verifiedagents.ai
All posts

7 min readAI Agents · Cybersecurity

Check What You Already Own Before Buying AI Security

By Josh Woodruff, Founder & CEO, MassiveScale.AI | Founding Chair, Agentic Trust Framework at the CSAI Foundation

Hero: Check What You Already Own

TL;DR: Teams shopping for AI security products usually own a big share of what they're about to buy, sitting unconfigured in licenses they pay for annually. Map your real missing controls first, turn on what you already bought, then buy narrowly against what's left, on the shortest contract you can get.

Last updated October 6, 2026. I rebuilt this piece from the ground up around the buying sequence, because the order of operations is the whole trick.

A security leader walked into a call ready to evaluate AI security vendors. Partway through, a different question surfaced: what can we do with what we already have? They were a Microsoft shop with a high-tier license and a data governance rollout half finished. A meaningful chunk of the capability they were about to shop for was already paid for and switched off. That's not an unusual situation. It's closer to the default.

Why do teams reach for a new tool first?

Because a new category feels like it needs a new product. AI security arrived fast and loud, with a vendor landscape, an analyst category, a dedicated budget line, and a conference floor full of booths. When something gets framed as a new problem, the natural response is to find the thing built for it.

The existing stack doesn't market itself that way. Your identity provider isn't running ads about agent governance. Your data classification tooling isn't positioned as an AI control. So the capability sits there, described in the language of the last problem it was bought for, and nobody connects it to the new one. There's a budget dynamic underneath too: configuring something you own produces no line item and no project, while buying something produces both, and both are easier to point at when someone asks what you're doing about AI risk.

What's usually already in the stack?

Where it sits

What you probably already own

The AI question it answers

Identity and access

Conditional access, risk-based policies, service account visibility at higher license tiers

The foundation of agent governance, because an agent is an identity holding credentials

Data governance

Classification and loss-prevention tooling bought for compliance

What can this agent reach, and what happens if it leaves

Network and endpoint telemetry

Egress visibility you already collect

The cheapest way to find shadow AI and count the agents you already have

Most of the AI-specific products in this space add a layer on top of exactly these primitives. None of this means the stack is sufficient. It means the honest starting question is which missing controls are real, not which product is best.

What does "buy narrowly" mean in practice?

Buy against a named missing control, not a category. The version that works: write down the specific thing you can't do today, in one sentence, with evidence. "We can't tell which applications are calling model providers directly, and here's the log comparison showing the blind spot." Then evaluate products against that sentence. The version that goes badly: buying a platform because the category exists, then discovering 70 percent of it overlaps what you own and the remaining 30 percent is what you actually needed. Narrow purchases are also easier to unwind, which counts more than usual right now. The full vendor script is in evaluating AI security vendors when nobody can vouch.

Why do short contracts count more this year?

Because the vendors themselves are moving underneath the evaluation. One client was mid-evaluation on a product when the company was acquired by a major AI lab, and the roadmap they were buying stopped being the roadmap. Consolidation is running fast, so a two-year commitment to a startup in a hot space is a bet on the acquirer's priorities as much as the product.

The practical guidance: shortest feasible term, and prefer capabilities you can migrate off. If the product becomes the only place a control lives, an acquisition becomes your problem instead of the vendor's. This isn't an argument against buying from young companies, where plenty of the useful work is happening. It's an argument for pricing the risk into the contract length. And budget time for peer validation, because in a category with no track record, a trusted peer running the product at your scale is the only signal with real information in it. Vendor-arranged references don't substitute. Neither does a demo, especially given how much of the market is agent washing.

Where does Zero Trust fit?

Zero Trust is the foundation, and it's usually the part of the stack that's furthest along. It verifies every request against identity, device, posture, and behavior signals, continuously and per request. Those investments carry straight over to agents: same identity, same policy engine, same enforcement points.

What agents add is a need for a defined identity underneath and a view of the sequence on top. A single agent request can pass every check while the run of fifty requests around it adds up to something nobody approved. That sequence view is the missing control worth buying against, if you can't close it with what you own. Framed that way, "return on your existing investments" isn't a way to avoid spending. It's how you find out what to spend on.

What does this look like at small scale?

My own lab runs four agents on a dedicated Mac Studio: Atti orchestrates, Forge codes, Scout researches, Quill writes. When Forge routed around its sandbox and ran unmonitored for two hours, my instinct was to go find monitoring. What actually closed the hole was configuration: a defined tool scope, written down, with a review required to change it, using tooling that was already there.

No purchase would have fixed it, because the problem wasn't missing capability. It was a decision that had never been recorded anywhere, which is the same reason every agent needs one accountable human with the scope written next to their name. Tools enforce decisions. They don't make them, and buying one before the decision exists just adds a dashboard to the confusion.

What can you do this week?

  1. Pull your license entitlements.

    The actual SKU list, not what you remember buying. Most teams find capabilities they're paying for and haven't enabled.

  2. Write down three real missing controls.

    One sentence each, with evidence. If you can't produce evidence, that's a visibility problem, and it's cheaper to fix than a control problem.

  3. Map the list against the entitlements.

    Anything covered by something you own goes on a configuration list, not a purchase list.

  4. Cap contract length on anything left.

    Shortest feasible term, and check what happens to your control if the vendor gets acquired.

  5. Find one peer running what you're considering.

    Not a vendor-arranged reference. Someone you'd believe if they said it wasn't working.

Frequently asked questions

Should I buy an AI security tool or extend what I have?

Map your missing controls first, then check them against your existing entitlements. Anything your current stack covers belongs on a configuration list. Buy only against what's left, and only where you can state the shortfall in one sentence with evidence.

What existing tools help with AI agent security?

Identity platforms at higher tiers provide conditional access and risk-based policy, plus service account visibility, which together are the foundation of agent governance. Data classification answers what an agent can reach. Network telemetry surfaces unsanctioned AI use.

How long should an AI security contract be?

The shortest feasible term. This category is consolidating fast, and one client had a product acquired by a major AI lab mid-evaluation. Prefer capabilities you could migrate off, so an acquisition doesn't become your problem.

What if I can't tell what I'm missing?

Then that's your first finding, and it's a visibility problem rather than a control problem. Fixing logging and inventory is cheaper than any platform, and no purchase compensates for not knowing what your agents are doing.

Key takeaways

  • Teams shopping for AI security frequently own a large share of the capability already, unconfigured, in licenses they renew annually.

  • The unused capability clusters in identity and data governance, plus network telemetry, all labeled for the last problem instead of this one.

  • Buy against a named missing control with evidence attached, never against a category.

  • Keep contracts short, because a multi-year commitment in a consolidating market is partly a bet on a future acquirer.

  • Tools enforce decisions. They don't make them, so record the decision before you shop for the dashboard.

The fastest way to name your real missing controls: the free self assessment takes about ten minutes and scores you across all five framework elements.

The teams getting this right aren't spending less. They're spending later, against shortfalls they can name, on terms they can exit, and that sequence survives an acquisition and a budget review. It also survives the auditor asking why the line item exists.

See where your agents stand.

The free assessment takes ten minutes and scores you on the five elements of the Agentic Trust Framework.