Market-code
Blueprint Alliance Targets AI Agent Security

AI agents are moving beyond simple chatbots. Businesses are increasingly using them to access data, interact with applications, automate workflows, and take actions on behalf of employees and customers. As these systems become more capable, security teams face a new challenge: how to control software that can make decisions and act across multiple enterprise systems.

A group of major technology companies is now working on that problem.

Okta, AWS, CrowdStrike, Databricks, Docker, Google Cloud, Lovable, Proofpoint, Salesforce, ServiceNow, Wiz, and Zscaler have formed the Blueprint Alliance, an industry coalition focused on creating a shared architecture for securing AI agents.

The initiative aims to give businesses a common approach to managing AI agents across models, applications, cloud environments, data platforms, and security systems.

Why AI Agents Create a New Security Challenge

Traditional software generally operates within defined permissions and workflows. AI agents introduce another layer because they can interpret information, make decisions, call tools, interact with other systems, and sometimes delegate tasks to other agents.

That creates a broader security surface.

An agent may need access to customer information, internal documents, business applications, databases, APIs, or payment systems. If those permissions are too broad, a compromised or poorly configured agent could potentially affect multiple systems.

The problem becomes even harder when companies use agents from different vendors. Organizations may have internally developed agents running alongside agents provided through SaaS platforms and other third-party services.

The Blueprint Alliance says businesses need better visibility into where these agents exist, what they can access, what they are doing, and how security teams can respond when something goes wrong.

A Shared Architecture for AI Agent Security

The Blueprint Alliance is building on a framework first introduced in March 2026. The expanded approach focuses on four fundamental questions that enterprises need to answer.

The first is where their AI agents are.

Organizations cannot effectively secure agents they cannot identify. The framework therefore emphasizes discovering and cataloging agents, including internally developed systems, third-party agents, and unmanaged or “shadow” AI agents.

Each agent should have a distinct identity and an accountable owner.

The second question is what those agents can do.

Instead of giving an agent broad, permanent access, the alliance promotes task-based permissions. An agent should receive access based on the specific task it needs to complete.

This follows the broader security principle of least privilege.

The third question is what the agents are actually doing.

Identity controls alone are insufficient once an agent begins operating. Businesses also need continuous monitoring of agent activity so they can identify unusual behavior, data leakage, prompt injection attempts, or unauthorized access.

The fourth question is how organizations should respond when an agent becomes risky.

Security teams need the ability to quickly revoke tokens, terminate sessions, limit activity, or isolate an agent. The framework also emphasizes controlled recovery, allowing organizations to revalidate an agent before restoring access.

Why Interoperability Matters

One of the biggest challenges for enterprise AI is that companies rarely use technology from a single vendor.

A business might use one provider for cloud infrastructure, another for identity management, another for data platforms, and several different AI models and SaaS applications.

A security approach that works only within one vendor’s ecosystem can therefore leave gaps between systems.

The Blueprint Alliance is attempting to address this through greater interoperability. Its members plan to work with open standards including the Model Context Protocol, Open Cybersecurity Schema Framework, Shared Signals Framework, and Continuous Access Evaluation Profile.

The goal is to allow security signals and controls to work across different parts of an enterprise technology environment.

For example, if one system detects suspicious activity from an AI agent, that information could potentially trigger a response across connected security and access-control systems.

What This Means for B2B Companies

The development is particularly relevant for companies adopting AI agents for sales, customer service, IT operations, marketing, finance, and other business functions.

AI agents can potentially automate repetitive work and connect business systems in ways that traditional automation cannot. But wider access also increases the importance of identity, governance, monitoring, and access controls.

For IT and security leaders, AI agent security may therefore become part of the broader enterprise security strategy rather than being treated as a separate AI project.

Businesses may need to maintain an inventory of their agents, assign ownership, review permissions, monitor activity, and establish procedures for disabling compromised or misbehaving agents.

This becomes more important as organizations move from experimenting with AI to deploying agents across operational systems.

Conclusion

The formation of the Blueprint Alliance reflects a broader shift in enterprise AI. The discussion is moving beyond what AI agents can do toward how organizations can deploy them responsibly at scale.

The alliance is not proposing a single security product. Instead, its members are working toward a common reference architecture that can operate across different vendors and technology environments.

As AI agents become more deeply connected to enterprise systems, security will increasingly depend on visibility, controlled access, traceable actions, and continuous monitoring.

For B2B technology companies, that means AI adoption and cybersecurity strategy are becoming increasingly connected. The ability to deploy agents safely could become just as important as the capabilities those agents provide.