Back to blog

Why I Joined Noma

Gal Moyal

Chris Hughes

September 1, 2026

Every prior tech wave changed where workloads ran, this one changes who is taking the action.

By now it’s clear that AI and autonomous agents are and have moved from experimentation into production systems, touching real data, identities, and business environments.

This is the defining challenge of our time in cybersecurity and is precisely why I’ve decided to join Noma Security, a leader in the AI and Agent Security space, helping some of the most critical organizations and sectors tackle this challenge head on. 

Security, as an industry, runs the risk of perpetuating historical behavior of being a late adopter, as we have in prior technological cycles. We as security practitioners are risk averse by nature, show up late, and end up trying to bolt controls on after the business has already adopted the technology. The behavior was already problematic in the past, but the accelerated adoption cycle of AI and agents, coupled with their autonomy and machine speed activity make that sort of behavior even more unacceptable. 

We have an opportunity to be an innovator and early adopter, and ensure security and governance are fundamental aspects of this technology cycle – something Noma has already taken the reins on

As AI security challenges hit our ecosystem, the market has responded the way it always does – with acronyms. We have AISPM, AIDR, AI-BOM –  the list goes on –  and we are early enough that it will be longer by the time you read this. I’m not above any of this, as Noma uses several of these terms, and so do I. They are useful right until the label starts doing the work the capability is supposed to do. 

Many organizations are still treating AI security as a model problem, when it is really an identity, access and runtime behavior problem – because agents hold tools, act autonomously, and take real actions in the enterprise.

Organizations need a continuous inventory of each agent, its toolset, its data access, its skills, and the MCP servers it is wired into, across SaaS, endpoint, and homegrown agents alike. Those agents need distinct identities, tool-scoped authorization, and the same supply chain rigor we already apply to software. Above all, agents demand runtime enforcement across their entire trajectory, with deterministic hard boundaries aligned to organizational requirements.

That last piece is the hardest to build, and it is why I landed at Noma. The team was already working the full agent trajectory, from discovery through runtime enforcement, while much of the market was still arguing about model guardrails. Getting to shape that while enterprise agent architectures are still being decided is a narrow window, and it is open right now.

As a community we hand-wrung through Cloud, sleep-walked through SaaS, and embraced our reputation as the "office of no" through DevOps. Each time the business moved ahead anyway while we spent years catching up, bolting on controls that could have been built in from the start. Security already thinks in identity, least privilege (now least autonomy), blast radius, provenance, and runtime enforcement, the exact vocabulary agent security needs.

We're not being asked to learn something new as much as we're being asked to show up on time and meet the moment as it is demanded of us.

I look forward to working with Noma to close the gap between what practitioners are dealing with and what the category is selling, and to ensure we deliver real capabilities to drive secure business outcomes in a market of buzz words and acronyms.

READ TIME
9 min
CATEGORY
News
That's a great question
TABLE OF CONTENTS
100%
Share this:

Discover more

Research
Product
Education

How to Safely Deploy Fable 5, Mythos 5, and Daybreak in Enterprise Environments

Gal Moyal

Gal Moyal

September 2, 2026

News
That's a great question

Why I Joined Noma

Gal Moyal

Chris Hughes

September 1, 2026

Partnerships

Noma Power for Amazon Kiro: AI Security Context, Built Into Your Coding Agent

Gal Moyal

Nadav Lotan

August 26, 2026