API Security for AI Agents: What CISOs Need to See, Govern, and Protect
AI agents are moving into every part of the business, and each one runs on APIs. Salt Security Co-Founder and COO Michael Nicosia and CMO Michael Callahan walk through what that shift means for security leaders. A single AI agent can generate thousands of API calls, and once agents start talking to each other through MCP servers and agent-to-agent protocols, the number climbs into the millions. That growth widens the attack surface and turns prompt injection into a common entry point.
The session covers what CISOs are asking about agentic AI, why Gartner projects that half of security breaches will connect to AI by 2028, and how 80% of organizations may see agents consume most of their API traffic in the same window. It also breaks down the McDonald's McHire breach, where a default password and a business object authentication flaw exposed 64 million applicant records, and explains why that type of flaw was preventable.
The core approach stays consistent: see your APIs, govern them with policy, and protect them from attack. Nicosia and Callahan show how Salt Illuminate delivers each step, including an external attacker view, a full API and MCP server inventory in under 10 minutes, deeper data risk analysis, and patented context-based threat detection that catches low and slow attacks.
Salt Security created the API security category in 2018 and protects APIs for organizations deploying AI at scale. The platform gives security teams visibility, governance, and protection so they can adopt agentic AI without adding risk.
Run a free external attack surface assessment: https://salt.security/attack-surface
Speakers:
- Michael Nicosia, Co-founder & COO of Salt Security
- Michael Callahan, CMO of Salt Security
Timestamps:
0:00 The CISO's dilemma with agentic AI
2:39 What changed: AI agents, LLMs, and MCP servers explained
7:55 The API fabric and why it is exploding
10:33 How many companies deploy AI agents by 2025
12:24 One agent versus 500: the API sprawl problem
14:21 Agent-to-agent communication and extended risk
16:37 Why the risk skyrockets: attack surface, data leakage, prompt injection
18:15 What Gartner and KuppingerCole predict for AI and API breaches
23:33 Compliance and regulation: EU AI Act, GDPR, and API rules
25:03 Solving the problem: see it, govern it, protect it
29:11 Inside Salt Illuminate: surface, connect, collect, protect
34:34 Is it real? A live look at seeing, governing, and protecting MCP servers
37:15 The McDonald's McHire breach and why it was preventable
39:16 Summary and why API security is the requirement
41:16 Q&A: prevention, LLM memory, RBAC, compliance frameworks
45:49 The Policy Hub and free resources