Noma’s 8-Agent Laptop Coverage Shows AI Security Moving From Apps to Actions

Employee laptop running AI coding agents and MCP servers under Noma endpoint agent security access controls

TL;DR · 30-second read

The Short Version

Many programmers and office workers now use artificial intelligence assistants that act on their own. They edit code, open files and pass data to other systems, using the same logins and permissions as the person who installed them.

Noma, a New York security company, launched software that finds these assistants on company laptops, decides what each one may do, and blocks risky actions as they happen.

The bigger shift: companies are moving from asking “is this tool approved?” to “is this specific action allowed?” An assistant might be allowed to read a database but not delete it.

On September 28, 2026, Noma Security announced in a release distributed via PR Newswire that it has extended its AI agent security platform to employee endpoints, meaning the laptops and desktops where staff work. The new capabilities find AI agents, MCP servers and skills running on managed machines. They place those assets under access control and apply runtime protection through Noma’s AI Detection and Response (AI-DR) layer. MCP servers are connectors built on the Model Context Protocol that let agents reach databases, repositories and applications. Skills are packaged instructions that agents load for specific tasks.

Noma says coverage spans agents including Claude Code, Claude Cowork, Cursor, Codex, Windsurf, Kiro, Antigravity and OpenClaw. It works through tools companies already run: endpoint detection and response (EDR) software, mobile device management (MDM) software, agent hooks, AI and MCP gateways, and SDKs. Noma also says it plans to bring its Agent Boundaries feature to the endpoint, without giving a date.

Executive Summary

Noma’s announcement targets a specific problem. AI agents installed by individual employees inherit that employee’s credentials and can chain actions together across a session, such as reading files, calling tools and changing systems, without a human approving each step. Noma’s pitch is that the laptop, not the cloud, is where these agents are multiplying fastest and where security teams have the least visibility.

The product has three layers. Discovery reads local evidence to build a live inventory. Access Control assigns every agent, MCP server and skill a status of approved, needs review or blocked, and ties it to the responsible employee’s identity. AI-DR watches behavior at runtime and can alert, steer, block, mask data or hand an action to a human.

The release’s most important idea is stated in one line: “Approving an agent is not enough.” That marks a change in how enterprises govern AI tools. Deciding once whether an app is allowed is giving way to deciding, continuously, which individual actions an allowed agent may take.

Why the Laptop Became the Blind Spot

Enterprise AI security so far has concentrated on systems the company builds or buys centrally: homegrown applications on cloud AI platforms, and SaaS agent builders run through IT. Coding and productivity agents took a different route. Developers and business users often install them directly, the same way unsanctioned SaaS apps once spread before IT caught up. By the time security notices, the agent already holds the user’s access to source code, production infrastructure, documents and internal data.

MCP servers and skills widen that reach. Each connector adds new tools an agent can call, and each skill adds new instructions it can follow. Noma’s argument is that this exposure “already exists before any attacker is ever involved.” The risk is not only malicious code. It is also a legitimate tool doing something broader than intended, with credentials nobody scoped for it.

From Approving Apps to Governing Actions

The headline shift is visible in how Noma structures control. Its release names at least eight agents from several vendors: Claude Code, Claude Cowork, Cursor, Codex, Windsurf, Kiro, Antigravity and OpenClaw. An approve-or-block decision per application does not scale across that many tools, each with its own connectors and update cycle. Noma instead governs at five levels: the agent, the MCP server, the skill, the individual tool and the specific action. Its example is precise. Read access can stay broadly available while create, update and delete operations are limited to a smaller group.

The runtime layer extends the same logic across time. Noma says its Contextual Policies correlate prompts, tool calls, tool responses, data access and identity across a full session. The goal is to catch threats that “develop across a sequence of otherwise permitted actions.” This is the core of the argument. Every step can be individually allowed while the sequence is harmful, for example an approved database tool turning a routine task into mass deletion. To support the claim that sanctioned tools can misbehave, Noma cites a security researcher’s finding that xAI’s Grok Build coding assistant uploaded tracked repositories and full Git history to the provider’s cloud after being told not to open files.

The people affected are concrete. Security teams gain a registry and policy engine keyed to user and group identity from the company’s identity provider. Developers and business users may see new review states, write restrictions, or human-approval steps inserted mid-session. Agent vendors face customers who expect hooks and telemetry detailed enough to support action-level enforcement.

Riding on EDR and MDM: The Deployment Bet

Noma does not install a new heavyweight agent on every laptop. It connects through EDR or MDM tools already deployed and reads configuration files, skills directories, connector history and running processes. Enforcement runs through agent hooks, gateways and SDKs. That lowers adoption friction, a real advantage in enterprises wary of adding more endpoint software.

The trade-off is dependency. Discovery depends on what existing EDR and MDM tools can see. Inline blocking depends on how much control each agent’s hooks expose. The release frames inventory around managed devices, which leaves personal and unmanaged machines outside the described scope. The approach also places Noma alongside two sets of possible competitors: EDR vendors that already sit on the endpoint, and agent vendors that could build governance controls into their own products.

What the Release Substantiates, and What It Does Not

The functional description is specific. It names detectors (prompt injection, sensitive data leakage, tool poisoning, scope violations, behavioral drift), enforcement modes, and data sources. Security buyers can test claims at that level of detail.

The commercial claims are less specific. “Market-leading,” “widely adopted by Fortune 500 customers,” “hundreds of AI-DR policies” and work with “dozens of Fortune 500 security teams” are not quantified or tied to named customers. The release gives no detection accuracy, false-positive rates or performance impact for inline blocking. Agent Boundaries is described as planned, with no timeline. None of this undercuts the product’s premise, but buyers will need proof-of-concept results rather than the announcement to judge effectiveness.

Background

Noma Security is a New York-based company that sells an AI and agent security platform for large enterprises. Before this announcement, the company described coverage across homegrown AI applications built on AWS Bedrock, Azure AI Foundry and Databricks, SaaS agent platforms such as Microsoft Copilot Studio and Salesforce AgentForce, and prebuilt agents like Claude Code, Cursor and GitHub Copilot on developer machines. Its backers include Evolution Equity Partners, Ballistic Ventures, Glilot Capital, Cyber Club London, Databricks Ventures and SVCI. The company says Gartner has recognized it as a leader in AI trust, risk and security management (AI TRiSM).

The wider market context is the rapid spread of autonomous AI agents. These tools do more than suggest text: they take actions such as editing code, querying databases and operating SaaS apps. The Model Context Protocol has become a common way to connect agents to outside tools. That has made the question of what an agent is permitted to do a security and governance problem, not only a productivity one.

Sources

Source: Noma Extends Agent Security and Governance to the Employee Endpoint, Noma Security’s September 28, 2026 announcement of discovery, access control and runtime protection for AI agents on employee machines.