API Security for AI Agents: What CISOs Need to See, Govern, and Protect

AI agents are moving into every part of the business, and each one runs on APIs. Salt Security Co-Founder and COO Michael Nicosia and CMO Michael Callahan walk through what that shift means for security leaders. A single AI agent can generate thousands of API calls, and once agents start talking to each other through MCP servers and agent-to-agent protocols, the number climbs into the millions. That growth widens the attack surface and turns prompt injection into a common entry point.

The session covers what CISOs are asking about agentic AI, why Gartner projects that half of security breaches will connect to AI by 2028, and how 80% of organizations may see agents consume most of their API traffic in the same window. It also breaks down the McDonald's McHire breach, where a default password and a business object authentication flaw exposed 64 million applicant records, and explains why that type of flaw was preventable.

The core approach stays consistent: see your APIs, govern them with policy, and protect them from attack. Nicosia and Callahan show how Salt Illuminate delivers each step, including an external attacker view, a full API and MCP server inventory in under 10 minutes, deeper data risk analysis, and patented context-based threat detection that catches low and slow attacks.

Salt Security created the API security category in 2018 and protects APIs for organizations deploying AI at scale. The platform gives security teams visibility, governance, and protection so they can adopt agentic AI without adding risk.

Run a free external attack surface assessment: https://salt.security/attack-surface

Speakers:

  • Michael Nicosia, Co-founder & COO of Salt Security
  • Michael Callahan, CMO of Salt Security

Timestamps:

0:00 The CISO's dilemma with agentic AI

2:39 What changed: AI agents, LLMs, and MCP servers explained

7:55 The API fabric and why it is exploding

10:33 How many companies deploy AI agents by 2025

12:24 One agent versus 500: the API sprawl problem

14:21 Agent-to-agent communication and extended risk

16:37 Why the risk skyrockets: attack surface, data leakage, prompt injection

18:15 What Gartner and KuppingerCole predict for AI and API breaches

23:33 Compliance and regulation: EU AI Act, GDPR, and API rules

25:03 Solving the problem: see it, govern it, protect it

29:11 Inside Salt Illuminate: surface, connect, collect, protect

34:34 Is it real? A live look at seeing, governing, and protecting MCP servers

37:15 The McDonald's McHire breach and why it was preventable

39:16 Summary and why API security is the requirement

41:16 Q&A: prevention, LLM memory, RBAC, compliance frameworks

45:49 The Policy Hub and free resources