AI News Feed
Market watch
Cybersecurity

Broadcom: Network and identity controls are key to stopping shadow AI before deployment

Broadcom executives at VMware Explore stressed that securing agentic AI before deployment requires network and identity controls, unveiling AgentMinder to catch shadow AI via the packet path.

“If you don’t have security, you really can’t go deploy agentic AI,” Mahajan said. “First, you have to make sure that the agentic AI workloads don’t get compromised from the outside. Then, we see the agentic AI workloads can themselves go rogue and start attacking outwards, so you need security both inwards and outwards.” Mahajan and Donley explained that the packet path, or the network traffic layer, has become the place to discover and stop shadow AI — unauthorized agents, models or Model Context Protocol servers that appear without oversight.

Donley noted that while the industry has spent decades managing employee and customer access to systems, “we’ve had about 15 minutes to figure out how to do it for AI agents,” and the growing autonomy of these agents makes the problem more urgent. Broadcom’s answer includes AgentMinder, which combines signed agent identities with runtime inspection of application programming interface traffic and observability. Sitting in the packet path allows the network tier to spot MCP servers, agents and models, and flag those that are unauthorized as shadow AI, Mahajan said.

Mahajan also emphasized that customers often struggle when forced to merge separate security products into a cohesive system. “If we make a customer stitch together multiple products, they have an awful time; they make mistakes,” he said. “Having a curated security stack completely from Broadcom goes a long way in securing them.” The executives’ remarks came during VMware Explore coverage, part of theCUBE’s live broadcast from the event.