Autodesk, Inc.

NASDAQ Global Select
Somewhat Bullish +50

Autodesk taps Permiso Security to monitor AI agents across its cloud and workforce

πŸ€– Autodesk has partnered with Permiso Security to launch a new platform for monitoring AI agents across its cloud and workforce environments.

πŸ” The partnership focuses on runtime security, providing continuous visibility into agent activity including tool calls and data access.

🌐 Permiso's solution extends its unified identity platform to cover autonomous agents operating in both managed and shadow IT environments.

πŸ‘€ Sebastian Goodwin, Autodesk's chief trust officer, noted that Permiso was their existing identity security partner, making the collaboration a natural next step for agentic AI identities.

⚠️ Jason Martin of Permiso highlighted that most security teams cannot currently answer basic questions about running agents, such as how many exist or what tools they use.

🧠 Permiso argues that traditional identity providers lose visibility once an agent authenticates, whereas their approach treats agents like humans by attributing every action to a specific identity.

πŸ›‘οΈ The platform offers six key capabilities including discovery, runtime attribution, observability, anomaly detection, behavioral sandboxing, and identity-first controls.

βš–οΈ These features are designed to address deterministic security measures on non-deterministic AI brains that may perform unauthorized actions.

πŸ”’ Security research from Permiso's P0 Labs informed the platform against threats like LLMjacking attacks and cross-prompt injection vulnerabilities.

πŸ“‘ The new capabilities are available immediately via an agentless, API-based architecture that requires no infrastructure changes.

Bullish Signals
  • Autodesk has signed on as the launch customer for Permiso Security's new AI agent runtime security capabilities, validating the strategic importance of securing agentic AI identities.
  • Autodesk is investing significantly in AI across its workforce, infrastructure, and products, signaling strong commitment to the company's artificial intelligence strategy.
  • The new solution offers no-infrastructure-change deployment via an agentless API-based architecture, allowing Autodesk to rapidly integrate advanced security without operational disruption.
  • Permiso's platform provides continuous visibility into every agent activity, enabling Autodesk to track tool calls and data access in real-time across its cloud and on-premises environments.
  • The collaboration leverages Permiso's P0 Labs threat research, including documented LLMjacking attacks and cross-prompt injection vulnerabilities, to proactively protect Autodesk's critical assets.
Risk Factors
  • Autodesk is facing significant reputational and operational risks as it rapidly deploys AI across its workforce and products without fully governing the fastest-growing, least-regulated identity class in the enterprise.
  • The industry faces a critical visibility gap where most security teams cannot answer basic questions about agent count, tool calls, or data access, increasing the likelihood of unmonitored autonomous decisions.
  • There is an inherent instability risk described as 'putting a deterministic capability on a non-deterministic brain,' where AI agents may perform actions they were not explicitly programmed to do.
  • The ecosystem is already circulating documented threats such as LLMjacking attacks, cross-prompt injection vulnerabilities in enterprise copilots, and malicious agent skills available on public marketplaces.
  • Security relies heavily on runtime detection of over-privileged access and policy violations, which suggests a high risk of anomalous tool usage occurring before human intervention can stop it.
Full Analysis
Autodesk has become the inaugural launch customer for a new suite of runtime security capabilities from Permiso Security, specifically designed to monitor and manage AI agents within enterprise cloud and on-premises environments. This strategic partnership highlights Autodesk's significant investment in securing its workforce, infrastructure, and product lines as it integrates advanced artificial intelligence technologies. The solution extends Permiso's existing unified identity platform to cover the rapidly expanding category of agentic identities, addressing a critical security gap where traditional identity providers lose visibility once an agent authenticates and operates autonomously. The new technology enables security teams to achieve continuous visibility into agent activity by discovering every agent in the environment, whether managed or operating as shadow IT. Crucially, the system tracks runs, events, tool calls, and data access across agents, sub-agents, Model Context Protocol (MCP) servers, and their underlying infrastructure. This observability allows organizations to answer fundamental security questions that current tools often miss, such as identifying how many agents are active, what identities they assume, what external tools they invoke, and which data stores they interact with at machine speed without human oversight. Autodesk's adoption is driven by the need to prevent non-deterministic behavior in AI systems, where agents might perform actions they were not explicitly programmed to do, a risk Permiso terms "LLMjacking" or malicious agent skills. The platform provides six key capabilities, including agent discovery across various environments like containers and Lambda functions, runtime identity attribution that ties every action to a specific human or AI entity, and behavioral sandboxing for new skills. It also features identity-first controls such as least privilege recommendations, approval gates, and kill switches, all delivered through an application programming interface-based architecture that requires no infrastructure changes from Autodesk or its customers.