You Can't Have AI Security Without API Security: The Agentic Action Layer

AI agents run on APIs, and that is where most security programs have a gap. Salt Security Co-Founder and COO Michael Nicosia and CMO Michael Callahan explain why you cannot secure AI without securing the APIs underneath it. An AI agent uses an LLM to reason and an MCP server to broker calls out to other systems, and every one of those calls is an API interaction. Deploy one agent and the traffic multiplies. Deploy hundreds, and the internal east-west traffic climbs to several times what a pre-AI environment carried.

The session walks through the API fabric that AI agents create, why edge security tools built for north-south traffic miss the internal action layer, and where the real risk sits. Michael and Michael cite Salt research showing that 85% of companies planned to use AI agents by the end of 2025 and 18% run more than 500. They use a concrete example, an agent selling a car through a dealership, to show how the LLM, MCP server, payment, parts, and delivery services all connect through APIs, and where an attacker would target unauthenticated APIs, BOLA flaws, and shadow MCP servers.

Analyst context frames the stakes: Gartner projects that over half of API security breaches will connect to AI by 2028, and that 80% of organizations will see agents consume most of their API traffic. KuppingerCole notes that APIs now define business operations rather than just support them, and that regulations like the EU AI Act and GDPR make API security a requirement rather than an option.

The approach stays consistent: see your APIs, govern them with policy, and protect them in production. Salt Security created the API security category and built the OWASP API Top 10. The platform gives security teams visibility across cloud and hybrid environments, posture governance, and threat protection for the agentic action layer.

Run a free external attack surface assessment: https://salt.security/attack-surface

Speakers:

  • Michael Nicosia, Co-Founder and COO of Salt Security
  • Michael Callahan, CMO of Salt Security

Timestamps:

0:00 Why AI security needs API security

1:57 What changed: AI agents as your new employees

6:04 The API fabric explosion

9:51 East-west traffic and why the edge cannot see it

13:19 Agent-to-agent communication and the road ahead

14:00 How many companies deploy AI agents

15:41 The crowded AI security landscape

16:41 The action layer that model security misses

21:16 The brain, the spine, and the nervous system: how the pieces fit

22:55 The Chevy dealership $1 car chatbot

24:22 Selling a car through agents: the API interactions behind it

26:37 Where attackers find risk in the fabric

29:47 Why the risk skyrockets: attack surface, data leakage, ease of attack

31:11 What Gartner and KuppingerCole say

35:04 Solving it: see it, govern it, protect it

37:20 Summary: no AI security without API security

38:15 Q&A: healthcare adoption, hybrid cloud, and autonomous agent actions

45:03 Free resources and closing