You Can't Have AI Security Without API Security: The Agentic Action Layer
AI agents run on APIs, and that is where most security programs have a gap. Salt Security Co-Founder and COO Michael Nicosia and CMO Michael Callahan explain why you cannot secure AI without securing the APIs underneath it. An AI agent uses an LLM to reason and an MCP server to broker calls out to other systems, and every one of those calls is an API interaction. Deploy one agent and the traffic multiplies. Deploy hundreds, and the internal east-west traffic climbs to several times what a pre-AI environment carried.