Noma Security is extending its AI agent security platform to employee endpoints, giving enterprises a way to discover, govern and monitor AI agents, MCP servers and skills running on laptops alongside SaaS and internally built agents.
Noma Security is expanding its enterprise AI security platform to employee endpoints, targeting a growing blind spot as developers and business users install AI agents that can access corporate systems, data and credentials.
The company’s latest capabilities are designed to discover AI agents, Model Context Protocol (MCP) servers and agent skills running on employee machines, establish access policies for those assets and monitor their behavior at runtime. Noma says the same policy and context can follow an agent between endpoint, SaaS and internally developed environments.
The expansion reflects a broader change in enterprise AI security. Employees are increasingly using coding agents such as Claude Code, Cursor and Codex, while business users are adopting AI assistants that can interact with documents, browsers, SaaS applications and internal information. MCP servers and skills can extend those agents into databases, repositories and other enterprise systems.
That creates a security problem that traditional endpoint controls were not necessarily designed to address. An AI agent can inherit the permissions of the employee who installed it, potentially allowing it to read data or execute actions that would otherwise require deliberate human interaction.
Noma’s approach begins with discovery. The company says it can use existihttps://hrtechedge.com/ai-in-hr/knowbe4-study-shadow-ai-and-employee-pressure-emerge-as-top-cyber-risks-for-uk-businesses/ng endpoint detection and response (EDR) or mobile device management (MDM) infrastructure to identify agents, MCP servers, skills and connected accounts across managed devices. Those assets can then be assessed for risks including exposed secrets, excessive permissions and unsandboxed execution.
The discovery layer feeds into Noma’s Access Control capabilities, which provide a registry showing whether individual agents and tools are approved, require review or are blocked. Noma also associates agents with the human users behind them, allowing policies to be applied according to users, groups, tools or organizational requirements.
More granular controls can govern individual tools and actions. That distinction matters because an agent may need broad read access while more consequential operations—such as creating, modifying or deleting information—need tighter restrictions.
The approach aligns with emerging guidance around agent governance. Gartner predicts that by 2027, 40% of enterprises will demote or decommission autonomous AI agents because of governance failures discovered after production incidents. The research argues that organizations need different controls depending on an agent’s autonomy and the scope of its access.
Gartner has separately predicted that 25% of enterprise generative AI applications will experience at least five minor security incidents annually by 2028, compared with 9% in 2025. The research specifically identifies MCP adoption as a factor that could expand the attack surface of agentic AI systems.
The risk is not limited to malicious software exploiting a conventional vulnerability. Agents can be manipulated through prompt injection, compromised tools or malicious instructions embedded in data returned by connected systems. Gartner identifies agentic automation hijacking as an emerging cybersecurity threat because attackers can manipulate an agent’s behavior without necessarily compromising the underlying model.
MCP itself is becoming an important part of this security conversation. Microsoft has noted that while MCP standardizes how AI agents discover and use tools, the protocol does not inherently define how organizations should govern those tool calls. Its own work on MCP governance focuses on putting policy enforcement around tool execution.
Noma’s second layer is runtime protection through its AI Detection and Response (AI-DR) technology. Rather than examining individual actions in isolation, the system monitors agent sessions across prompts, tool calls, responses, data access and behavior.
The company says its detection capabilities can identify prompt injection, sensitive-data leakage, malicious intent, tool poisoning, scope violations and behavior that diverges from an agent’s intended purpose. Organizations can configure individual detections to monitor, alert, steer, block or mask sensitive data, with certain actions routed to human review.
This session-level approach is important because an agent’s individual actions can appear legitimate while becoming dangerous when chained together. A permitted database query followed by a series of tool calls could ultimately produce unauthorized data movement or destructive changes.
Google’s own security documentation for MCP-enabled agents similarly warns that autonomous agents can be exposed to prompt injection and insecure tool chaining, and recommends dedicated agent identities and least-privilege access.
Noma is positioning its endpoint capabilities as part of a wider security control plane. Its Open Enforcement model can apply policies through agent hooks, AI and MCP gateways, SDKs, APIs and existing EDR or MDM infrastructure. The company says the platform supports agents including Claude Code, Claude Cowork, Cursor, Codex, Windsurf, Kiro, Antigravity and OpenClaw.
The company previously introduced Agent Access Control for discovering and governing AI agents and MCP servers across enterprise environments. The endpoint expansion extends that model to where many agents are first installed and used: employees’ computers.
That shift could become increasingly important as enterprises struggle with AI agent sprawl. Gartner estimates that an average Fortune 500 company could have more than 150,000 AI agents in use by 2028, compared with fewer than 15 in 2025, while only 13% of organizations currently believe they have appropriate agent governance.
For security teams, the challenge is therefore moving beyond deciding whether an AI tool is approved. They need to know which agents exist, whose identity they operate under, what systems they can access and whether their behavior remains within defined boundaries.
Noma’s endpoint expansion is aimed at that control problem. Its success will depend on whether enterprises can use the additional visibility without creating excessive friction for developers and employees who increasingly depend on AI agents for everyday work.
The underlying security shift is clear, however: as AI agents move from chat interfaces into operating systems, codebases, databases and business applications, endpoint security is becoming part of the enterprise AI governance problem.
Market Landscape
Enterprise AI security is moving toward runtime governance, identity-aware access control and agent discovery as organizations deploy autonomous systems with increasingly broad permissions.
Gartner’s research indicates that agent governance cannot be treated as a binary approve-or-block decision. Controls need to reflect an agent’s autonomy, access and potential impact.
The competitive landscape includes AI security platforms, cloud providers, traditional cybersecurity vendors and emerging agent-security specialists. Microsoft, Google and other major technology providers are developing their own controls around agent and MCP security, while specialized vendors such as Noma focus on centralized visibility and runtime enforcement.
The key differentiator is increasingly likely to be context: knowing not only what an agent is doing, but who it represents, which permissions it has, what data it accessed and how a sequence of individually permitted actions creates risk.
Top Insights
- Noma is extending agent discovery, access control and runtime AI security from SaaS and homegrown systems to employee endpoints.
- The platform can identify agents, MCP servers and skills through existing EDR or MDM infrastructure rather than requiring another endpoint agent.
- Identity-aware policies can restrict individual tools and actions based on users, groups, organizations and agent permissions.
- AI-DR monitors complete agent sessions to detect threats that emerge through sequences of otherwise legitimate actions.
- Gartner expects agent sprawl and governance failures to become major enterprise challenges as autonomous AI deployment accelerates.
Join thousands of HR leaders who rely on HRTechEdge for the latest in workforce technology, AI-driven HR solutions, and strategic insights





