Agentic AI Expands Enterprise Attack Surface, Forcing Security Deeper Into Infrastructure
As agentic AI systems drive rapid changes in cloud infrastructure, enterprises must move security enforcement from the network perimeter down to the virtualization layer to keep pace with increasingly automated threats.

The growing deployment of agentic AI is fundamentally reshaping how enterprises think about security, expanding the attack surface through constantly evolving cloud environments. Traditional perimeter-based defenses are proving inadequate against threats that move faster and more dynamically than legacy security tools can respond. This shift is compelling organizations to push security policy enforcement deeper into their infrastructure stack, specifically toward the virtualization layer, where controls can operate at scale without introducing performance bottlenecks.
According to Umesh Mahajan, vice president and general manager of the Application Networking and Security Division at Broadcom Inc., the window for delayed action has closed. "This is the time where you can't put off security any longer," he said. "'Oh, I got a perimeter firewall. I'm good.' No, no, no – not good. It can be bypassed. Now the security gurus or experts are saying, 'No, you can't take two years, three years. You have to deploy lateral security.'" Mahajan shared these insights during an exclusive interview with theCUBE's John Furrier at VMware Explore 2026, where he discussed how agentic AI reshapes the enterprise attack surface, zero-trust implementation strategies, and API security for Kubernetes environments.
Building zero trust into cloud infrastructure
Many organizations have accumulated security solutions over time without integrating them into a cohesive system, creating vulnerabilities at the boundaries between disconnected tools. Broadcom's strategy involves delivering an integrated software platform where security components share intelligence and context across the vDefend and Avi Load Balancer product families. "Our customers have bought multiple security products. They can't put it together," Mahajan explained. "It's like buying Swiss cheese. Yeah, you have pieces of security, but you have plenty of holes which people can drive through."
Performance constraints present another critical challenge. AI workloads generate substantial east-west traffic patterns that penalize any security inspection point introducing latency. To address this, Broadcom has embedded security enforcement capabilities directly into the hypervisor layer rather than relying on separate security appliances. This architectural shift represents part of a broader modernization of VMware's security offerings designed for AI-era threats, encompassing firewalling, intrusion detection, and intrusion prevention capabilities optimized for both throughput and low latency. "We are doing 75 terabits per vCenter cluster for firewalling. We are doing 17 terabits for IDS IPS, and the other aspect is also latency," Mahajan stated. "Because in AI workloads, latency matters, so our security is done at the hypervisor level."
Securing AI workloads demands continuous visibility into running systems and their resource consumption. Since agents and Model Context Protocol services operate transiently, administrators require real-time awareness of authorized resources and detection of unauthorized shadow IT deployments. This visibility requirement is becoming integrated into private cloud modernization initiatives, helping enterprises spot and contain unauthorized activity before it becomes a breach. "It has to be at the infrastructure level; it has to be at scale," Mahajan said. "Otherwise, when are you going to do it? Two years from now? By that time you'll be compromised."


