The Agent Security Map
Who secures AI agents, what each tool controls, and who owns it now. Sourced and dated.
61 vendors across 12 categories. Updated 2026-09-24.
Buying? Start with the CISO checklist for AI agent security: the questions to put to any vendor, mapped to the identity primitives that answer them.
The identity spine
Who the agent is, on whose behalf it acts, and what it may do.
- 1. Agent identity and credentials
Who the agent is
11 vendors
- 2. Delegated and user-to-agent auth
On whose behalf the agent acts
6 vendors
- 3. Agent authorization and fine-grained policy
What the agent may do
2 vendors
Data
What data agents and the people using them can reach.
- 7. AI data security and DLP
What data reaches agents
6 vendors
- 11. Workforce AI usage control
How employees use AI tools
4 vendors
Runtime
What happens while agents run, and how they are tested.
- 5. MCP and AI gateways
The tool-call chokepoint
3 vendors
- 6. Runtime guardrails and AI firewalls
What goes into and out of the model
14 vendors
- 8. Agent detection, response, and audit
What the agent did, and how to stop it
3 vendors
- 9. Red teaming and evaluation
Testing before and after deployment
4 vendors
- 10. Model and agent supply chain
Where models, servers, and skills come from
3 vendors
Discovery and governance
What exists, who owns it, and the evidence trail.
- 4. Agent discovery and AI posture
What agents exist
3 vendors
- 12. AI governance and GRC
Accountability and evidence
2 vendors
Latest deals
- 2026-08-17 Fortinet acquired Virtue AI
- 2026-07-30 Okta acquired Permiso Security
- 2026-07-28 Cyera acquired Oasis Security
- 2026-06-15 SailPoint acquired Entro Security
- 2026-05-27 Snowflake acquired Natoma