Arm Newsroom Blog
Blog

Beyond the model: Securing the path from intelligence to action in the agentic AI era

As AI moves from generating answers to taking actions, security must extend beyond the model to protect the complete system that turns intelligent decisions into action.
By Arm Editorial Team

Throughout the generative AI era, much of the security conversation focused on protecting models, prompts and data. The agentic era adds another layer to the security challenge, as the AI itself can now use tools, access systems, write code and take actions at machine speed. A good example of this difference in a real-life use case is flight bookings – a generative AI system might suggest booking a flight, but an agentic system could search fares, use stored payment details, and complete the booking on a user’s behalf.

The security fundamentals for the agentic era remain familiar: identity, least privilege, isolation, trusted execution, memory safety, monitoring and resilience. However, what changes is the operating model. As agents act autonomously, dynamically select actions and operate across different software, infrastructure, edge and physical systems, they need deterministic, enforceable boundaries around what they can access and do. Securing the model alone is no longer enough; the entire path from intelligence to action needs to be secured.

This is critical for broader agentic AI adoption. Organizations need confidence that autonomous systems are operating within defined boundaries, that actions are attributable and that unexpected behavior can be contained. Security does not create trust on its own – that ultimately depends on the user, application and level of risk – but it provides the verifiable boundaries, accountability and resilience on which trust depends.

Will Abbey, Arm’s Chief Commercial Officer, outlines the shift to agentic AI and what it means for cloud, edge and physical environments

Agentic AI requires security at every layer

No single security mechanism can protect the complete path from reasoning to action. Security in the agentic era requires multiple complementary controls that operate across the agent runtime, software stack, host compute, infrastructure and ultimately the devices and systems where decisions take effect.

Systems need to identify who or what is acting, under whose authority, and authorize what that actor is permitted to do. Policies need to remain enforceable as agents dynamically select actions. Activity needs to be observable, so autonomous behavior remains accountable. And systems need ways to contain unexpected or unauthorized behavior when something goes wrong.

The fundamental architectural principle underneath all of these is straightforward: The component making a decision should not also be the sole authority deciding whether that decision is permitted. The model proposes, but the system authorizes and enforces.

Putting that principle into practice requires protection at multiple points between intelligence and action:

  • Establishing trust in the execution environment;
  • Protecting the path from decision to execution;
  • Independently enforcing whether an action is permitted; and
  • Securing the device or system where that action ultimately takes effect.

This is where Arm’s decades of work in secure computing is especially relevant. Arm provides the architectural foundation spanning the Root of Trust (RoT), secure and measured boot, attestation, isolation and memory safety, alongside reference software, APIs and ecosystem enablement that makes those capabilities accessible to developers.

These technologies address different parts of the agentic AI security challenge across the system. Secure boot and attestation help verify that workloads and security controls are running in the expected environment. However, verifying the environment is only part of the challenge, as an attacker could still exploit vulnerabilities in the agent runtime, tool host or policy-enforcement software to bypass controls or trigger unauthorized actions. Memory safety technologies such as Arm Memory Tagging Extension (MTE) and other architectural defenses help mitigate that risk by making classes of memory safety vulnerabilities in the software between reasoning and execution harder to exploit.

Arm Memory Tagging Extension explained

As agents gain persistent access to private context, memory and state, security also needs to govern when sensitive data is released. In higher-trust workflows, attestation can help verify the execution environment before protected context is made available to an agent.

Independent enforcement around agents

Infrastructure provides another dimension to security in the agentic era. As agents become more capable and persistent, infrastructure needs compute to execute agent workloads and independent compute capable of observing, governing and containing them.

The established CPU-plus-DPU architecture is just one example of how this principle can be implemented, with Arm providing a common compute foundation across both sides of this compute boundary. CPUs run agent runtimes, harnesses, orchestration, tool execution and applications. DPUs can provide a separate environment for infrastructure services including networking, monitoring, isolation and security.

Animated video demonstrating the system-level security model where Arm CPUs host and run agent workloads, while Arm-based DPUs independently observe, govern, isolate and help protect them.

This reinforces the principle that security controls are stronger when they are isolated from the processes they govern. NVIDIA’s new Open Agent Safety Platform demonstrates how this architectural model can be applied to agentic infrastructure.

Security has to follow the action

As agentic workflows increasingly move beyond data centers to span PCs, smartphones, edge devices and physical AI systems, the security challenge becomes broader.  An agent might reason using a model in the cloud, process private context locally on an edge device, and ultimately trigger an action through a robot or industrial equipment.

Security therefore needs to extend in two dimensions:

  1. Through the computing stack within each system; and
  2. Across each compute environment an agent touches.

The broad principle remains the same across all compute environments: an agent should only be able to access the resources and perform the actions it has been authorized to use. However, edge and physical AI systems introduce challenges that look different from the cloud and data center.

The agentic workflows across edge, cloud and physical environments

Consumer devices, cameras, robots, vehicles and industrial equipment cannot always be isolated like virtual cloud resources. As intelligence increasingly leads to a physical action, security mechanisms need to extend through software and communications to the device where the action is executed. This creates additional requirements around device identity, authenticated communication, permissions, device-side enforcement and auditability. Arm Device Connect provides a common way for AI agents and heterogeneous devices to discover and interact with one another, helping establish the connectivity layer where identity, permissions and governance can be applied.

Furthermore, as agents increasingly interact with physical machines and systems, agentic security needs to dovetail with established device security and functional safety approaches. Identity, authentication and authorization need to extend to the device, but they must operate alongside device-side enforcement, operating limits, fail-safe behaviour and the broader safety mechanisms already used to govern physical systems. Security determines whether an action is authorized; however, functional safety determines whether that action can occur within defined safe operating limits. As agentic AI moves into physical systems, both need to work together.

Building security around intelligence

The transition from generative to agentic AI changes a fundamental assumption about security for AI. Previously, models generated information that people chose whether to act upon, but agentic AI systems can initiate actions themselves. Security must extend beyond just protecting models and data to governing the complete path from reasoning to execution.

This creates a new architectural pattern for AI: the model determines what it wants to do, but an independent system determines whether it is allowed to do it. From Root of Trust and attestation to memory safety, independent infrastructure controls and device identity, each layer helps enforce that separation as agentic AI expands from cloud to edge and physical systems.

Arm provides a common architectural foundation with security technologies that help enforce these boundaries across the system, so as agentic AI gains greater freedom and capabilities to act, security can scale with it.

Arm is the platform for AI-enabled systems

Build custom and scalable security solutions on the Arm compute fondation.

Article Text
Copy Text

Any re-use permitted for informational and non-commercial or personal use only.

Editorial Contact

Arm Editorial Team

Stay informed with Arm's top stories, insights, and conversations.

Latest on X

promopromopromopromopromopromopromopromo