisions about lateral movement and data exfiltration. Elisity neutralizes these capabilities by enforcing identity-aware policy at the network access layer, the one layer an AI agent running on an endpoint cannot circumvent. Because Elisity is agentless, there is no local software for embedded AI malware to disable or tamper with.
The picture moved quickly in 2026. NIST’s CAISI Request for Information on AI Agent Security closed March 9, 2026, and NIST’s Summary Analysis, published May 18, 2026, reported that commenters widely agreed AI agents present novel security threats and that existing cybersecurity principles, while still relevant, require adaptation. On May 1, 2026, CISA, the NSA, and allied international agencies published joint guidance on the careful adoption of agentic AI services. And Executive Order 14409, signed June 2, 2026, directed CISA to issue Binding Operational Directives on AI-enabled threats and named the use of AI agents for unlawful access as a criminal enforcement priority.
On April 7, 2026, Anthropic launched Project Glasswing and published the Claude Mythos red-team assessment: a single model autonomously discovered thousands of high-severity zero-day vulnerabilities across every major operating system and browser, chained exploits into full Linux kernel privilege escalation for under $2,000, and surfaced decades-old bugs in security-hardened code. The Mythos moment collapses the time from vulnerability disclosure to weaponization, which is the exact gap identity-based microsegmentation was designed to contain. For the full threat-model walk-through, see Claude Mythos found 27-year-old bugs: your unpatchable devices are exposed.
Six major frameworks independently codified identity-based microsegmentation as the compensating control of record for devices that cannot be patched: NIST SP 800-207 (Section 3.1 Approach #2), NIST CSF 2.0 (PR.IR-01), IEC 62443-3-3 (SR 5.1, SR 5.2, plus the compensating-countermeasures clause), HIPAA 2025 NPRM (45 CFR 164.312(a)(2)(vi)) supported by HHS 405(d) HICP Practices #6 and #9, PCI DSS 4.0 (Requirements 1.2 through 1.5 and Appendix B), and CISA ZTMM v2.0 Network pillar (Advanced and Optimal). The same control pattern that contains AI-driven lateral movement on this page is what those frameworks now require.
Resources

Elisity Release 26.7: Hierarchical policy, broader platform support, and deeper device context

AI Agent Network Security: Why Microsegmentation Is the Missing Layer

