AI security protects models and their outputs, while AI agent security protects the actions an agent takes across enterprise systems. Traditional AI security covers model robustness, data poisoning, bias, and content safety. Agent security adds identity, least-privilege authorization, credential and token handling, real-time policy enforcement, human approval, and action-level audit, because an agent can read, write, and transact rather than only generate text. The distinction matters as agents spread: Gartner projects 40% of enterprise applications will embed task-specific AI agents by the end of 2026, up from less than 5% in 2025.