FAQ · REVIEWED SEPTEMBER 2026
AI agent security FAQ
The verdict
Short answers to the questions buyers ask most about AI agent security: what the category covers, what tools cost, how the nine vendors we score differ, and how our scores work. Each answer links to the page that goes deeper.
What is AI agent security?
What is AI agent security?
The set of controls that let an organization see which AI agents are running, decide what each one may do, stop actions that break policy, and keep a record of who did what. It matters because agents act with a person's access.
Read more: What is AI agent security
How is an AI agent different from a chatbot?
A chatbot answers; an agent acts. Coding agents such as Claude Code, Codex and Cursor can run shell commands, install packages, edit files and call APIs, usually with the permissions of the person who started them.
Read more: Where AI agent controls sit
What is MCP, and why does it matter for security?
The Model Context Protocol is an open standard that connects AI apps to tools and data through MCP servers. The specification warns that local MCP servers run with the same privileges as the client, so an unvetted server can act with the user's access.
Read more: MCP security
What is shadow AI?
AI tools, agents, extensions or MCP servers used without the organization's approval or visibility. Discovery on the device comes first, because many of these tools never touch the corporate network.
Read more: What is shadow AI
Do AI agent security tools replace EDR?
No. EDR detects malware and intrusion at the process level; these tools decide whether a trusted agent's action should run. Several, including Bay and Noma Security, state that they deploy through the EDR or MDM you already run.
Read more: AI agent security and EDR
What is indirect prompt injection?
Instructions hidden in content an agent reads, such as a web page, a file or a tool result, that steer it into actions its user did not ask for. Controls at the action layer check the action itself, whatever the text looked like.
Read more: Indirect prompt injection
What changed in the MCP specification in July 2026?
The 2026-07-28 revision makes MCP stateless, tightens authorization (clients must validate the iss parameter, and Dynamic Client Registration is deprecated in favor of Client ID Metadata Documents) and adds headers that let gateways route traffic without reading request bodies.
Read more: What the 2026-07-28 specification changes
How do you buy an AI agent security tool?
How much do AI agent security tools cost?
None of the nine vendors in this guide publishes list prices as of September 2026. Harmonic Security publishes tier names (Explore, Guide, Command) without prices. Budget with vendor quotes.
Read more: Buyer's checklist
What should I ask vendors?
Ask each vendor to show four checkpoints on your own devices: what it sees, how it decides before an action runs, what it can do besides block, and what it logs. Then check deployment and vendor maturity.
Read more: 30 questions to ask vendors
How long should an evaluation take?
Plan for a few weeks on real developer machines: about a week to deploy and build the inventory, a week with rules in simulation, and a week enforcing for a pilot group.
Read more: Buyer's checklist
Which tools deploy through existing EDR or MDM?
On public pages reviewed in September 2026, Bay and Noma Security state that they deploy through existing EDR or MDM, Harmonic Security rolls out through Intune, JAMF, Kandji or Group Policy, and Koi is available as a Cortex XDR module or standalone.
Read more: AI agent security and EDR
Which tools can stop a tool call before it runs?
On public pages reviewed in September 2026: Bay (Allow, Ask or Deny on pre-tool calls), Zenity (block or modify before execution), Onyx Security (inline inspection of every tool call) and Lasso Security (inspects every Claude Code tool call before execution).
Read more: MCP security
Can I rank the tools by my own priorities?
Yes. The score calculator re-weights our seven criteria and re-ranks all nine tools, and the side-by-side page compares two to five tools on every criterion.
Read more: Score calculator
How do the nine vendors differ?
What is Bay best for?
Controlling what AI agents do on employee devices: it inventories agents, MCP servers and credentials, returns Allow, Ask or Deny on each tool call with session context, and deploys through existing EDR or MDM. It scores 7.9 (rank 1) and scores lowest of the nine on maturity and on coverage beyond the endpoint.
Read more: Bay review
What is Noma Security best for?
Agent estates that span laptops, SaaS platforms and homegrown apps. It discovers endpoint agents through existing EDR or MDM and adds posture management, runtime detection and red teaming. It scores 7.5 (rank 2).
Read more: Noma Security review
What is Zenity best for?
Enterprises whose agents live mainly in Microsoft 365 Copilot, Copilot Studio, Salesforce and ServiceNow, with pre-execution blocking for coding agents through agent hooks and an MCP gateway. Its endpoint deployment method is not published. It scores 7.4 (rank =3).
Read more: Zenity review
What is Onyx Security best for?
Inline control across browser AI, coding assistants, desktop agents, cloud workloads and MCP servers, with five actions: alert, block, mask, steer or ask. It uses its own endpoint agents and browser extensions. It scores 7.4 (rank =3).
Read more: Onyx Security review
What is Harmonic Security best for?
Protecting sensitive data in everyday AI use, with block, warn or log choices, rollout through Intune, JAMF, Kandji or Group Policy, and MCP-layer governance in Harmonic Command. It scores 7.1 (rank =5).
Read more: Harmonic Security review
Who owns Koi, and who is it for?
Palo Alto Networks completed its acquisition of Koi on 14 April 2026 and sells it as Cortex Agentic Endpoint Security, as a Cortex XDR module or standalone. It suits Cortex customers. It scores 7.1 (rank =5).
Read more: Koi review
Who owns Prompt Security, and who is it for?
SentinelOne announced its acquisition of Prompt Security on 5 August 2025 and describes it as built into the Singularity Platform. It suits SentinelOne customers who want AI usage, code assistant and homegrown app protection in one place. It scores 6.6 (rank =7).
Read more: Prompt Security review
What is Lasso Security best for?
Teams that want an open-source MCP gateway and inspection of each Claude Code tool call through its lifecycle hooks, plus AI usage control and red teaming. It has several components to deploy. It scores 6.6 (rank =7).
Read more: Lasso Security review
What is Bloom Security best for?
A fleet-wide inventory of software, extensions, packages and AI tools on endpoints, with blocking across npm, the Chrome Web Store and Open VSX. Its deployment method and tool-call decisions are not published yet. It scores 6.0 (rank 9).
Read more: Bloom Security review
How does this site score tools?
How does this site score tools?
Seven criteria are scored 0-10 from public vendor material, then weighted and totalled in code. Weights: visibility 22%, tool-call control 20%, policy 15%, identity and audit 12%, footprint 13%, breadth 8%, maturity 10%.
Read more: How we score
Did you test the products?
No. Scores come from public vendor pages, documentation, blog posts and press releases reviewed in September 2026. There was no product testing and no vendor briefing.
Read more: Limitations
What does "Not published" mean on this site?
We could not find the information on the vendor's public pages in September 2026. It does not prove the capability is absent; treat it as a question for the vendor.
Read more: How to read vendor claims
How often is the site updated?
Vendor facts were last reviewed in September 2026. We re-check each vendor's public pages every quarter and after acquisitions or major launches; the next scheduled review is December 2026.
Read more: How we score