AWS Brings Security Guardrails to Agentic AI
AWS Puts Security at the Center of Agentic AI
Alan Shimel speaks with Gee Rittenhouse of AWS during Techstrong TV’s Black Hat 2026 coverage. The discussion focuses on agentic security and why AI agents require a different approach from traditional applications. Rittenhouse explains that AWS has treated security as a core priority from the beginning. As AI workloads move into production, that same focus now has to extend to agents, models, identity and policy.
Rittenhouse says AI became another workload for AWS customers, but it behaves differently from earlier cloud workloads. Customers started with proofs of concept and experimentation. As those projects moved closer to production, security became a much larger concern. That shift helped drive AWS offerings such as Amazon Bedrock and AgentCore.
Agentic Workloads Need Guardrails
The conversation explores what organizations need when they build and run AI agents. Rittenhouse says teams want to create agentic workloads without managing every piece of security plumbing on their own. They need identity, policy, gateways, sandboxes and governance built into the workflow. That is where agentic security becomes a practical requirement rather than a future concept.
AWS is focused on helping customers build agents safely and monitor them once they are running. Rittenhouse points to the need to understand whether agents are behaving within expected limits. Teams also need to watch for takeover risks, hallucinations and actions that could disrupt applications. In his view, the goal is to make secure development easier without slowing builders down.
Identity and Least Privilege Still Matter
Alan and Rittenhouse also discuss the security fundamentals that still apply. Rittenhouse says organizations should continue to “eat your security vegetables.” That means minimum privilege, short-lived tokens and strong identity controls remain important. These ideas are not new, but they become more urgent when agentic systems can act quickly and independently.
The discussion connects agentic security to familiar cloud security principles. Teams should start with limited access and expand only where needed. They should also use policy to define what agents can do. That approach helps organizations move faster while keeping the blast radius under control.
Governance Will Shape AI Adoption
Rittenhouse also addresses concerns about trust, autonomy and AI safety. He notes that the industry has faced major technology transitions before, including the move to cloud. Each shift created uncertainty at first. Over time, better controls, better platforms and better operating models helped teams adopt the technology with more confidence.
For enterprise leaders, the takeaway is clear. Agentic AI can create new value, but it needs strong governance from the start. Agentic security gives teams a path to build, run and monitor AI workloads with greater confidence. AWS is positioning identity, policy, observability and platform controls as key parts of that path.
Transcript
Hey everyone, welcome back to our coverage of Black Hat. We go nowhere. It was in the media room here.
They actually had a step and repeat they offered us, so we're now sort of official looking with our Black Hat background. But I'm really happy to have my next guest on. When they told me he was coming, I was excited.
It's my friend, Gee Rittenhouse. Gee, you may or may not know Gee, but when you hear his story, it's just an amazing story of the security industry. And Gee's with AWS now.
We're going to hear all about that. But Gee, welcome. It's great to have you here.
Thank you. I really appreciate the invitation. Not a problem.
It's my pleasure, as I said. Gee, give people your story. It's a great story.
Yeah. So I've been a long time tech person, all the way from Bell Labs, and then joining security with Cisco, leading the security business. Of course, that all moves to the cloud, so I went to SkyHigh and did that.
And then, it's always you get attracted to the cloud, so you have to go to the source. Right. And so a few years ago, I went to AWS to run the security business there, and just recently took a new role leading agentic security at AWS.
Could there be a hotter- ... part of security right now than agentic security? Yeah.
Now, it's a great story, but if you don't mind, I want to jump into this whole agentic security thing. Sure. Specifically with AWS, right?
AWS, look, I go to re:Invent every year. I go to a lot of their other regional and security related events. They have a great agentic story.
They recognized agentics early on. They did things like Bedrock, and they've recently actually started renewing some of the agentic offerings there. But when did agentic security, obviously it's risen now if they're giving- Yeah ...
this, your domain, to handle. But when do you think it really kind of hit critical mass for them? " Yeah, I think, first of all, let's take a step backwards.
Go ahead. From the very first line of code at AWS, security was job one, priority one. Absolutely.
Job zero. So from the hardware through the hypervisor, all the way up through the stack to protect workloads, we were focusing on security. And then, of course, AI just became another workload.
Yeah. Right? But, of course, that workload behaves a little differently than traditional ones.
Just a little bit. And so how to manage it, we saw customers kind of struggling with that, so we- Yeah ... created Bedrock.
And so now you have your models, it's all managed, you can swap things in and out. You don't have to do the plumbing. You can let AWS do that for you.
And that worked well. There was a lot of proof of concepts. Customers were playing around with it.
And then as it went to production, we started to really see the security focus coming in from our customers. Yeah. And then created Agent Core to help that- Yes ...
with a gateway, with identity- Uh-huh ... with policy, and it just kind of continues from there. Yeah.
I think that's a great way of looking at it, foundationally up, right? Look, we're at Black Hat. Agentic AI is probably the biggest thing here, obviously.
Yeah. Whether we're talking about securing agentic AI, harnessing agentic AI, protecting from agentic AI. You're in charge of this at AWS.
Yeah. What do you view your mission there in doing this? Yeah.
So we want to do two things primarily. The first one is to make sure that customers can build agents and agentic workloads securely, really easily. Okay.
They don't have to do all this complex stuff, just click a few buttons and then we build a secure environment. There's a sandbox, there's gateways, the identity is right, the policy is right. Just make that easy, the governance side- Piece of it ...
of that. People want to build agentic workloads, let's just do it safely. Then after that, of course, the attack surface is not zero, so we want to monitor that.
We want to be able to look at it and make sure that they're behaving correctly within the specs. No takeover, no hallucinations that could disrupt their applications. So let's, if you don't mind- Yeah ...
I want to take that down to the product level. Uh-huh. So let's look at the governance piece first, right?
Mm-hmm. Sort of registering your agent- Sure ... seeing what is happening.
I'm sure 90% of the people watching this have an AWS instance- Mm-hmm ... that's running. What's the product name for that?
Where do they go for that? What's the on-ramp, if you will? Yeah.
It is a journey for us. Right now, they go to it through many different services like IAM, IDC, Agent Core, Bedrock. But, we know that that can be problematic for our customers, so we are pulling it together into platforms.
Right. You saw this with Security Hub. Yes.
We extended Security Hub into a partner with Security Hub Extended. All of these are starting to come together into platforms, whether it's on the perimeter side, network security, all the way through the identity, registry, et cetera. Loving.
Let's take the second piece now, which sounds almost more frontier. I don't mean frontier model. Yeah.
But I see almost more cutting edge stuff. Yeah. Is that something that's coming together, coalescing as we speak?
Mm-hmm. Or if people watching this at home, anything they could do now? Yeah, so first thing Eat your security vegetables.
It's the same attack vectors, it's the same things. Less- Minimum privilege ... defenses.
Yeah ... short tokens that are short-lived. Never goes out of style.
Never goes out of style. So just do the things that we know from the very beginning. It makes life a lot easier.
Yeah. If you're going to have long-lived credentials, make sure they're MFA, all of that kind of stuff. Then the second thing, though, is to make sure that you're putting them and deploying them correctly.
So if you're going to have, I don't know, a restaurant reservation agent, you don't need Fable or the latest frontier model- No ... coupled to an untrusted source. Mm-hmm.
So scope the agent down correctly, making sure that the model is appropriate, making sure the number of tools are appropriate. So these are the things that are unique to agentic workloads- Yeah ... that kind of build on top of the usual posture management and things that you would find in a regular- I was just going to say that, yes, they're unique to agentic, but it's almost zero trust, right?
Yeah. You start at zero and- Yeah ... build just what you need and nothing more.
Just in time for a short amount of time. Yeah. Absolutely.
Now, look, we're here at Black Hat, and people at Black Hat are a little jaded, right? They're used to this stuff. But people watching at home, and they're tech people too, but they're hearing the stories about the Hugging Face incident and Anthropic got loose, and I got to tell you the truth, the feedback we're getting is it's really shaking people's confidence- Mm-hmm ...
in being able to govern, to- Mm-hmm ... use these agents safely. Mm-hmm.
What's your advice to them, G? What should people out here do? Look, we've gone through this many times in our industry.
It's true. Every time... The cloud, right?
That was the biggest thing ever. The internet, mobile. I remember, yeah.
And there's these transition periods where people are figuring it out and trying- Mm-hmm ... to understand what's going on. There are best practices and patterns emerging throughout the industry now around sandboxing, around guardrails, around minimum privilege.
All of those things are true. Some of the things that are unique, though, about AI, particularly in a corporate environment, is its use is being encouraged by the most senior levels of the organization. Mm-hmm.
And so people are experimenting on their laptops, which can then provide supply chain risk into your environment- Sure ... and trying to understand. So you can't protect what you can't see.
Always. So discovery, look at what the agents are doing, look at what they're supposed to be doing, and then adjust accordingly. I'm listening to you talk, and you mentioned when cloud-- I remember when the internet came out.
" Right? And it's the same thing here. Yeah.
It is. Don't leave your common sense and your good security hygiene that you've had for all these years at the door. Those rules still apply.
They do. They still apply. They do.
Now, the other thing I think people are dealing with is how many agents can I adequately manage, can I adequately track, can I adequately govern, right? I've got my frontier model agents. I've got agents from a lot of the SaaS apps that I'm using.
Everybody, it seems, wants to give me their agent, and then I have my own agents that I spin up. Mm-hmm. What's your advice to those people, G?
Do you just let it go or...? Yeah, I think about it slightly differently. Okay.
So instead of focusing on the agents, focus on the use cases. If you're putting an agent in an application or using an agent for development, we have SDLC, we have our processes, we have our app reviews. We have all of those things to keep a handle on what's going on inside of our environment.
And as a result, the lines of business and the developers will choose which agent is appropriate for their application, and we can challenge those assumptions. Again, if we feel it's over scoped, we can provide golden paths or paved roads- Sure ... so that they're using the right things, and all of that is good.
There is another class of user which AI has fundamentally opened up, and those are the non-technical people writing agents. They're writing no-code agents. Yeah.
They're doing all sorts of things on- Absolutely ... following YouTube or something on their laptops and trying to- They're asking the AIs themselves how to do it. Exactly.
And that's how they do it. That doesn't follow a process. Right.
That doesn't have an AppSec review and things like that. And so we have to then make sure that our environment is resistant to the things that people are bringing in there that may inadvertently cause some damage. Excellent.
Hey, I know you've got another event or thing to do here, so I want to be mindful of that. Two quick things. Number one, here we are in August.
In the blink of an eye, we're going to be back in Vegas here for re:Invent. Yeah. Sure.
Without giving too much, can we expect to hear more? I'm sure we're going to hear more on this at re:Invent. Yes, we will.
Yeah. Any ideas, hints, clues, a treasure map, something we can look at? Yeah, I would just say, look, this is a wide open space.
We take security and securing AWS workloads very seriously, but we also recognize that customers have workloads in other places. Yes. Right?
And so you'll see that our portfolio extends- Extends beyond Yes, very much so. That's excellent. Yeah.
Last thing, and it is an easy one, hopefully. For people who want to get more information about what AWS is doing with agentic and agentic security specifically- Yes ... what's their best place to-- I mean, we- Go to our blogs.
Go to blogs. Go to AWS Blogs. That has all the information.
Yes. Excellent. You heard it here.
G, thank you so much. My pleasure, Alan. I appreciate it.
Thank you so much. Love you here. We'll see you hopefully at re:Invent.
We'll be at re:Invent- Looking forward to it ... doing videos. Looking forward to it.
We'll have you there again. Enjoy. Thanks again.
Hey, we're here at Black Hat, Gee Rittenhouse, AWS. We'll be back with more.