Category 11 of 12 · Controls: How employees use AI tools
Workforce AI usage control
Browser, endpoint, and network controls over which AI tools employees use and what data they paste in, including coding agents on developer machines.
Mitigates: ASI05 Unexpected Code Execution, LLM02 Sensitive Information Disclosure
Vendors, by signal score
- #1ZscalerPlatform suite70
Zscaler AI Protect extends the Zero Trust Exchange to AI: secure access to GenAI apps, AI asset discovery, and runtime guardrails, plus AI Red Teaming from the SPLX acquisition, an AI Broker with an agent registry for MCP and A2A traffic, and an AI Access Graph built on Symmetry Systems.
- #2WitnessAI36
AI security and governance for employees and agents: catalogs AI apps, agents, and MCP servers, applies intent-based policy by department and role, enforces control at the tool-call and MCP-server level, and blocks prompt injection and jailbreaks.
- #3Aurascape23
AI usage control and agent governance: discovers public, embedded, and shadow AI apps and agents, protects sensitive data in prompts, governs coding assistants, and routes agent tool calls through a gateway that enforces policy before actions reach external systems.
- #4LayerXAcquired by Akamai20
Browser-based AI usage control and enterprise browser security: discovers shadow AI, prevents sensitive data leaking into AI tools, restricts access to unsanctioned AI apps and accounts, and covers AI browsers, IDEs, and plugins. Acquired by Akamai in 2026.
Ranked within this category only. How the score works.
Also covers this category
- AcuvityAcquired by Proofpoint10
AI security and governance across endpoints, browsers, MCP servers, and local AI tools: discovers AI usage, inspects interactions at runtime, and enforces policy at the MCP boundary. Acquired by Proofpoint in 2026.
- Aim SecurityAcquired by Cato Networks17
AI security for employee AI use, coding agents, and MCP: discovers agents, inspects prompts and tool calls, and blocks unsafe actions at runtime. Acquired by Cato Networks in 2025; now part of Cato's SASE platform.
- Apex SecurityAcquired by Tenable10
Discovery and governance of how employees and agents use enterprise AI platforms. Acquired by Tenable in 2025; the product now ships as Tenable One AI Exposure.
- Check PointPlatform suite55
The Check Point AI Defense Plane combines Workforce AI Security, AI Application and Agent Security, and AI Red Teaming (in limited release), built on the Lakera acquisition (Lakera Guard and Lakera Red) and the Cyata agent discovery acquisition.
- CrowdStrikePlatform suite67
Falcon AIDR, now presented as Falcon Guardian, discovers workforce AI and endpoint agents, governs which agents may run, and ties each prompt, identity, and tool call to downstream system actions in Falcon Next-Gen SIEM. Built with the Pangea acquisition, with SGNL powering Continuous Identity for AI Agents.
- Cyberhaven31
Data security platform built on data lineage: inventories AI apps, coding assistants, agent frameworks, and MCP servers, and blocks, warns, or redacts when sensitive data moves into or out of AI tools and agents.
- Harmonic Security19
Data protection for employee AI use, using specialized language models to spot sensitive data in prompts, plus an MCP gateway that sets what actions agents may take and what data they may share with each tool.
- Knostic15
Need-to-know access control for enterprise AI: finds where assistants such as Microsoft 365 Copilot overshare data, and its Kirin product enforces least-privilege profiles and runtime guardrails for agents, coding assistants, and MCP servers.
- KoiAcquired by Palo Alto Networks21
Agentic endpoint security: inventories the AI agents, models, MCP servers, extensions, and skills installed on endpoints, applies policy to them, and removes risky packages and AI tools. Acquired by Palo Alto Networks in 2026 and now sold as Cortex Agentic Endpoint Security.
- Nightfall AI34
AI-native DLP that inspects data moving through AI agents, MCP servers, endpoints, and SaaS, with an MCP gateway that applies per-tool policy, logs every tool call with the SSO user, and lets admins revoke access.
- Prompt SecurityAcquired by SentinelOne16
AI firewall and usage control for employee AI tools, coding assistants, and homegrown AI apps: blocks adversarial prompts, scrubs sensitive outputs, and keeps a log of agent actions. Acquired by SentinelOne in 2025.
- SentinelOnePlatform suite55
AI security built on the Prompt Security acquisition: runtime protection for employee and homegrown AI, discovery of shadow MCP servers and agents, Prompt AI Agent Security (preview) for agent governance, and Prompt AI Red Teaming.
Questions to ask a vendor
- Can it see and control AI use in the browser without breaking productivity?
- Does it cover coding agents and local tools, not only web chat?
- Can it coach users in the moment rather than only block?
FAQ
- Is blocking public AI tools effective?
- Rarely on its own. Employees move to personal devices. Visibility plus approved alternatives plus in-the-moment guidance tends to work better.
- Why do coding agents need special attention?
- They run with a developer's local access and can execute commands, so they combine data exposure with code execution risk.