Best AI Security markBest AI Security

Guide · Checked against vendor sites, September 2026

AI agent security buyer's checklist: 30 questions to ask vendors

The verdict

Ask every vendor to show, on your own devices, the four checkpoints: what it sees, how it decides before an action runs, what it can do besides block, and what it logs. Then check deployment and vendor maturity. The 30 questions below are grouped that way and are printable.

Part of the University: Buying track

See (1-6)

  1. 1. Which AI agents, coding assistants and desktop AI apps can you discover by name today?
  2. 2. Do you discover MCP servers configured locally, including ones the user added?
  3. 3. Do you discover browser extensions, IDE extensions, plugins and skills?
  4. 4. Do you show which credentials, tokens and files each agent can reach?
  5. 5. How quickly does a newly installed agent appear in the inventory?
  6. 6. Can you export the inventory to our asset or CMDB tooling?

Decide (7-12)

  1. 7. Do you evaluate individual tool calls before they execute, or only after?
  2. 8. What context does a decision use: user, device, prior actions in the session, data touched?
  3. 9. Which agents support in-line decisions today, and which are monitor-only?
  4. 10. What is the decision latency, and where is it computed (device or cloud)?
  5. 11. Can we run a new rule in simulation and see what it would have done?
  6. 12. How are rule conflicts and exceptions ordered?

Allow or block (13-18)

  1. 13. Which actions exist besides allow and block: ask the user, warn, mask, modify?
  2. 14. Can we restrict MCP servers to an approved list per team?
  3. 15. Can we control shell, package installation, cloud CLIs and container commands separately?
  4. 16. What does the user see when an action is paused or denied?
  5. 17. Can a user request an exception, and who approves it?
  6. 18. What happens if the control component is removed or tampered with?

Log (19-22)

  1. 19. Does the record separate human actions from agent actions?
  2. 20. Does it show the chain from prompt to system action?
  3. 21. Where are logs stored, for how long, and can we send them to our SIEM?
  4. 22. Can you produce an audit report for a given user, agent or time range?

Deployment (23-26)

  1. 23. Does it deploy through our existing EDR or MDM, or does it add a resident agent?
  2. 24. Which operating systems and environments are supported, including remote VMs and containers?
  3. 25. What changes on developer machines, and what is the performance impact?
  4. 26. How are policy changes delivered to devices, and how fast?

Vendor (27-30)

  1. 27. Which compliance reports can we review (SOC 2, ISO 27001)?
  2. 28. Can we speak to two reference customers of our size?
  3. 29. How is pricing calculated (per user, per device, per agent), and what is included?
  4. 30. If you were acquired or are part of a larger platform, what is the roadmap for the standalone product?

Use these alongside the scores on the rankings page. Where a vendor answers "yes" to a question its public pages do not cover, ask to see it working.

Frequently asked questions

How long should an evaluation take?

Plan for a few weeks on real developer machines: one week to deploy and inventory, one to run rules in simulation, and one to enforce for a pilot group.

Related