Not long ago, the biggest AI data security concern was employees pasting sensitive information into ChatGPT.
Now imagine a departing employee using a sanctioned AI application to review customer contracts and pricing data. The application is approved, but the employee is using a personal account, working with sensitive information, and asking AI to identify customer renewal risks. The app may be sanctioned, but the interaction isn't necessarily sanctioned.
Now take that same scenario one step further. An AI agent acting on the employee's behalf can retrieve customer data through Model Context Protocol (MCP), call enterprise tools, and pass information to another agent through Agent2Agent (A2A) , without the employee manually uploading a single file.
This evolution forces a fundamental shift in strategy. DLP can no longer focus solely on manual uploads; it must now protect what AI itself can access, retrieve, and share.
Where the New Data Risk Emerges
Securing agentic AI requires recognizing that data exposure no longer happens through front-door prompts alone. The risk has fractured across three distinct operational layers:
- Human to AI: Employees share source code, customer records, financial data, and other sensitive information with AI applications. The app is approved, but the account, intent, and data may not be.
- Agent to tool through MCP: MCP gives agents a standardized way to connect with enterprise tools and data. If a tool returns more information than the task requires, sensitive data can enter model context without a user ever explicitly sharing it.
- Agent to agent through A2A: As specialized agents collaborate, data traverses new trust boundaries. An agent with privileged access can retrieve sensitive information and pass it downstream to another agent operating in a different environment, often bypassing traditional perimeter controls.
Across all three layers, the underlying problem is the same: traditional security looks at the payload, but misses the context. It cannot tell what an agent is actually trying to do, why it’s doing it, or where that data will land next.
This is why data security must evolve toward Authority-Aware DLP, a dynamic approach that aligns data access with user identity, intent and context.. By evaluating user and agent identities alongside data sensitivity, destination, and business intent, security teams can finally answer the only question that truly matters in real time: Should this user, application, or AI agent be allowed to perform this action on this data?
That is how you move from blind blocking to precise control.
Security Has to Follow the AI Data Path
Putting Authority-Aware DLP into practice requires a security architecture that follows the actual path AI data takes at the speed of the workloads themselves.
Palo Alto Networks delivers this by embedding protocol-aware inspection natively across three critical layers of the enterprise footprint:
- Workforce and endpoints (Prisma Access): Secure AI usage and endpoint agents, with visibility and control over MCP connections and sensitive data flows.
- AI applications & agents (Prisma AIRS™ AI Runtime Security): Protect prompts, responses, MCP interactions, and agent-to-agent communications at runtime, helping teams scale AI securely.
- Enterprise infrastructure (Next-Generation Firewalls): Protect sensitive data across data centers, private clouds, and AI infrastructure as it crosses network and trust boundaries.
Together, these controls extend data protection across human-to-AI, agent-to-tool, and agent-to-agent interactions, helping enterprises accelerate AI adoption without losing control of their data.
Extend Zero Trust From Humans to Agents
For years, Zero Trust has focused on people: verify identity, limit access, and protect sensitive data based on context. AI agents now need the same discipline.
That means understanding agent identities and connections, limiting access to the data and tools required for a task, protecting sensitive context inline, and enforcing policy as information moves between agents.
The question is shifting from “What can this user access?” to “What can this agent access, and what is it authorized to do with the data?”
Protect Data at AI Speed
AI agents won't wait for a person to copy a file, approve a transfer, or click send. As agents take on more work, the volume and speed of enterprise data movement will only increase.
Data security has to evolve with it. Whether it's an employee interacting with a sanctioned AI app, an agent retrieving data through MCP, or agents exchanging information through A2A, approval at one layer should not imply trust at the next. Organizations need consistent visibility and control over sensitive data wherever AI accesses it, from the first prompt to an MCP tool call to the next agent in a workflow.
Ready to secure your AI agent data path? Talk to our data security expert today to audit your local agent footprint, inspect hidden MCP traffic, and enforce Zero Trust data protection across your entire AI ecosystem.