For years, the security industry has largely built around the idea of the security agent. Install an agent. Keep it running. Collect telemetry. Send the data somewhere. Analyze it. Generate an alert. Investigate. Respond.
The architecture is understandable because the infrastructure it was designed for was comparatively understandable. Servers were relatively persistent. Applications followed predefined execution paths. Security policies could be defined ahead of time. Human analysts remained central to investigation and response. Compute was treated as abundant enough that security software could maintain a substantial presence across the environment.
That world is changing.
Cloud infrastructure is increasingly ephemeral. Kubernetes has become a dominant operating layer. AI workloads are becoming operationally significant. AI agents can execute multi-step workflows across systems. Machine identities vastly outnumber human identities. And software is increasingly capable of adapting its behavior based on what it discovers at runtime.
CNCF's 2026 Annual Cloud Native Survey reports that 82% of container users run Kubernetes in production, while 66% of organizations hosting generative AI models use Kubernetes for some or all inference workloads.
Sysdig's 2025 usage research found that 60% of containers in its dataset lived for one minute or less, while workloads using AI/ML packages grew by 500% year over year.
At the same time, AI agents are introducing a new operational model. Google Cloud's 2026 research found that 83% of surveyed organizations said they need infrastructure upgrades to support production-grade agentic AI, while 79% of technology leaders identified security, governance or operations as a major challenge to scaling inference.
The infrastructure is becoming more dynamic. The workloads are becoming more autonomous. The attack surface is becoming more interconnected. And security is still frequently designed around the assumption that the best answer is to put another permanent sensor everywhere.
The security agent was designed to observe a relatively static world.
The next generation of infrastructure requires a security system that can adapt to a dynamic one.
The security agent was an important abstraction
The security agent solved a real problem. It brought security closer to the workload. Instead of relying exclusively on perimeter controls, organizations could place software directly on endpoints, servers and workloads.
But the model also introduced an architectural assumption: Every protected workload should maintain a relatively persistent security presence.
That assumption becomes increasingly expensive as infrastructure scales. 100,000 workloads requires 100,000 security agents. The security footprint scales linearly with the infrastructure footprint.
Datadog's 2026 engineering analysis of eBPF-based workload protection makes this tradeoff explicit. The company describes CPU and memory consumed by the user-space agent, additional kernel-level overhead, and the need to benchmark security instrumentation under real production loads.
A security agent is an execution component. A security system is a control architecture.
The environment has become a moving target
The infrastructure ecosystem has continuously evolved to abstract away static hardware.
NIST describes Moving Target Defense (MTD) as an approach in which the defender changes aspects of the environment to increase uncertainty for attackers.
Can we change the defender's observation pattern so that an attacker has a harder time learning where and when security is strongest?
The Three Assumptions That Are Breaking
Assumption 1: The environment is relatively stable.
Modern cloud infrastructure is not. Containers are created and destroyed. Nodes scale. Workloads migrate. Identities rotate. Networks change. Services appear and disappear. AI inference infrastructure can scale according to demand.
Assumption 2: The execution path is relatively predictable.
Autonomous agents challenge this assumption. An agent may observe, reason, call a tool, observe the result, change strategy, and call another tool. The next action is not necessarily predetermined.
Assumption 3: More observation is always better.
More observation can increase visibility. But it also increases compute, memory, telemetry, storage, analysis, latency, and cost. The optimal security system therefore cannot simply maximize observation. It must optimize useful observation.
Randomness is not the point
There is an important distinction between random security and unpredictable security. Randomly selecting workloads without context would be a poor security strategy.
Security-game research (like Stackelberg Security Games) has studied precisely this problem: defenders have limited resources, attackers can observe defensive patterns, and randomized strategies can allocate resources in ways that make attacks harder to optimize against.
Adaptive Security Density
Imagine 10,000 workloads. A traditional architecture might attempt to maintain approximately equivalent security instrumentation across all of them.
Most workloads do not need maximum defensive computation at every moment. But any workload can potentially earn more security attention when its state changes.
Security computation therefore becomes proportional to risk state, not merely workload count. This is Adaptive Security Density, enforced by what we call Special Forces.
The Capability Delta
A workload has an expected capability envelope. The executable might be unchanged. But the workload has become capable of doing substantially more. The question becomes: What changed? Why? And what can this new capability enable next?
Before
- ✓ Read model
- ✓ Call inference API
- ✓ Read dataset
- ✗ Shell
- ✗ External network
- ✗ Kubernetes API
After
- ✓ Read model
- ✓ Call inference API
- ✓ Read dataset
- ✓ Credential access
- ✓ Shell
- ✓ External network
- ✓ Kubernetes API
Events are not enough
A file access is normal. A network connection is normal. A shell is normal. The security signal is no longer necessarily any individual event.
MITRE ATT&CK's detection strategies increasingly describe behavioral chains and temporal relationships between events rather than relying only on isolated indicators.
The objective becomes attack-chain interruption, not alert generation. The sequence is the signal.
The Execution Boundary
AI makes this particularly important. An AI model can reason. An agent can choose. A tool can expose capability. But eventually something must execute.
Google Cloud's 2026 agent-governance research describes agents as systems that are granted access to databases and APIs and argues for stronger governance around dynamic permissions.
The implication is important: AI security cannot depend entirely on understanding AI intent. The machine's execution is observable.
The Resource Problem
Runtime security consumes resources. AI infrastructure makes this more important. Security is now competing for the same compute that AI needs to operate.
The Casino Model
Imagine N workloads, but only K deep-inspection resources, where K << N. Rather than permanently maintaining maximum inspection everywhere, the system can allocate deep inspection dynamically. Security does not need to be equally dense everywhere.
Asynchronous Observation
Continuous baseline monitoring remains useful. But deep inspection does not need to be perfectly synchronized with the workload's ordinary execution path. The defender can observe independently of the workload's expected timeline.
The defender does not need to follow the attacker's timeline.
Distributed, not fragmented
A security system can be distributed without being fragmented. Security resources exist close to workloads. Security state can be correlated across the environment. Critical decisions can happen close to execution.
Distributed execution. Coordinated intelligence. Local control.
The Opsonance System
SENTINELS
Observe and enforce.
SYNAPSE
Maintain local security state.
NEKRON
Reason across context, capability and attack paths.
SPECIAL FORCES
Concentrate security resources where risk demands them.
The New Control Loop
The future of runtime security is not more security software.
It is a more intelligent security system.
The security agent was an important stage in the evolution of runtime defense. It brought visibility closer to the workload. But modern infrastructure has become too dynamic, too distributed and increasingly too autonomous for security to be understood as a collection of permanently installed sensors.