Best AI Security markBest AI Security

LESSON · 29 SEPTEMBER 2026

Where AI agent security controls sit

The verdict

A control can sit inside the agent (hooks and managed settings), on the device (a component deployed through EDR or MDM, or its own agent), in a network or MCP gateway, or inside the SaaS platform that hosts the agent. Each sees a different slice of activity, and many companies combine two.

By Best AI Security editors · 29 September 2026 · 2 min read

Inside the agent

Coding agents expose settings and lifecycle hooks that an administrator can manage centrally. A policy here sees each tool call before it runs, with its arguments. Bay describes managed settings for Claude Code, Codex and Claude Desktop, and Lasso Security connects to Claude Code's lifecycle hooks. The limit: it covers only agents that offer such hooks.

On the device

A component on the endpoint can inventory every agent, MCP server, extension and credential, including ones no gateway ever sees. Bay and Noma Security say they deploy through existing EDR or MDM; Koi runs as a Cortex XDR module or standalone. This works alongside EDR: EDR watches processes and files for malware, while the agent control decides whether a trusted agent's action should run.

In a gateway

A gateway inspects traffic routed through it. It suits remote MCP servers and model APIs, and the 2026-07-28 MCP headers make routing easier. It does not see a local MCP server talking to an agent over stdio on the same laptop.

In the SaaS platform

Agents built in platforms such as Microsoft 365 Copilot, Salesforce Agentforce or ServiceNow run in the vendor's cloud. Controls there connect to the platform's APIs; Zenity lists integrations with these platforms.

How do you choose where to start?

Start from where your agents run. If most AI use is coding agents and desktop assistants on employee laptops, a control on the device or inside the agent covers the most ground, including local MCP servers that no gateway sees. If most agents are built in SaaS platforms, start with controls that connect to those platforms. If traffic already flows through a proxy, a gateway adds control over remote MCP servers and model APIs. Many companies combine a device-level control with one other layer. Our rankings weight the device because that is this guide's topic; the score calculator lets you change the weights.

Related

Sources