Agentic AI security is not one product. It is at least ten categories, each protecting a different part of what an agent does.
This map names the categories, gives example vendors, and shows where an AI agent allow list fits: the web pages agents may open.
Classic AI security protects a model that answers questions. Agent security protects a program that takes actions.
Keys, tokens and sessions let them act as a person or a service.
Who is the agent, what may it access, and for how long?
Through APIs and MCP servers, often ones nobody reviewed.
Which servers and tools are approved, with which arguments?
They open pages, fill forms and follow links on their own.
Which pages may they open, and which are off limits?
Any page or file can carry hidden instructions.
Detect injected instructions before they steer the agent.
Each row maps to a different part of the market. No single vendor covers all four well today.
Read the map from left to right as a life cycle: discover the agent, give it an identity, protect it at runtime, then control the traffic it sends.
The last step splits in three: model traffic, tool traffic and web traffic. Each has its own category below.
Vendors appear as examples of each category, based on how they describe their products. Many vendors span several categories.
Know what exists before you protect it.
Every agent needs an identity that can be limited and revoked.
Inspect what goes into and out of the model while it runs.
One path for all model traffic.
Control the tool servers agents connect to.
The browser is where agents and people meet the web.
Attack the agent before an attacker does.
Policies, inventories and evidence for auditors.
See what agents actually did, step by step.
The data that tells every other layer what a URL is.
Large security vendors bought AI security startups quickly. Buyers now often meet these products inside a platform.
Became part of Cisco AI Defense.
Model and AI application security folded into its platform.
Agent and MCP security research joined a developer security platform.
AI usage security added to a SASE platform.
Runtime AI protection joined an endpoint and cloud platform.
AI guardrail services added to its platform.
AI runtime security joined an application delivery vendor.
Prompt injection defence joined a network security vendor.
The pattern: platforms buy runtime protection. Data layers, such as page-type data, tend to be licensed rather than rebuilt.
| Agent risk | Primary category | Supporting category |
|---|---|---|
| Unknown agents running in the company | AI-SPM (01) | Governance (08) |
| Over-privileged agent credentials | Non-human identity (02) | AI-SPM (01) |
| Hidden instructions on a web page | Runtime protection (03) | Page policy data (10) |
| Agent creates accounts or buys things | Page policy data (10) | Browser security (06) |
| Risky third-party MCP server | MCP security (05) | Red teaming (07) |
| Uncontrolled model spend | AI gateway (04) | Observability (09) |
| Agent posts or uploads to public sites | Page policy data (10) | Runtime protection (03) |
| No audit trail for an incident | Observability (09) | Governance (08) |
| Regulator asks for an agent register | Governance (08) | AI-SPM (01) |
Two rows depend mainly on category 10. Those are the rows where an agent acts on the open web.
Runtime tools judge text. Page policy data judges the destination, before the request leaves.
The 8 action types are signup, password_reset, cart, checkout, upload, post_create, comment and subscribe. Denying them by default removes most of the ways an agent can act on a site.
The 20 read types, such as pricing, documentation and status, stay open, so research agents keep working.
Inventory every agent and its credentials. Log every URL agents request, tagged by page type.
Deny the 8 action page types by default. Approve MCP servers one by one.
Add runtime protection to the riskiest agents. Run a red-team exercise and keep the evidence.
Prompts, tool calls, credentials or page loads.
A tool cannot control traffic it never sees.
Detection alone leaves the action to happen.
Agents act in seconds, faster than a human review.
SaaS, your cloud, or fully on-premise.
Regulated teams may need the data to stay inside.
Open or closed when the service is down.
For agents, closed is the safe default.
Per-decision logs with agent, target and reason.
Auditors and incident reviews need the trail.
Your own, vendor SaaS agents, browser agents.
Coverage gaps become the attacker's path.
Its own research, or data it licenses.
Coverage and freshness decide real accuracy.
Gateways, proxies, SIEM, identity provider.
A tool that stands alone becomes shelfware.
| Category | Usual owner | Usual budget line |
|---|---|---|
| 01 AI-SPM | Cloud security | Cloud security platform |
| 02 Non-human identity | Identity and access team | IAM |
| 03 Runtime protection | Application security | AppSec or AI security |
| 04 AI gateways | AI platform team | AI platform |
| 05 MCP security | AI platform with AppSec | AI platform |
| 06 Browser security | Endpoint or network security | SASE or endpoint |
| 07 Red teaming | Offensive security | Testing services |
| 08 Governance | Risk, legal and compliance | GRC |
| 09 Observability | AI engineering | Engineering tools |
| 10 Page policy data | Network security or AI platform | Security data feeds |
Category 10 often sits next to existing web filtering feeds. Teams that already license URL category data add page types to the same contract line.
Mapping login and checkout pages on tens of millions of domains is a large crawl and classification job.
An OEM license ships the data inside your product.
Real login pages hide on subdomains, locales and app routes.
Each page-type URL in the data was found on the site, not guessed.
"Would this have stopped the 2026 incidents?"
The incident analysis maps each step to the rule that denies it.
Options and prices are on the pricing page. Product teams in categories 03 to 06 are the usual OEM fit.
Gateway, browser and SASE vendors can check the data against their own traffic samples before signing.
The honest fine print — the same two assumptions we publish, plus two operational ones
OWASP, NIST and the AWS scoping matrix, compared.
Category 02 in detail, with the agent angle.
The controls to have in place before agents go live.
Our sibling product for controlling people's use of AI tools.
Test page-type data on 100 real domains, then choose API, on-premise or OEM.