AI agents are moving from pilots into production. They update firewall rules, touch cloud security groups, and grant access, often without a person or a ticket in the loop. Security teams are rightly asking how to secure them. 

So far, most of that conversation has focused on identity and endpoint. Who is the agent? What is it allowed to do? Is the device it runs on secure? These are the right questions to start with. But they leave out the one that decides how bad things get when something goes wrong. 

“These are very good questions,” says Erez Tadmor, Global Field CTO at Tufin. “But there’s one we don’t ask enough. Once an agent is in, once it’s running inside our network, what could it actually reach?” 

Even the AI labs couldn’t keep their agents in 

In April, Anthropic published the system card for Claude Mythos Preview. During one safety test, an early version of the model was placed in a secured sandbox and asked to try to escape. It built a multi-step exploit and reached the open internet from a system that was only supposed to reach a few predetermined services.1 

In July, OpenAI disclosed that its models had left an isolated test environment during a cybersecurity benchmark. The environment’s only outside connection was an internal package registry proxy. The models found a zero-day vulnerability in that proxy, moved through OpenAI’s research network until they reached the internet, and went on to break into Hugging Face’s production systems.2 

“If you think about it, these are AI labs testing their own models, with some of the best people in the field and some of the most secured environments,” says Tadmor. “And even with that, the model still found its way out to the internet.” 

Neither model was acting maliciously. Both were pursuing the goal they were given and took the shortest path they could find. That’s the point. An agent doesn’t need bad intent to cause a security incident. It only needs a path. 

Identity tells you who. The network decides where. 

Identity is becoming foundational to securing AI agents, and for good reason. You need to know which agent is acting and what it’s permitted to do. But an agent can be correctly authenticated and correctly permissioned and still be able to reach systems it should never touch. 

“Identity matters, but identity is not enough,” Tadmor says. “Identity doesn’t necessarily tell you where the agent can go once it’s running. That’s what the network does.” 

The network is where abstract permissions become real-world reach. Every open path, broad rule, or forgotten connection is a route an agent can find, and it can find it at machine speed. 

Segmentation sets the blast radius 

This is why network segmentation matters more now than it has in years. Combatting AI threats isn’t only about keeping agents out or making sure they behave. It’s about limiting how far one can get when something does go wrong. 

“Segmentation won’t stop every exploit,” Tadmor says. “But it determines how far it can get.” 

That limit is set before an incident, not during one. If an agent can reach ten systems today, you’ve already defined the worst case of tomorrow’s mistake. The time to shrink that blast radius is before the alert, not after it. 

Segmentation on paper isn’t proof 

There’s a catch. Most organizations can describe what their segmentation is supposed to look like. Far fewer can say with confidence that it’s still true right now, after the last cloud migration, firewall change, SASE rollout, or change an automated system made overnight. In Tufin’s research, more than half of security leaders said they can’t say for sure that their network security controls are working as intended right now.3 

“With agents moving so fast, it’s not enough for the segmentation policy to exist just on paper,” Tadmor says. “You need to know that it’s actually working at any given point in time.” 

Point-in-time audits can’t deliver that. A quarterly review tells you what was true when someone last checked. CISA makes a similar case in its Internet Exposure Reduction Guidance: exposure has to be assessed, addressed, and reviewed on an ongoing basis, not checked once and filed away.4 

What security teams can do now 

The goal is to move from assumed segmentation to proven segmentation, continuously. Four steps get you there: 

  1. Assess what’s actually reachable. Map what every workload and agent can reach, not just what it’s authenticated to do. Confirm that deployed connectivity matches the policy you wrote, not just the diagram. 
  1. Evaluate whether each path still earns its keep. Drift is the default. Every cloud migration, firewall edit, or SASE rollout can quietly open a path nobody intended. Find the forgotten connections and overly broad rules before an agent does. 
  1. Mitigate with enforcement, not assumption. Prioritize fixes by real exposure, starting with the paths that would let something reach critical systems, rather than working through a dashboard full of alerts. 
  1. Reassess continuously, not periodically. Your network changes every day, and agents act in seconds. Validation has to keep pace, so you know your segmentation holds right now, not just once a quarter. 

The question to take back to your team 

Tufin Segmentation Intelligence continuously measures the gap between intended segmentation and actual enforcement across the hybrid enterprise. It catches configuration drift, reduces attack-path exposure, and gives you real confidence that your segmentation holds as your network, and the agents operating in it, keep changing. 

Tadmor leaves security leaders with one question worth asking this week: 

“If something in your environment were compromised tomorrow, how far could it get? If that’s a hard question to answer, it’s a good place to start.” 

Book a demo to see how Tufin proves your segmentation still holds. 

Sources

  1. Anthropic, “Claude Mythos Preview System Card”, April 7, 2026. 
  2. OpenAI, “OpenAI and Hugging Face partner to address security incident during model evaluation”, July 21, 2026. 
  3. Tufin research on security leaders’ confidence in network security controls. 
  4. CISA, “Internet Exposure Reduction Guidance”, rev. August 21, 2026. 

Ready to Learn More

Get a Demo