The agentic frontier: A CIO’s guide to securing autonomous AI Nearly 90% of IT leaders have already experienced security incidents tied to AI pilot programs, according to industry data cited in a CIO guidance piece from HPE and NVIDIA. HPE and NVIDIA outlined three measures for securing autonomous AI agents in production: a silicon-level root of trust, zero-trust identity for non-human actors, and real-time behavioral guardrails. The guidance argues that over-privileged agents and prompt injection attacks expand the enterprise attack surface beyond traditional security frameworks. While first-wave AI was largely conversational—chatbots that summarized documents or drafted emails—the second wave is operational. AI agents are autonomous entities capable of reasoning, planning, and executing multi-step workflows. They don’t just tell you that your inventory is low. They negotiate with suppliers, update ERP systems, and optimize shipping routes without human intervention. However, this autonomy introduces a paradox. The more useful an agent becomes, the more dangerous it can be if compromised. While we can add humans-in-the-loop, when agents gain the power to act on behalf of the enterprise, they expand the attack surface beyond traditional security frameworks. In fact, current industry data suggests that nearly 90% of IT leaders https://www.gravitee.io/blog/state-of-ai-agent-security-2026-report-when-adoption-outpaces-control have already experienced security incidents related to AI pilot programs. To move to a production-ready AI factory, CIOs must move beyond wrapper security and embrace a framework of sovereign AI. HPE and NVIDIA have identified three ways to secure the agentic enterprise: Establishing a silicon-level root of trust, implementing zero-trust identity for non-human actors, and deploying real-time behavioral guardrails. 1. Building on a silicon root of trust Security for autonomous agents cannot exist solely at the software or application layer. If the underlying infrastructure is compromised, every decision the agent makes—and every piece of data it touches—is at risk. In an era where model poisoning and firmware hijacking are real threats, security must be anchored in the hardware itself. The vulnerability of “black box” infrastructure Many organizations began their AI journeys in the public cloud. While convenient for training, the public cloud often limits visibility into the physical security of the stack. For AI agents handling sensitive intellectual property or regulated customer data, this lack of control is a liability. The solution: Hardware-enforced integrity The foundation of a secure AI agent is a silicon root of trust. Through HPE servers—specifically optimized for NVIDIA’s Blackwell architecture—security is embedded directly into the motherboard. 2. Zero trust governance for the “agentic identity” The second major security hurdle for CIOs is the identity explosion. We are rapidly approaching a reality where there are more AI identities in a corporate network than human identities. Unlike human employees who have predictable working hours and clear organizational charts, AI agents can spin up thousands of sub-tasks and API calls in seconds. The risk of over-privileged agents Most AI agents are currently overprivileged. Developers often grant agents broad read/write access to databases so they just work. However, if an agent is compromised via a prompt injection attack—where a malicious user tricks the AI into ignoring its original instructions—that agent can become an internal threat, exfiltrating data or deleting critical records. Implementing a “least privilege” framework To secure these entities, CIOs must treat AI agents as high-privilege users, subject to the same zero-trust principles as any human executive. 3. Real-time behavioral monitoring and guardrails Unlike traditional software, which is deterministic Input A always leads to Output B , AI agents are fluid. They reason their way toward a goal, and that reasoning can occasionally lead to hallucinations or jailbroken behavior. Beyond static firewalls A traditional firewall cannot stop an AI agent from accidentally leaking trade secrets during a negotiation. Securing agents requires a new category of active security that monitors the intent and output of the AI in real-time. Set agent guardrails As part of the HPE AI Factory ecosystem, developers can set agent guardrails. The strategic path forward: Building a secure AI factory For the CIO, the goal isn’t just to “secure AI”—it’s to build a resilient, scalable, and secure AI factory that fuels business growth. Securing AI agents shouldn’t be seen as a bottleneck. It is actually the primary enabler of speed. When the business knows that its agents are running on a silicon root of trust, governed by zero trust identities, and protected by real-time guardrails, they can innovate with confidence. The partnership between HPE and NVIDIA provides the full stack of HPE AI Factory solutions designed for this new reality. By combining HPE’s decades of experience in secure, hybrid infrastructure with NVIDIA’s world-leading AI software and hardware, we are giving CIOs the tools to lead the agentic revolution safely. Conclusion: The 90-day mandate The window for experimental AI is closing. As your competitors begin deploying autonomous agents into their supply chains, customer service, and R&D labs, the security of those agents will become your most significant competitive advantage. In the next 90 days, CIOs should prioritize three actions: The future is agentic. Let’s make sure it’s secure. Learn more about the HPE Sovereign AI Factory https://www.hpe.com/emea europe/en/ai-factory/sovereign-ai.html . As AI becomes increasingly central to economic competitiveness, scientific advancement, and national priorities, organizations require infrastructure that balances performance with security and sovereign control. Together, HPE and NVIDIA co-engineer rack-scale AI systems that integrate AI computing, high-performance networking, and supercomputing expertise to support large-scale AI workloads. This provides enterprises, governments, and research institutions with a trusted foundation for sovereign AI initiatives while maintaining control over critical data, models, and operations.