You Can't Have AI Security Without API Security: The Agentic Action Layer
AI agents run on APIs, and that is where most security programs have a gap. Salt Security Co-Founder and COO Michael Nicosia and CMO Michael Callahan explain why you cannot secure AI without securing the APIs underneath it. An AI agent uses an LLM to reason and an MCP server to broker calls out to other systems, and every one of those calls is an API interaction. Deploy one agent and the traffic multiplies. Deploy hundreds, and the internal east-west traffic climbs to several times what a pre-AI environment carried.
The session walks through the API fabric that AI agents create, why edge security tools built for north-south traffic miss the internal action layer, and where the real risk sits. Michael and Michael cite Salt research showing that 85% of companies planned to use AI agents by the end of 2025 and 18% run more than 500. They use a concrete example, an agent selling a car through a dealership, to show how the LLM, MCP server, payment, parts, and delivery services all connect through APIs, and where an attacker would target unauthenticated APIs, BOLA flaws, and shadow MCP servers.
Analyst context frames the stakes: Gartner projects that over half of API security breaches will connect to AI by 2028, and that 80% of organizations will see agents consume most of their API traffic. KuppingerCole notes that APIs now define business operations rather than just support them, and that regulations like the EU AI Act and GDPR make API security a requirement rather than an option.
The approach stays consistent: see your APIs, govern them with policy, and protect them in production. Salt Security created the API security category and built the OWASP API Top 10. The platform gives security teams visibility across cloud and hybrid environments, posture governance, and threat protection for the agentic action layer.
Run a free external attack surface assessment: https://salt.security/attack-surface
Speakers:
- Michael Nicosia, Co-Founder and COO of Salt Security
- Michael Callahan, CMO of Salt Security
Timestamps:
0:00 Why AI security needs API security
1:57 What changed: AI agents as your new employees
6:04 The API fabric explosion
9:51 East-west traffic and why the edge cannot see it
13:19 Agent-to-agent communication and the road ahead
14:00 How many companies deploy AI agents
15:41 The crowded AI security landscape
16:41 The action layer that model security misses
21:16 The brain, the spine, and the nervous system: how the pieces fit
22:55 The Chevy dealership $1 car chatbot
24:22 Selling a car through agents: the API interactions behind it
26:37 Where attackers find risk in the fabric
29:47 Why the risk skyrockets: attack surface, data leakage, ease of attack
31:11 What Gartner and KuppingerCole say
35:04 Solving it: see it, govern it, protect it
37:20 Summary: no AI security without API security
38:15 Q&A: healthcare adoption, hybrid cloud, and autonomous agent actions
45:03 Free resources and closing