Mapping the AI Security Landscape

Mapping the AI Security Landscape & How To Get Real Visibility

Shaun Archer

9/28/20268 min read

world map poster
world map poster

Mapping the AI Security Landscape & How to Get to Real Visibility

Every security team is currently trying to answer the same four questions about AI, in the same order, whether they've said so out loud or not. Where are our agents. What can they do. What are they actually doing. And when one of them does something wrong, how do we respond. The market has organised itself around those four questions almost exactly, which makes it a useful map for a landscape that otherwise looks like a hundred logos with no obvious order.

The AI security landscape

Three things are happening at once, and each one is expanding the problem on its own.

The first is agent sprawl. Agents are standing up inside Copilot Studio, Azure AI Foundry, Bedrock, and Vertex, and a growing share of them reach the outside world through tool-calling protocols like MCP, giving an agent the ability to call internal APIs on its own initiative rather than just answering a prompt. Gartner's widely cited projection is that the average Fortune 500 enterprise will run over 150,000 agents by 2028, up from fewer than 15 in 2025. Adoption has already outrun governance. Well over half of organisations report having agents in production, and observability and evaluation are consistently named the weakest link in how they're run.

The second is shadow AI. Employees adopted AI tools faster than anyone could write policy for them, and most of that adoption happens through personal accounts, browser extensions, and OAuth grants nobody reviewed, none of which show up in an identity provider's sign-in log or an existing DLP rule.

The third is that the attack surface it all creates is now standardised enough to have its own OWASP list. The OWASP MCP Top 10 names tool poisoning, prompt injection through contextual payloads, privilege escalation through scope creep, and shadow MCP servers among the most critical risks in agent-to-tool communication, which tells you the industry has moved past treating this as speculative risk and started treating it as a known, recurring pattern.

Those three forces, sprawl, shadow adoption, and a standardised new attack surface, are why the vendor landscape has grown so quickly, and why it has consolidated just as quickly behind it.

Which tools exist for each problem

The tooling splits cleanly along the same four questions, and it's worth being precise about which question each category actually answers, because vendors routinely market across the boundary.

Discovery tools answer where are my agents. They work in one of three ways. Browser and desktop-edge monitoring watches for AI tool usage at the point of access. Identity and SaaS-layer discovery reconstructs AI usage from OAuth grants and app-to-app connections. Agentless AI-SPM scanning inventories models, datasets, and agent deployments across cloud and SaaS estates.

Posture tools answer what can they do. This is where AI-SPM overlaps with a newer, more specific category built around non-human identity and agent identity governance, whose entire job is resolving what a given agent or service credential is actually entitled to reach, not just that it exists.

Runtime and behavioural tools answer what are they doing. This covers MCP gateways and runtime guardrails that sit in the path of every tool call, AI-native DLP that inspects prompts and outputs for sensitive content leaving the organisation, and agent observability platforms that trace an agent's reasoning and execution path for drift, injection patterns, and anomalies.

Response tools answer how do I respond, and this is the thinnest layer of the four. It's largely built from the enforcement side of the runtime gateways (block or allow a tool call in real time), the containment side of identity platforms (revoke a credential, disable an agent identity centrally), and whatever SIEM or XDR integration lets an AI security finding join the same incident workflow as everything else.

What companies are actually trying to understand

Underneath the tooling, every serious AI security conversation reduces to the same four questions, and it's worth stating them plainly because they double as a maturity ladder later on.

  1. Where are my agents. Every AI tool, every agent, every MCP server, sanctioned or not, that has a live presence in the environment.

  2. What can they do. The permissions, OAuth scopes, and data each one can reach, and how that compares with what it actually needs.

  3. What are they doing. The behaviour, not the entitlement. What a given agent or tool is actually calling, and whether that's consistent with what "normal" looks like for it.

  4. How do I respond. Once something looks wrong, whether the organisation can contain it fast enough to matter, revoking a credential, blocking a tool call, or disabling an agent identity, rather than just logging that it happened.

The questions are cumulative. You can't answer question two with any confidence if you don't trust question one's inventory. You can't answer question three at all without question two's baseline of what's normal. And question four is only as fast as the weakest answer underneath it.

Who plays in each domain

The names below reflect public positioning as of late 2026, and the market is consolidating fast through acquisition. Treat category membership as a snapshot, not as permanent.

Discovery and shadow AI. Harmonic Security and dope.security lead on browser and desktop-edge detection, watching AI tool usage at the point of access. Reco and DoControl approach discovery through the identity and OAuth graph, treating shadow AI fundamentally as an identity problem. On the AI-SPM side, Wiz (now part of Google), Noma Security, Cranium, HiddenLayer, and Varonis (via its Atlas platform, built in part on its AllTrue.ai acquisition) provide agentless discovery of the broader AI estate, models, datasets, and pipelines included. Netskope, Zscaler, and Palo Alto Networks' Prisma AIRS bring AI visibility in as an extension of existing CASB and SSE platforms rather than as a standalone product.

Posture and entitlement. Non-human and agent identity governance has consolidated hard and fast. Oasis Security is now the last major independent pure-play vendor in the category, after Cisco absorbed Astrix Security and SailPoint acquired Entro Security, both in June 2026. Token Security focuses specifically on access review and certification for non-human identities, a workflow human-IAM tooling was never built to handle. On the SaaS posture side, AppOmni leads on depth of app coverage, Obsidian Security on identity-centred threat detection, and CrowdStrike (via its Adaptive Shield acquisition) on folding SaaS posture into a broader platform play. The identity providers themselves have all shipped a distinct, ownable agent identity type. Okta has Agent SSO, extended to Amazon Bedrock and opened to rival IdPs. Microsoft Entra has Agent ID, paired with the Agent 365 licence for full governance. Google Cloud has IAM Agent Identity, Ping Identity has its own agent identity offering, and CyberArk has Secure AI Agents.

Runtime and behaviour. MCP-specific security splits into scanners that vet a server before it's trusted and gateways that enforce policy on every tool call, with Invariant Labs (acquired by Snyk), Defend AI, Straiker, and Akto among the named players. AI-native DLP, purpose-built to catch sensitive content in prompts and outputs rather than retrofitted from file-based DLP, is led by Nightfall AI and Cyberhaven, with Cyberhaven notably extending into agent and MCP-server discovery on the endpoint through 2026. Agent observability, tracing an agent's reasoning path for drift and anomalies, is a newer and more fragmented field, with Arthur, Braintrust, and Confident AI among the more established names.

Response. This category barely exists as a standalone product yet. What there is lives inside the runtime gateways above (block a tool call in real time) and inside the identity platforms (revoke or disable an agent identity centrally). CrowdStrike has gone furthest towards packaging this as its own thing, positioning itself as an agentic identity provider in its own right, and Obsidian Security has extended its identity threat detection and response model to cover AI agent ecosystems specifically.

How to actually do this in practice

Buying a logo in each of the four categories above is not the same as achieving visibility, and most of the organisations furthest along didn't start by shopping. They started by sequencing.

Start with a real inventory, and be honest about how it has to be built. No single source, not the identity provider, not email, not OAuth records, sees the whole picture on its own. A locally running agent that talks to a tool through MCP doesn't necessarily touch an IdP sign-in log at all. A shadow AI tool accessed through a personal account doesn't touch a company OAuth grant. Getting to where are my agents in practice means combining identity-and-OAuth-graph signal with browser or endpoint-level signal, because each one sees a different slice and neither is complete alone.

Once the inventory exists, resolve entitlement before behaviour. What can they do has to be answered before what are they doing means anything, because a behavioural baseline is only useful once you know what's normal for that specific type of identity, and normal depends entirely on what it's allowed to touch. This is the step organisations most often skip, jumping straight to a monitoring tool without first having a trustworthy map of permissions to monitor against.

Treat behavioural monitoring as a baseline problem, not an alert-volume problem. The agent observability and runtime-guardrail tools above are only as good as the baseline they're comparing activity to, and a baseline that hasn't been given enough time or enough clean entitlement data behind it produces noise, not insight. This is the stage where most deployments stall, generating alerts nobody trusts enough to act on.

Design the response path before you need it, not after. The tooling gap in the response category is real, and it means most organisations have to hand-build the connection between an AI security finding and an actual containment action, a credential revocation, a tool-call block, an agent disablement, rather than buying it off the shelf. Decide in advance who owns that action and how fast it can happen, because the value of everything upstream collapses if the answer to how do I respond is "we open a ticket."

Where this lands on the visibility, insight, and action framework

The four questions map onto a maturity model that's been around in security operations for years, even if AI has made the gaps in it more visible than usual. Visibility feeds insight. Insight feeds action. You cannot generate an insight from something you never saw, and you cannot act on an insight you never generated.

Where are my agents and what can they do are both visibility questions, inventory and entitlement together, because neither one is behaviour yet. They're the precondition. An organisation that can't answer them with confidence doesn't have an AI security programme with gaps in it. It has telemetry with no programme attached.

What are they doing is the insight stage, and it only produces anything useful once the visibility underneath it is solid. A behavioural anomaly is only as trustworthy as the entitlement baseline it's measured against, which is why skipping straight to a monitoring tool, without first fixing inventory and posture, tends to produce a wall of alerts nobody has the context to act on.

How do I respond is the action stage, and it's the stage the market has invested in least, which is exactly why it's the stage most organisations should plan for deliberately rather than assume will exist by the time they need it.

Practically, that argues for a specific order of operations rather than a simultaneous buying spree. Fix discovery first, across both identity-graph and endpoint signal, because nothing else is trustworthy without it. Fix entitlement and posture second, so that whatever behavioural baseline gets built afterwards is measuring against a real map of what's allowed. Only then invest seriously in behavioural detection, because it inherits the quality of everything underneath it. And build or buy the response path deliberately, rather than discovering during a real incident that how do we respond was never actually answered.

Every stage of that ladder is a taxonomy problem before it's a tooling problem. Visibility, the kind that actually produces insight and action, starts with correctly classifying what you're looking at, human, non-human, agent, and knowing what each is allowed to do. Everything the market above is selling is an attempt to answer one of the four questions faster. None of it works if the classification underneath it was never solid to begin with.

Stay

Get weekly cyber tips straight to your inbox

Contact

NEWSLETTER

shaun@shaunarcher.co.uk

© 2026. All rights reserved.