Best AI Security markBest AI Security

NEWS · UPDATED SEPTEMBER 2026

AI agent security news

The verdict

Fourteen items from April to September 2026: acquisitions, funding and product news from the vendors we score, and releases from the MCP project and the OWASP GenAI Security Project. Vendor claims, including analyst placements, are summarized as the vendor states them.

Summaries of public announcements, with links to the original source. Updated monthly.

23 Sep 2026Zenity

Zenity says Gartner placed it as a Market Shaper for AI application security

Zenity says it was named a Market Shaper in Gartner's inaugural Emerging Market Quadrant for AI Application Security, Startup Vendors, one of two vendors in that category among nearly 20 assessed.

Source: Zenity newsroom

23 Sep 2026Noma Security

Noma Security reports the same Gartner Market Shaper placement

Noma says Gartner placed it in the "Full-Spectrum, Context-Aware Agentic Security" group of the same Emerging Market Quadrant for AI Application Security, Startup Vendors.

Source: Noma Security blog

SentinelOne named an AI security platform leader by Latio

SentinelOne says Latio's 2026 AI Security Market Report named it an AI Security Platform Leader. It says Prompt Security covers more than 15,000 AI applications and sites and extends to agents, MCP servers and custom-built applications.

Source: SentinelOne press

9 Sep 2026Lasso Security

Lasso introduces LEAP guardrails that run on ordinary CPUs

Lasso describes LEAP as a patent-pending classification architecture that matches the detection accuracy of a GPU-based transformer guard while running on a CPU. Its throughput and latency figures are vendor-stated.

Source: Lasso Security blog

1 Sep 2026Field

OWASP publishes its 2026 Top 10 for LLM Applications and adds an Agent Control Standard

The OWASP GenAI Security Project announced the 2026 edition of its Top 10 for LLM Applications, with Excessive Agency ranked third, and said the Agent Control Standard has been donated to the project to extend its guidance toward runtime enforcement.

Source: OWASP GenAI Security Project

Harmonic reviews Gartner's new Market Overview for AI Usage Control

Harmonic summarizes Gartner research on AI usage control, which it quotes as predicting that "by 2030, more than half of enterprises will use dedicated AI usage control technologies."

Source: Harmonic Security

26 Aug 2026Noma Security

Noma brings its security findings into Amazon Kiro

Noma Power for Amazon Kiro shows AI asset inventory, exposure and risk-ranked findings inside the Kiro coding environment, with reports in markdown, PDF or Word.

Source: Noma Security blog

22 Aug 2026Field

MCP roadmap puts agent identity and enterprise security on the list

The MCP maintainers' new roadmap names five priority areas, including agent identity based on DPoP and Workload Identity Federation, and says the Enterprise-Managed Authorization extension is now stable.

Source: Model Context Protocol blog

3 Aug 2026Zenity

Zenity raises a $125 million Series C

Zenity announced a $125 million Series C led by Norwest, to expand in Europe and Asia Pacific and fund research through Zenity Labs.

Source: Zenity newsroom

Aug 2026Bay

Bay describes "Ghostjacking" through trusted AI agents

Bay's research write-up describes indirect prompt injection that uses a trusted agent's own permissions, calls it "an authorization problem disguised as a prompt problem", and argues for policy enforced at the action layer.

Source: Bay blog

30 Jul 2026Bloom Security

Bloom Security sets out why it built an AI-native endpoint platform

Bloom's launch post describes "one platform to control, defend, and manage everything running across the endpoint fleet", covering AI agents, extensions and packages.

Source: Bloom Security blog

29 Jul 2026Onyx Security

Onyx Security announces a $113M Series B

Onyx announced a $113M Series B led by Bessemer Venture Partners.

Source: Onyx Security blog

28 Jul 2026Field

MCP specification 2026-07-28 makes the protocol stateless

The new MCP revision removes the initialize handshake and protocol sessions, requires clients to validate the iss parameter, and deprecates Dynamic Client Registration in favor of Client ID Metadata Documents. Our note on the changes has the detail.

Source: Model Context Protocol blog

Palo Alto Networks completes its acquisition of Koi

Palo Alto Networks completed the Koi acquisition, with a new Cortex XDR module and Prisma AIRS integration planned. Koi remains available as a standalone offering.

Source: Palo Alto Networks press