Best AI Security markBest AI Security

NOTE · 29 SEPTEMBER 2026

AI agent security news recap: April to September 2026

The verdict

This recap covers announcements from April to September 2026. Palo Alto Networks completed its acquisition of Koi, Onyx Security and Zenity announced large funding rounds, several vendors reported analyst placements, and both the MCP project and the OWASP GenAI Security Project published changes that shape what buyers should ask for.

Six months of announcements from the vendors we score and from the standards projects they build on, grouped by what they mean for buyers.

By Best AI Security editors · 29 September 2026 · 5 min read

What does this recap cover?

It covers public announcements dated between 14 April and 23 September 2026 from the nine vendors on this site and from two standards projects, the Model Context Protocol and the OWASP GenAI Security Project. Each item also appears on our news page, where every entry links to its original source. Vendor claims, including analyst placements and performance figures, are summarized as the vendor states them. This note was published on 29 September 2026.

Who bought whom?

On 14 April 2026 Palo Alto Networks completed its acquisition of Koi. Koi's website now redirects to Cortex Agentic Endpoint Security, and Palo Alto Networks said it would integrate Koi with Prisma AIRS, add a new Cortex XDR module and keep Koi available as a standalone offering. The other platform move in this guide predates the window: SentinelOne announced its agreement to acquire Prompt Security on 5 August 2025 and now describes it as built into the SentinelOne Singularity Platform.

For buyers, the practical question with both is packaging: what sits inside the platform module, what remains standalone, and what the roadmap is for customers on other EDR platforms. Our comparison of Bay and Koi looks at an EDR-module product beside a tool that deploys through any EDR or MDM.

Who raised money?

Two vendors announced large rounds within a week of each other. On 29 July 2026 Onyx Security announced a $113M Series B led by Bessemer Venture Partners. On 3 August 2026 Zenity announced a $125 million Series C led by Norwest, to fund expansion in Europe and Asia Pacific and research through Zenity Labs. Company backing is one input to our maturity criterion; it does not change the other six rows of the score.

Which analyst placements did vendors report?

  • 23 September 2026: Zenity and Noma Security each said Gartner named them a Market Shaper in its inaugural Emerging Market Quadrant for AI Application Security, Startup Vendors. Zenity said it was one of two vendors in its category among nearly 20 assessed; Noma said it was placed in the "Full-Spectrum, Context-Aware Agentic Security" category.
  • 15 September 2026: SentinelOne said Latio's 2026 AI Security Market Report named it an AI Security Platform Leader, and that Prompt Security covers more than 15,000 AI applications and sites.
  • 28 August 2026: Harmonic Security summarized Gartner's Market Overview for AI Usage Control and quoted its prediction that "by 2030, more than half of enterprises will use dedicated AI usage control technologies."

These are the vendors' own summaries of reports we have not read in full. Our lesson on reading vendor claims explains how this site treats them.

What did vendors ship or publish?

  • 9 September 2026, Lasso Security: LEAP, a patent-pending guardrail classification architecture that Lasso says matches the detection accuracy of a GPU-based transformer guard while running on an ordinary CPU. Its throughput and latency figures are vendor-stated.
  • 26 August 2026, Noma Security: Noma Power for Amazon Kiro, which shows AI asset inventory, exposure and risk-ranked findings inside the Kiro coding environment, with reports in markdown, PDF or Word.
  • August 2026, Bay: research on "Ghostjacking", indirect prompt injection that turns a trusted agent's own permissions into the attack path, which Bay calls "an authorization problem disguised as a prompt problem."
  • 30 July 2026, Bloom Security: a launch post describing "one platform to control, defend, and manage everything running across the endpoint fleet", covering AI agents, extensions and packages.

What changed in the standards?

The MCP project released the 2026-07-28 specification on 28 July. It removes the initialize handshake and protocol sessions, adds multi round-trip requests, requires clients to validate the iss parameter per RFC 9207, and deprecates Dynamic Client Registration in favor of Client ID Metadata Documents. On 22 August the maintainers published a roadmap that names agent identity and enterprise security, based on DPoP and Workload Identity Federation, as a priority area, and said the Enterprise-Managed Authorization extension is now stable.

On 1 September the OWASP GenAI Security Project announced its 2026 Top 10 for LLM Applications, with Excessive Agency ranked third, and said the Agent Control Standard had been donated to the project to extend its guidance toward runtime enforcement. Our notes on the MCP specification and on Excessive Agency go deeper.

What does it mean for buyers?

  • Ask platform-owned products what is in the module and what is standalone, and how they serve customers on other EDR platforms.
  • Treat analyst placements as the vendors' own summaries until you have read the report.
  • Ask every vendor which MCP specification revision it supports, and how it records identity now that MCP has no protocol sessions.
  • Ask how the product limits what an agent may do, not only what it can see. That is the concern Excessive Agency names.

Related

Sources