← Back to list

Consolidate or Collapse: Why Multicloud is an Anti-Pattern for Agentic AI Security

The attack surface is expanding faster than defences can mature. With 80% of enterprises reporting shadow AI usage and only 25% having full…

Tom Croll · 2026-05-13 14:28 · 0 claps · 9.3 min read paywalled
#ai-security #agentic-ai #cybersecurity #infosec #data-security
Open on Medium ↗
Wiki topics: AGT · AI Agents 🔒 · Cybersecurity

Consolidate or Collapse: Why Multicloud is an Anti-Pattern for Agentic AI Security

The attack surface is expanding faster than defences can mature. With 80% of enterprises reporting shadow AI usage and only 25% having full visibility, the window for experimentation has closed. This is not a three-year transformation - it’s a 90-day sprint to August 2, 2026, when the EU AI Act becomes fully enforceable.

Summary

The explosion of agentic AI has rendered hybrid multicloud security strategies obsolete. To secure AI ROI and survive the 2026 regulatory cliff, cybersecurity leaders must ruthlessly consolidate platforms, networks, and talent.

Strategic Planning Assumptions

“By 2029, the CISO’s biggest threat will not be a hacker in a hoodie, it will be their own AI agents.”

  • By 2027, organisations deploying agentic AI without unified identity and runtime controls will see compromised AI agents surpass humans as the primary source of insider risk
  • By 2029, compromised autonomous agents will cause more financial damage than human-initiated external attacks

Key Findings

1. Multicloud complexity is now a security liability. Hybrid multicloud use is standard for more than 80% of organisations, driving customers to use 3rd party tooling to secure multiple IaaS and PaaS providers. However, third-party tools are insufficient to secure the exponential increase in complexity of multicloud agentic AI deployments, with 32% of organisations citing unsupervised data access by AI agents as a critical threat.

2. Shadow AI is everywhere. Visibility is not. End user LLM usage is not sufficiently safeguarded by traditional network security tools, leaving organisations exposed to increased risk of DLP and the use of unsanctioned ‘shadow AI’. Approximately 80% of enterprises report moderate-to-pervasive shadow AI usage, yet only 25% have full visibility into these tools, creating an unmanageable attack surface.

3. AI incidents aren’t waiting for regulation. Increased regulatory pressure from emerging AI regulations pose significant obstacles to delivering compliant AI systems. Meanwhile AI incidents are not waiting for regulation to catch up: 40% of organisations report inaccurate outputs, 27% data breaches, 26% regulatory action, 22% legal claims, all in the past 12 months.

4. Skills gaps compound every other challenge. Organisations continue to report severe security skills gaps, exacerbating the challenges of securing the corporate network, delivering production-ready agents and seeing return on their AI investments in 2026.

Recommendations

Cybersecurity leaders seeking to optimise AI security and ROI in 2026 must:

  1. Deliver secure, production-ready LLM technologies by consolidating agentic AI development to a single cloud service provider (CSP) and using the tightly integrated controls available in their unified development ecosystem.
  2. Block all unsanctioned AI usage and protect against data loss by deploying an AI aware SASE offering to inspect all network traffic, inventory all LLM usage and sanitise traffic using AI gateways.
  3. Replace traditional compliance with high-frequency assurance, including adversarial red teaming, continuous model monitoring and agent containment.
  4. Execute a comprehensive AI cloud security strategy by investing in senior expertise and scale with AI automation to ensure complex AI systems are deployed rapidly and in line with security best-practices and internal standards.

Analysis

Enterprises are transitioning from generative AI experimentation to production agentic AI deployments. Increased regulatory pressure, AI coding inefficiencies and a proliferation of high-profile cyberattacks are making multicloud strategies a security liability. Furthermore, they are prohibitively expensive for organisations competing in today’s financially constrained market.

“Prompt injection is SQL injection without parameters.”

Hybrid multicloud security strategies rely on poorly integrated platforms or siloed tool stacks that create dangerous blind spots, control gaps and require overly permissive roles to function effectively.

Consequently, reliance on decentralised, multicloud security technologies is currently not viable for agentic AI development.

The proliferation of technologies such as Model Context Protocol (MCP) servers, IDE-integrated coding assistants like Anthropic’s Claude Code, and unsanctioned web-based LLMs has created an attack surface that is impossible to secure without aggressive consolidation.

Cybersecurity leaders must abandon the illusion that they can secure fragmented AI deployments against the rapidly expanding AI threat landscape (see Figure 1). Instead, they must drive a ruthless consolidation strategy across platforms, networks, and personnel to secure agentic AI development, protect against unsanctioned LLM use and achieve Return on Investment (ROI) in 2026.

Fig. 1: The Enterprise AI Threat Landscape Heat Map showing specific technologies and their corresponding risk exposure

Fig. 1: The Enterprise AI Threat Landscape Heat Map showing specific technologies and their corresponding risk exposure

Why Non-Deterministic Threats Demand Architectural Simplicity

The technical threats from compromised agents and LLMs require deeply integrated defences. Prompt injection attacks are like SQL injection without parameters. Additionally, the non-deterministic nature of model behaviour means constant monitoring, regularly updated technical controls and strict containment is critical.

Because of this unpredictability, organisations must increase the cadence of their technical control validation, deploy continuous adversarial testing tools (see Figure 2) and enforce tightly integrated controls by aggressively consolidating their capabilities for building, using and protecting against internal and external AI threats.

Fig. 2: Addressing non-deterministic threats with continuous monitoring and testing

Fig. 2: Addressing non-deterministic threats with continuous monitoring and testing

Because of this non-deterministic nature (unlike traditional software), and increased blast radius, driven by machine-speed attacks and exacerbated by tool integrations (such as model context protocol (MCP) servers) you cannot secure them across fragmented, multi-vendor environments. You need the unified telemetry and integrated guardrails that only a single CSP currently provides.

In 2026, cybersecurity leaders should target, contain and eliminate multicloud agentic AI development and unsanctioned LLM use. The complexity of managing identities, data flows, and runtime guardrails across disparate environments poses existential risks for AI producing organisations.

Furthermore, for the vast majority of enterprises (except highly classified military or government entities), on-premises AI development is currently beyond their capabilities, creating a resource-draining operational burden. While building AI systems in private data centres offered optimal data sovereignty and model security three years ago - just as keeping your PII databases on-premises was considered the safest option ten years ago for cloud security - the landscape has fundamentally shifted.

Most of the security challenges of public cloud adoption have been overcome, however agentic AI development poses a new threat, making organisations reluctant to move sensitive data into shared infrastructure environments.

CSP Native Guardrails Available Today:

  • GCP Model Armor
  • AWS Bedrock Guardrails
  • Azure Foundry Content Filters

Integrated AI gateways and firewalls are now standard across the major IaaS and PaaS providers, providing native guardrails for input and response sanitisation to protect against threats such as prompt injection attacks, jailbreaking and unsafe content generation. Additionally, further advances in identity management, data security and supply chain monitoring now make unified CSP development ecosystems the safest option for agentic development.

To achieve tangible Return on Investment (ROI) for internal LLM and agentic AI development in 2026, cybersecurity leaders must abandon fragmented architectures and commit to aggressive consolidation and CSP-native agentic development environments.

Consolidate Agentic AI Development onto a Primary Cloud Platform

Fig. 3: Integrated security and monitoring controls are critical to contain agentic AI threats

Fig. 3: Integrated security and monitoring controls are critical to contain agentic AI threats

Cloud service providers (CSPs) like GCP, AWS, and Azure now have sufficiently mature native capabilities to ensure end-to-end visibility and integrated security for production-ready agentic AI development (see Note 1 for detailed comparison).

Using native features (like GCP Agent Identities or AWS Guardrails) and built-in AI-SPM capabilities provides a seamless, cryptographically verifiable, tightly-contained ecosystem (see Figure 3). Conversely, attempting to bolt on third-party security tools to manage multicloud AI development leaves enterprises vulnerable to control gaps and exposed to the risk of compliance failure.

“In 2026, the benefits of integrated agentic AI security features outweigh the risks of CSP vendor lock-in.”

In 2026, the benefits of automated identity management services, such as managed certificates and seamless native integration outweigh the risks of CSP vendor lock-in. Successful organisations will use these capabilities for delivering production-ready agentic AI models to achieve ROI in AI spend this year.

Decision Matrix: Infrastructure & Development Strategy

Cybersecurity leaders should use the following decision matrix to determine their infrastructure and development strategy.

Consolidate Network Security Using a Single SASE Provider

Fig. 4: Route traffic from multiple managed and unmanaged devices through a single SASE to identify and secure AI traffic

Fig. 4: Route traffic from multiple managed and unmanaged devices through a single SASE to identify and secure AI traffic

While CSP consolidation secures machine-to-machine AI development, human-to-machine AI usage requires a different consolidation strategy at the network edge.

Modern SASE platforms have rapidly integrated AI security capabilities, claiming to enable the detection and control of enterprise AI usage and secure genAI usage. SASE is highly effective at identifying shadow AI, blocking access to unapproved web-based LLMs, and preventing sensitive data from being uploaded to cloud-hosted LLMs like ChatGPT or Grok. Combined with their sophisticated capabilities for protecting against increasingly advanced AI-driven external attacks, they form an essential part of your AI threat defense armoury.

However, cybersecurity leaders must exercise caution.

Do not rely on these SASE technologies to provide sufficient preventative controls for hybrid agentic AI development. While SASE excels at end-user access control, it is currently too immature to inspect and secure complex, automated agent-to-agent (A2A), app-to-LLM communications or API-driven MCP server interactions and hence cannot be relied upon to enforce reliable controls across multicloud agentic AI deployments.

Unless your organisation is mandated to use private cloud infrastructure (e.g., highly secure government environments), avoid relying on controls at the network perimeter and use preventative controls for agentic AI interactions within the chosen IaaS/PaaS provider’s native security stack, protected by inline security proxies (e.g., GCP Model Armor, AWS Guardrails or Azure Content Filters), and tightly bound permissions using x509 certificates (e.g., GCP Agent Identities).

Use AI-aware SASE tools as an additional defence-in-depth layer at the network edge for insider threats and external attacks.

Three-Layer Defence Architecture

A single SASE provider should be used to create a three-layered, defence-in-depth strategy and route all corporate traffic through secure proxy layers (see Figure 5):

Layer 1: AI Gateway: The central control plane for all LLM traffic. It handles authentication, logging, and intelligent routing.

Layer 2: AI Firewall: This layer performs deep inspection of prompts and responses, sanitisation, threat detection, and sensitive data redaction.

Layer 3: AI Security Posture Management (AI-SPM): This aims to provide continuous governance of all AI models and agents, including discovery, vulnerability scanning, and compliance monitoring.

All traffic, whether from humans, applications, or agents, must pass through all three layers before reaching any AI resource.

Fig. 5: The Enterprise AI Threat Landscape. SASE is critical for containing Shadow AI, but native CSP controls are required for MCP and Agentic AI risks.

Fig. 5: The Enterprise AI Threat Landscape. SASE is critical for containing Shadow AI, but native CSP controls are required for MCP and Agentic AI risks.

Decision Matrix: End-User AI Access & Network Security

Action Plan: 5 Steps to Ensure AI ROI in 2026

“The window for experimentation has closed. This is not a three-year roadmap. This is a 90-day sprint.”

Cybersecurity leaders must enforce a default-deny posture for unsanctioned internal LLM use and agentic AI development by executing the following 90-day plan:

Step 1: Consolidate AI Development onto a Single CSP

Standardise your agentic AI development on a single major cloud provider (e.g., GCP, AWS, or Azure). Use their native AI-SPM, KMS, and identity frameworks (like GCP Agent Identities or Azure Blueprints) to eliminate the integration gaps inherent in using third-party security tools.

Step 2: Standardise End-User Access via a Single SASE Provider

Route all employee traffic through one comprehensive SASE platform to gain maximum visibility and enforce strict DLP policies on external AI applications like ChatGPT, Grok, and Abacus ChatLLM.

Step 3: Halt On-Premises AI Development

Cease all self-hosted or multicloud AI development. Accept CSP lock-in as a tactical advantage that provides managed certificates, seamless integration, and faster time-to-market, treating on-premises AI as a legacy anti-pattern (except in specific top secret environments).

Step 4: Enforce High-Cadence Control Testing

Treat AI vulnerabilities, such as prompt injection attacks as non-deterministic, parameter-less threats. Shift from periodic penetration testing to continuous, high-frequency adversarial attack simulations and AI red teaming as mandated by new standards, such as AIUC-1.

“3 senior architects + AI automation < 1 catastrophic breach. M&S alone lost £300M.”

Step 5: Consolidate the Talent Strategy

Eliminate over-reliance on fragmented, costly outsourced security services, which lack the context to manage AI-driven threats. Instead, reinvest those budgets into a smaller, centralised team of seasoned security architects, scaling their output using AI automation.

Conclusion

Fragmented, ‘best-of-breed’ security tooling and distributed multicloud architectures are incompatible with the speed and scale of secure agentic AI development. To realise AI security and ROI in 2026, security leaders must invest in aggressive consolidation programs.

By committing to a single cloud service provider (CSP) for agentic AI development and a unified SASE platform for end-user access, enterprises eliminate the dangerous control gaps inherent in multicloud development which are monitored by poorly integrated third-party platforms or multiple point offerings.

Furthermore, organizations must operationalize this architecture by using experienced, AI-augmented talent to enforce continuous, agentic AI controls, adversarial testing against non-deterministic threats and elimination of unsanctioned LLM use.

In 2026: architectural simplicity; native integration; scaled, experienced resources; and high-cadence testing are the ultimate competitive advantages.

This article was originally published in February 2026

Note 1: CSP Agent Security Controls Comparison and Guidance


메타데이터
post_id
2a2dcfa51235
slug
consolidate-or-collapse-why-multicloud-is-an-anti-pattern-for-agentic-ai-security-2a2dcfa51235
url
https://medium.com/@tomcroll/consolidate-or-collapse-why-multicloud-is-an-anti-pattern-for-agentic-ai-security-2a2dcfa51235
canonical_url
https://medium.com/@tomcroll/consolidate-or-collapse-why-multicloud-is-an-anti-pattern-for-agentic-ai-security-2a2dcfa51235
author_url
https://medium.com/@tomcroll
status
ok
fetched_at
2026-07-10 16:32:07