AI Agent Allowlist
Home Page-Types Database Agent Guardrails 2026 Incidents API Docs Pricing
Resources
Use Cases (15) Industries & Buyers (12) Learn: Core Concepts (12) Implementation Guides (15) Comparisons (8) Schema & Data Reference (6) FAQ Glossary
Why It Matters
2026 Agent Incidents Category Targeting Database Refreshes Contact Customer Login
Download Free Sample
market map for security leaders, analysts and product teams

Agentic AI Security Market Map

Agentic AI security is not one product. It is at least ten categories, each protecting a different part of what an agent does.

This map names the categories, gives example vendors, and shows where an AI agent allow list fits: the web pages agents may open.

10Vendor categories
46Example vendors named
8Acquisitions since 2024
3Starter stacks
Why a map

What makes agent security different

Classic AI security protects a model that answers questions. Agent security protects a program that takes actions.

Agents hold credentials

Keys, tokens and sessions let them act as a person or a service.

So identity matters

Who is the agent, what may it access, and for how long?

Agents call tools

Through APIs and MCP servers, often ones nobody reviewed.

So tool control matters

Which servers and tools are approved, with which arguments?

Agents browse the web

They open pages, fill forms and follow links on their own.

So navigation control matters

Which pages may they open, and which are off limits?

Agents read untrusted content

Any page or file can carry hidden instructions.

So runtime protection matters

Detect injected instructions before they steer the agent.

Each row maps to a different part of the market. No single vendor covers all four well today.

Read the map from left to right as a life cycle: discover the agent, give it an identity, protect it at runtime, then control the traffic it sends.

The last step splits in three: model traffic, tool traffic and web traffic. Each has its own category below.

The map

Ten categories at a glance

01 DISCOVERAI security posture (AI-SPM)Find agents, models and data paths
02 IDENTIFYAgent and non-human identityCredentials, access, lifecycle
03 PROTECTRuntime protection and AI firewallsPrompt injection, data leaks
04 ROUTEAI and LLM gatewaysModel traffic, keys, budgets
05 CONNECTMCP security and gatewaysTool servers, scanning, allowlists
06 BROWSEEnterprise and AI browser securityBrowser agents, extensions
07 TESTRed teaming and evaluationAttack agents before launch
08 GOVERNAI governance and complianceInventory, policy, audit
09 OBSERVEAgent observabilityTraces, costs, behaviour
10 NAVIGATEWeb page policy dataWhich pages agents may open

Vendors appear as examples of each category, based on how they describe their products. Many vendors span several categories.

Category by category

What each category covers, with examples

01

AI security posture management

Know what exists before you protect it.

  • Discovers models, agents and AI services in cloud accounts
  • Maps which data each one can reach
  • Flags risky configurations
  • Feeds findings to the security team
Examples: Wiz AI-SPM, Palo Alto Networks Prisma AIRS, Microsoft Defender for Cloud, Noma Security, Zenity
02

Agent and non-human identity

Every agent needs an identity that can be limited and revoked.

  • Issues and rotates agent credentials
  • Scopes access per task
  • Finds orphaned keys and tokens
  • Links each agent to a human owner
Examples: Okta, SailPoint, CyberArk, Astrix Security, Oasis Security, Aembit, Keycard, Clutch Security
03

Runtime protection and AI firewalls

Inspect what goes into and out of the model while it runs.

  • Detects prompt injection and jailbreaks
  • Blocks sensitive data in outputs
  • Scores tool calls for risk
  • Works in-line or via API
Examples: HiddenLayer, Pillar Security, Lasso Security, Cisco AI Defense, and products now inside Check Point, SentinelOne, F5 and Palo Alto Networks
04

AI and LLM gateways

One path for all model traffic.

  • Routes calls across model providers
  • Holds keys and budgets per team
  • Adds filters and logging
  • Sometimes inspects tool calls
Examples: Kong, Cloudflare, Portkey, LiteLLM, Databricks. Full list: AI gateway vendors
05

MCP security and MCP gateways

Control the tool servers agents connect to.

  • Scans MCP servers for risky tools
  • Keeps an approved server list
  • Filters tools per agent
  • Logs every tool call
Examples: Docker MCP Gateway, IBM ContextForge, Amazon Bedrock AgentCore Gateway, Operant AI, Snyk (after acquiring Invariant Labs)
06

Enterprise and AI browser security

The browser is where agents and people meet the web.

  • Controls what browser agents may do
  • Governs AI extensions
  • Stops data pasted into AI tools
  • Records sessions for audit
Examples: Island, Palo Alto Networks Prisma Access Browser, LayerX, Menlo Security, Seraphic Security
07

Red teaming and evaluation

Attack the agent before an attacker does.

  • Automated attack runs against agents
  • Tests injection through web pages and files
  • Scores risk before release
  • Repeats after every change
Examples: Mindgard, Promptfoo, Giskard, Lakera Red (now part of Check Point)
08

AI governance and compliance

Policies, inventories and evidence for auditors.

  • Keeps a register of AI systems and agents
  • Maps them to frameworks and laws
  • Tracks approvals and owners
  • Produces audit evidence
Examples: Credo AI, Holistic AI, OneTrust, IBM watsonx.governance, ServiceNow AI Control Tower
09

Agent observability

See what agents actually did, step by step.

  • Traces each step and tool call
  • Measures cost and latency
  • Flags unusual behaviour
  • Supports incident review
Examples: Arize, Langfuse, Galileo, Datadog LLM Observability, LangSmith
10

Web page policy data

The data that tells every other layer what a URL is.

  • 28 page types per domain
  • 40M+ domains classified
  • About 40 egress URL rules
  • About 60 high-risk hosts
This site: an AI agent allow list delivered as API, on-premise database or OEM license. See the page types database.
Consolidation

Eight acquisitions that reshaped the map

Large security vendors bought AI security startups quickly. Buyers now often meet these products inside a platform.

Cisco acquires Robust Intelligence (2024)

Became part of Cisco AI Defense.

Palo Alto Networks acquires Protect AI (2025)

Model and AI application security folded into its platform.

Snyk acquires Invariant Labs (2025)

Agent and MCP security research joined a developer security platform.

Cato Networks acquires Aim Security (2025)

AI usage security added to a SASE platform.

SentinelOne acquires Prompt Security (2025)

Runtime AI protection joined an endpoint and cloud platform.

CrowdStrike acquires Pangea (2025)

AI guardrail services added to its platform.

F5 acquires CalypsoAI (2025)

AI runtime security joined an application delivery vendor.

Check Point acquires Lakera (2025)

Prompt injection defence joined a network security vendor.

The pattern: platforms buy runtime protection. Data layers, such as page-type data, tend to be licensed rather than rebuilt.

Names analysts use for these categories

AI TRiSMGartner's umbrella for AI trust, risk and security management.
AI-SPMAI security posture management, an extension of cloud posture tools.
NHI managementNon-human identity, covering service accounts, keys and agents.
AI runtime securityIn-line protection of prompts, outputs and tool calls.
Agent governanceRegisters, policies and approvals for AI agents.
Secure web gatewayThe classic place where URL policy lives, now meeting agent traffic.
Risk to category

Which category answers which agent risk

Agent riskPrimary categorySupporting category
Unknown agents running in the companyAI-SPM (01)Governance (08)
Over-privileged agent credentialsNon-human identity (02)AI-SPM (01)
Hidden instructions on a web pageRuntime protection (03)Page policy data (10)
Agent creates accounts or buys thingsPage policy data (10)Browser security (06)
Risky third-party MCP serverMCP security (05)Red teaming (07)
Uncontrolled model spendAI gateway (04)Observability (09)
Agent posts or uploads to public sitesPage policy data (10)Runtime protection (03)
No audit trail for an incidentObservability (09)Governance (08)
Regulator asks for an agent registerGovernance (08)AI-SPM (01)

Two rows depend mainly on category 10. Those are the rows where an agent acts on the open web.

Category 10 in numbers

The data behind page-level control

Runtime tools judge text. Page policy data judges the destination, before the request leaves.

40M+Domains
28Page types
8Action types
$99API from, per month

The 8 action types are signup, password_reset, cart, checkout, upload, post_create, comment and subscribe. Denying them by default removes most of the ways an agent can act on a site.

The 20 read types, such as pricing, documentation and status, stay open, so research agents keep working.

Starter stacks

Three ways to assemble the categories

First agent pilot

  1. AI gateway with budgets
  2. Page policy data in the fetch tool
  3. Observability traces
  4. A short approved-tools list

Scaling to many teams

  1. AI-SPM to find every agent
  2. Non-human identity for credentials
  3. MCP gateway with approved servers
  4. Page policy data at the egress proxy
  5. Runtime protection on high-risk agents

Regulated enterprise

  1. Governance register and approvals
  2. Identity with short-lived credentials
  3. Page policy data licensed on-premise
  4. Red teaming before each release
  5. Full audit logging of every decision

A 90-day plan for a security team starting from zero

Days 1 to 30: find and log

Inventory every agent and its credentials. Log every URL agents request, tagged by page type.

Days 31 to 60: close the action paths

Deny the 8 action page types by default. Approve MCP servers one by one.

Days 61 to 90: harden and prove

Add runtime protection to the riskiest agents. Run a red-team exercise and keep the evidence.

Evaluating any vendor

Eight questions that work in every category

1. What does it see?

Prompts, tool calls, credentials or page loads.

Why it matters

A tool cannot control traffic it never sees.

2. Can it block, or only alert?

Detection alone leaves the action to happen.

Why it matters

Agents act in seconds, faster than a human review.

3. Where does it run?

SaaS, your cloud, or fully on-premise.

Why it matters

Regulated teams may need the data to stay inside.

4. How does it fail?

Open or closed when the service is down.

Why it matters

For agents, closed is the safe default.

5. What evidence does it keep?

Per-decision logs with agent, target and reason.

Why it matters

Auditors and incident reviews need the trail.

6. Which agents does it cover?

Your own, vendor SaaS agents, browser agents.

Why it matters

Coverage gaps become the attacker's path.

7. What data does it depend on?

Its own research, or data it licenses.

Why it matters

Coverage and freshness decide real accuracy.

8. Does it plug into what you run?

Gateways, proxies, SIEM, identity provider.

Why it matters

A tool that stands alone becomes shelfware.

Who buys what

Which team usually owns each category

CategoryUsual ownerUsual budget line
01 AI-SPMCloud securityCloud security platform
02 Non-human identityIdentity and access teamIAM
03 Runtime protectionApplication securityAppSec or AI security
04 AI gatewaysAI platform teamAI platform
05 MCP securityAI platform with AppSecAI platform
06 Browser securityEndpoint or network securitySASE or endpoint
07 Red teamingOffensive securityTesting services
08 GovernanceRisk, legal and complianceGRC
09 ObservabilityAI engineeringEngineering tools
10 Page policy dataNetwork security or AI platformSecurity data feeds

Category 10 often sits next to existing web filtering feeds. Teams that already license URL category data add page types to the same contract line.

For vendors on this map

Why security vendors license page data

Building it is slow

Mapping login and checkout pages on tens of millions of domains is a large crawl and classification job.

Licensing is fast

An OEM license ships the data inside your product.

Guessing paths fails

Real login pages hide on subdomains, locales and app routes.

Verified URLs work

Each page-type URL in the data was found on the site, not guessed.

Customers ask for proof

"Would this have stopped the 2026 incidents?"

There is a replay

The incident analysis maps each step to the rule that denies it.

Options and prices are on the pricing page. Product teams in categories 03 to 06 are the usual OEM fit.

Gateway, browser and SASE vendors can check the data against their own traffic samples before signing.

What the 2026 incidents say about the map

  • Agents edited wikis, installed a plugin and uploaded datasets on third-party sites.
  • Each was an action on a web page, which sits in category 10 on this map.
  • In our replay, page data plus egress rules would have stopped almost all of them.
The 2026 agent incidents, prevented The DseWiki wiki hijack

The honest fine print — the same two assumptions we publish, plus two operational ones

  1. The policy engine must see every request — an agent with raw socket access or a second network path bypasses everything; enforcement belongs at the egress proxy/network layer, not only in an SDK hook.
  2. Default-deny must be on. In flag-only mode these become alerts within minutes rather than prevention — still a large improvement on a timeline measured in weeks (the DseWiki edits ran from late May to late June 2026, per the researchers), but not a block.
  3. For full URL+method matching on HTTPS you need to be the proxy or in-process hook — SNI alone shows only the host, which still catches the entire host-list layer.
  4. Policy can’t read intent inside a legitimately allowed action: an agent whose job is publishing packages keeps registry access. In our replay of the 2026 incidents, no crossing fits any plausible allowlist for the agents’ documented tasks.
Related

Keep reading

FAQ

Market map questions

What are the main agentic AI security categories?
Ten are useful for buyers: AI security posture, non-human identity, runtime protection, AI gateways, MCP security, browser security, red teaming, governance, observability and web page policy data.
Which agentic AI security companies should I look at first?
Start from your biggest risk. For unknown agents, look at AI-SPM. For credentials, non-human identity. For agents acting on websites, page policy data and browser security.
Is the market consolidating?
Yes. Cisco, Palo Alto Networks, SentinelOne, Check Point, F5, CrowdStrike, Snyk and Cato Networks all bought AI security startups in 2024 and 2025.
Where does an AI agent allow list fit?
In category 10. It supplies page-type data that gateways, proxies and browsers use to allow or deny each URL before an agent opens it.
Can a runtime firewall replace page policy data?
No. A runtime firewall judges text for injected instructions. Page policy data judges the destination. An agent with a clean prompt can still reach a checkout page.
What is AI TRiSM?
AI TRiSM is Gartner's term for AI trust, risk and security management. It groups governance, runtime protection, data protection and model operations, and most categories on this map fall under it.
Do I need a separate vendor for each category?
No. Platforms increasingly cover several categories. Check which layers a platform covers fully, and fill the gaps, often identity and page-level web control, with specialists.
How can a vendor on this map add page data?
Through the lookup API from $99 a month, an on-premise database from $14,999, or an OEM license agreed per product. Start with the free sample.

Fill category 10 in your agent security stack

Test page-type data on 100 real domains, then choose API, on-premise or OEM.

Download the sample