Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AI security vendor categories: which risks should teams prioritise?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: AI security buying is splitting into five categories, with agent and MCP security, LLM runtime protection, AI posture and governance, AI-native SOC, and enterprise platforms each addressing different risks, according to Akto’s analysis. The practical question is no longer which vendor is best, but which control layer matches the specific AI exposure you actually need to govern.

NHIMG editorial — based on content published by Akto: Best AI Security Vendors and Companies in 2026

By the numbers:

  • 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%).

Questions worth separating out

Q: How should security teams govern AI agents that choose tools at runtime?

A: Security teams should treat runtime tool choice as a governed access event, not a normal application call.

Q: Why do AI agents complicate traditional IAM and PAM controls?

A: AI agents complicate IAM and PAM because they can make decisions, chain tools, and act faster than human review cycles can respond.

Q: What breaks when AI security is treated only as model security?

A: Model-only security misses the part of the system that actually touches tools, data, and workflows in production.

Practitioner guidance

  • Map AI controls by risk category Separate agent and MCP security, prompt protection, posture governance, and detection into distinct control requirements before selecting tooling.
  • Inventory delegated AI access paths Document every AI agent, model, tool connection, API, and database path that can execute actions or retrieve sensitive data.
  • Apply least privilege to agent tool access Limit each agent to the smallest set of tools and data scopes needed for its task, and review whether those permissions are session-bound or persistent.

What's in the full article

Akto's full article covers the vendor-by-vendor feature detail this post intentionally leaves for the source:

  • Category-by-category vendor comparisons across agent security, prompt protection, posture governance, SOC, and enterprise platforms
  • Named examples of how specific vendors position runtime enforcement, discovery, red teaming, and compliance workflows
  • Practical shortlist criteria for deciding whether a specialist or platform approach fits your environment
  • The article's own evaluation framing for which categories matter most in 2026

👉 Read Akto's category map of AI security vendors and agentic AI risks →

AI security vendor categories: which risks should teams prioritise?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

AI security is converging on identity governance, even when vendors market it as a model or runtime problem. The article’s category split shows that the hardest AI security questions are increasingly about authority, delegation, and scope. When agents can call tools, access data, or trigger workflows, they behave like non-human identities with dynamic runtime behaviour. That means IAM and PAM teams cannot treat AI as a separate security island. The practitioner conclusion is straightforward: AI governance must include identity-bound controls for every agent and tool path.

A question worth separating out:

Q: How should organisations decide between specialist AI security tools and platform vendors?

A: They should decide based on the primary risk category, then map the control gap they need to close. If the problem is agent-to-tool access, specialist agent security is more relevant. If the gap is broader coverage and existing stack integration, platform vendors may fit better, but identity governance still needs explicit ownership.

👉 Read our full editorial: AI security vendor categories are fragmenting around agent risk



   
ReplyQuote
Share: