Tufin Field CTO Erez Tadmor and ONUG’s Nick Lippis on what it actually takes to secure AI agents before they touch your network.
An AI agent can rewrite a firewall rule in the time it takes to read this sentence. The security team reviewing that change is still working at the speed of a Tuesday-morning ticket queue. That mismatch — machine-speed change against human-speed governance — is quietly becoming the biggest risk most networks carry.
Erez Tadmor, Field CTO at Tufin, joined Nick Lippis on ONUG’s Built for Trust podcast to talk through exactly that gap, and what it actually takes to close it before an agent touches production. Here are four takeaways from that conversation.
- Your network, not your dev team, is the bottleneck now
- Containment only works if the boundary already exists
- Every agent needs a persona, a domain, and rights before it goes live
- Trust in agents has to be continuous, not just certified
1. Your network, not your dev team, is the bottleneck now
Dev teams have been running full-speed with AI agents for a while — scaffolding code, training agents on legacy systems, shipping faster than a human team ever could on its own. Infrastructure teams haven’t caught up, and that gap is becoming the real constraint on how fast a business can move.
“Developers are way ahead compared to infrastructure teams in the leverage and use of AI. That means delivery of applications is going to happen much faster. But the applications will not work in the void — the infrastructure is becoming the gating factor for enabling them.”
— Erez Tadmor, Field CTO, Tufin
That’s good news and bad news. Good, because it means the pressure to modernize infrastructure access is finally real and funded. Bad, because the instinct under that pressure is to open things up faster — grant broader access, skip a review step, cut corners to catch up. That’s exactly the moment security tends to lose.
2. Containment only works if the boundary already exists
Ask most security teams how they’d handle a compromised or rogue AI agent, and the answer is usually some version of “we’d isolate it fast.” That’s the wrong question.
“You can’t segment during an incident — segmentation is a steady state. The real question isn’t how fast you could isolate it. It’s what the blast radius was before the alert was fired.”
— Erez Tadmor, Field CTO, Tufin
Containment isn’t a reaction. It’s a property your network either already has or doesn’t. If an agent can reach three critical systems it never needed to touch, no amount of speed after the alert fires changes that. The boundary has to be there before the agent is.
This is also where compliance-driven segmentation earns its keep. Tadmor’s example: a PCI-regulated company can’t let its cardholder-data environment talk to unrelated parts of the network, agent or no agent. That’s not a nice-to-have policy — it’s the fence an agent has to operate inside from day one.
3. Every agent needs a persona, a domain, and rights before it goes live
The most practical part of the conversation is also the simplest. Nick Lippis described a two-part model for governing any AI agent before it touches production:
- Plan it first. Every agent should have a defined persona (what is this agent actually for?), a domain (what part of the infrastructure is it responsible for — virtual switches, routers, load balancers?), and explicit rights (what is it actually allowed to do?).
- Then deploy it on rails. Once live, the agent gets access to specific sources of truth — logs, alerts, identity, the policies governing roles and access — and everything it does gets tracked and documented.
Most organizations aren’t doing this yet. It’s a reasonable starting checklist for any team about to put its first agent into a live environment.
4. Trust in agents has to be continuous, not just certified
Zero trust has always leaned on the idea of a credential: you have the right certificate, so you’re trusted. That doesn’t hold up once agents are making decisions and taking actions at machine speed — trust has to become something you can prove, continuously, not something you check once.
Tadmor names three things that have to be true instead:
- An inventory of every non-human identity, mapped to exactly what it can reach.
- Segmentation boundaries that are machine-verifiable, not just written down somewhere.
- Change review that’s fully automated, not a manual box someone checks once a quarter.
The audit comparison is a useful one. Enterprises used to treat compliance like a twice-a-year event — weeks of prep, then back to business as usual.
“That audit doesn’t worth anything a day after, because the network changes all the time. It has to be continuous.”
— Erez Tadmor, Field CTO, Tufin
None of this means cutting people out of the loop, either — it means moving them to a different spot in it. The human role shifts from being in the loop to being on it: not approving every single action, but always able to pressure-test what’s happening and step in the moment it matters.
“Especially in the security world, we won’t be able to let it go so quickly, because we need this trust.”
— Erez Tadmor, Field CTO, Tufin
Listen to the Podcast
Tadmor and Lippis cover more ground in the full conversation, including how trust in autonomous systems gets built over time and what Tadmor calls the future “ninja” shape of security operations teams.
The gap between machine-speed change and human-speed governance isn’t closing on its own. The organizations that put boundaries in place before their agents arrive are the ones that get to move fast without losing control.
Ready to Learn More
Get a Demo