Tech giants form alliance to tackle AI agent security gap

by

Bernard Parado

-

22 seconds ago

Singapore – A cross-industry coalition of technology vendors has formed the Blueprint Alliance, a new initiative aimed at helping enterprises secure and govern the AI agents operating across their systems. The group brings together identity, AI, data, applications, infrastructure, cybersecurity and strategic industry players to co-author an expanded architecture for what is being called the “secure agentic enterprise.”

Founding members include Amazon Web Services (AWS), CrowdStrike, Databricks, Docker, Google Cloud, Lovable, Okta, Proofpoint, Salesforce, ServiceNow, Wiz, and Zscaler. GE Appliances and World Central Kitchen are also involved as strategic advisors, tasked with helping refine and validate the approach from a real-world operational standpoint.

The formation of the Alliance responds to a widening gap in how organisations manage AI agents as they proliferate across enterprise environments. According to Gartner, the average global Fortune 500 enterprise is projected to have more than 150,000 agents in use by 2028, yet only 13% of organisations currently believe they have adequate AI agent governance in place.

That gap, the coalition says, stems from an interconnected agentic stack in which agents must reason, act and connect across model providers, data platforms, SaaS applications, networks and infrastructure. As this complexity grows, so too does the risk of shadow agents multiplying unchecked, credentials crossing trust boundaries, and agents executing beyond their intended scope.

To address this, founding members have aligned around a shared set of principles for securing AI agents. These include treating every agent as a first-class identity, scoping access to the task rather than granting standing access, keeping delegation traceable, continuously monitoring runtime behaviour, enabling instant and reversible containment, and ensuring governance keeps pace with the speed of AI development.

Building on these principles, the Alliance has evolved a blueprint for the secure agentic enterprise, first introduced in March 2026, into what it describes as an open, multi-vendor reference architecture. The architecture is structured around four core questions that organisations must be able to answer: where are my agents, what can they do, what are they doing, and how do I respond.

The first pillar, agent discovery and identity, focuses on detecting and cataloguing every agent within an organisation, from internally built systems to imported SaaS and third-party agents, as well as unmanaged shadow AI, with each validated agent registered as a distinct, verified identity with an accountable human owner. 

The second pillar addresses access policies and governance, scoping access to specific tasks rather than standing privilege and keeping delegation traceable as agents spawn sub-agents or act on behalf of humans, supported by automated access reviews.

The third pillar centres on runtime authorisation and monitoring, enforcing access policies inline through gateways positioned in the execution path and continuously observing agent behaviour in-session to catch data leakage, prompt injection and anomalous activity. 

The fourth pillar covers response and enforcement, enabling organisations to neutralise threats through targeted containment, rate-limiting or token revocation, with contained agents subsequently restored through a deliberate, documented and auditable re-enrolment process.

Underpinning all four pillars are foundational elements of execution context and risk signals, continuously fed by runtime telemetry, logging and observability, which the Alliance describes as the connective tissue enabling the system to detect risk patterns and respond in concert.

Beyond the architecture itself, founding members have committed to deeper interoperability work. This includes building and testing cross-vendor signal sharing across open standards such as MCP, OCSF, SSF and CAEP, so that a threat signal raised by one runtime monitor can trigger real-time action across connected control planes.

Members have also committed to regularly publishing joint interoperability results and reference integrations, intended to serve as connective tissue for a broader multi-vendor security ecosystem.

Commenting on the initiative, Chet Kapoor, VP of Security, Search and Observability at AWS, said, “AWS joined the Blueprint Alliance as a founding member to provide customers a unified approach for seeing, governing, and trusting the agents they run across their enterprise.”

Daniel Bernard, Chief Business Officer at CrowdStrike, added, “AI is reshaping the enterprise, and security has to be foundational to everything that comes next. No single technology or vendor can secure the agentic era alone. CrowdStrike is bringing our leadership in securing the agentic enterprise to the Blueprint Alliance to advance an open, interoperable architecture that helps organisations deploy and operate AI agents securely at scale.”

David Meyer, SVP Product at Databricks, said, “Securing AI agents requires governance across the entire AI estate. Databricks joined the Blueprint Alliance to bring that open, multi-vendor approach through Unity Catalog and Unity Gateway, giving enterprises unified control over data, models, agents, and tools on any cloud, regardless of where they run. We’re contributing what we’ve learned building the Databricks AI Security Framework and look forward to helping the Alliance turn shared principles into interoperable standards.”

Tushar Jain, CTO of Docker, Inc., stated, “Docker is proud to be a founding member of the Blueprint Alliance, and honored to stand alongside so many companies that share our vision for a safer agentic future. That future depends on leaders throughout the industry coming together to develop a baseline approach organisations can use to extend trust beyond the model to the environments where agents execute. We’re looking forward to working with Okta and the other founding members to turn that shared blueprint into real interoperability, so that security, isolation, and governance always keep pace with the agents they’re built to secure.”

Abhi Sawant, VP of Engineering, Platform Security at Google Cloud, said, “As AI agents rapidly scale across enterprise environments, organisations need the flexibility to connect best-of-breed identity, security, and runtime solutions across heterogeneous stacks.”

“Google Cloud delivers a comprehensive, end-to-end agent platform and robust security capabilities, built with an enduring commitment to open, interoperable architectures that give customers full freedom of choice. We are excited to collaborate with Okta and the Blueprint Alliance to establish open standards that advance zero-trust governance, traceable delegation, and seamless protection across the entire agent lifecycle,” Sawant added.

Igor Andriushchenko, Head of Security at Lovable, expressed, “We joined the Blueprint Alliance because a shared architecture is more resilient than anything one company builds alone, and every advance benefits everyone. We’re excited to help build that architecture alongside other industry leaders, so every company can deploy agents with confidence.”

Andrew Comstock, SVP & GM at MuleSoft (Salesforce), said, “As enterprises scale their agentic operations, they’re running agents across a mix of models, platforms, and vendors — and that reality is exactly why security has to be a shared architecture, not a single vendor’s feature.”

“Agent Fabric is built as the AI control plane for that multi-vendor reality, giving customers a consistent way to govern every agent they run, in real time, as it acts, across their agentic enterprise. Joining the Blueprint Alliance lets Salesforce bring that same commitment to openness to security, sharing best practices with Okta and the other founding members to build the runtime governance standard the industry needs,” Comstock added.

Steven Tamm, SVP of Ecosystem at Okta, emphasised, “The blueprint started because our customers needed a consistent architecture for securing agents, one that governs identity, access, and execution across the entire stack without shutting down the autonomy that makes agents useful. Getting there required founding members across the Blueprint Alliance to align on a shared approach rather than each vendor solving it alone. We’re glad to have contributed to that work, and we look forward to the industry building and testing against it as we help secure the future of AI.”

Ryan Kalember, Chief Strategy Officer at Proofpoint, said, “The future of enterprise AI depends on trust, and trust cannot exist without shared security standards. As AI agents increasingly act on behalf of people across organisations, the industry needs a common approach to identity, governance and runtime protection. As a founding member of the Blueprint Alliance, we are proud to work alongside industry leaders to establish the architecture that will make securing the agentic workspace possible.”

Bhakti Pitre, VP, AI Platform Security and Governance at ServiceNow, expressed, “Securing the agentic enterprise requires more than identity controls. It requires governance, orchestration, and the ability to trace every decision and action an agent takes. The Blueprint Alliance brings together the full stack to answer the critical questions every organisation is asking: Where are my agents? What can they do? What are they doing? ServiceNow looks forward to working with Okta and our partners to make this standard work in practice, so enterprises can scale AI confidently and securely.”

Oron Noah, VP of Product, Extensibility & Partnerships at Wiz, said, “As organisations deploy AI agents, teams need complete visibility and clear context to scale AI securely. By joining the Blueprint Alliance, we are making it simpler for customers to manage AI risk without slowing down innovation. Ecosystem collaboration is how we empower defenders to move at machine speed.”

Raveesh Chugh, VP of Strategic Technology Partnerships at Zscaler, said, “The future of AI is agentic, and securing it starts with zero trust. By working with the Blueprint Alliance, Zscaler is helping to create a practical framework for controlling how AI agents connect, act, and access data across modern enterprise environments.”

On the advisory side, Mandar Deo, Chief Digital Technology Officer at GE Appliances, said, “AI agents have the potential to transform manufacturing by accelerating problem-solving, improving quality and strengthening collaboration across the value chain. Unlocking that value at scale requires strong governance, clear visibility into where agents operate, what they can access and how they make decisions.”

“As a strategic advisor to the Blueprint Alliance, GE Appliances is bringing a real-world manufacturing perspective to help shape and validate a secure, scalable architecture that can operate across complex industrial environments—while maintaining accountability, trust and human controls,” Deo continued.

Meanwhile, Brian Stoll, Chief Technology Officer at World Central Kitchen, said, “In order to support the urgent technology demands of disaster response on a global scale, World Central Kitchen is embracing the dynamic benefits of agentic technology. To do so responsibly requires establishing governance that is as dynamic as the agents themselves. We are looking forward to participating in the Blueprint Alliance for this exact reason: to help establish principles, processes, and tooling for agentic discovery, ownership, runtime control, and observability – not to mention a better night’s rest for the CTO.”

Recognise the innovators redefining commerce at the Retail & E-commerce Excellence Awards Asia Pacific 2026! Taking place this December 2026, we celebrate the region’s most impactful retail strategies, standout e-commerce experiences, and forward-thinking leaders—submit your entries today!
Honour the women shaping the future of marketing and technology at the Empowered Women Awards 2026! This December 2026, we celebrate inspiring leaders, changemakers, and rising voices driving impact across the industry—submit your entries today!
Share

RECENT ARTICLES

Tech giants form alliance to tackle AI agent security gap
AI-assisted tools drive more targeted malware as network attacks decline, report finds
VAST Data unveils confidential AI runtime to secure enterprise data
TEAM LEWIS unveils secure AI platform for multi-market marketing teams
Al-Futtaim partners with Juspay for payment orchestration across 50 brand
Ellipse 3

RELATED ARTICLES

watchguard report
VAST Data Unveils Confidential AI Runtime to Secure Enterprise Data
cohesity (1)
Ellipse 3

FEATURED ARTICLES

'Retail & E-Commerce Innovation Summit' returns for its 2nd edition in the Philippines — initial speaker lineup revealed
‘Retail & E-Commerce Excellence Awards Asia Pacific
Empowered Women Awards 2026 to honour leading women trailblazing the technology and marketing industries

Subscribe to UpTech Media Newsletter

JOIN OUR NEWSLETTER

Subscribe to our newsletter to get the latest APAC marketing news.