TL;DR: KuppingerCole’s 2025 Leadership Compass says securing AI depends on securing APIs first, with Salt Security cited for agentless API visibility, AI-powered threat detection, posture governance, and support for LLM-specific protections across REST, GraphQL, SOAP, and gRPC. The wider message is that API security is moving from point products to lifecycle governance, and identity-linked access controls now matter as much as detection.
NHIMG editorial — based on content published by Salt: KuppingerCole API security leadership analysis
Questions worth separating out
Q: How should security teams govern API access as a non-human identity?
A: Security teams should inventory APIs as identities, assign an accountable owner, and enforce lifecycle controls for issuance, rotation, expiry, and revocation.
Q: What breaks when API discovery is incomplete?
A: When discovery is incomplete, security teams miss shadow APIs, forgotten integrations, and endpoints that no longer have an obvious owner.
Q: How do you know if API threat detection is working?
A: You know it is working when the team can separate normal automation from suspicious request sequences without drowning in false positives.
Practitioner guidance
- Inventory all externally reachable APIs Build a continuously updated inventory that ties each API to an owner, authentication method, data sensitivity, and downstream systems.
- Bind API policies to service identity Require token scope, service account ownership, and operation-level authorisation to be defined together for sensitive endpoints.
- Tune detection for sequence abuse Monitor request chains, unusual call ordering, and high-risk operations invoked from otherwise legitimate identities.
What's in the full article
Salt's full analysis covers the operational detail this post intentionally leaves for the source:
- How Salt Security maps agentless API discovery and posture governance across distributed environments.
- The report's breakdown of Product, Innovation, and Market leadership criteria in KuppingerCole's scoring model.
- Details on the patented intent analysis engine and Workflow Hub capabilities discussed in the source.
- The vendor's own explanation of LLM-specific protections and how it positions those controls in the market.
👉 Read Salt's analysis of KuppingerCole's API security leadership assessment →
API security leadership and AI threats: are your controls keeping up?
Explore further
API security is becoming an identity governance problem, not just an application security problem. The report’s emphasis on discovery, posture, and AI-driven detection reflects a category shift. APIs increasingly depend on service accounts, tokens, and workload identities, which means API security decisions now influence access governance across human and non-human identities alike. Practitioners should treat API inventory, authentication, and authorisation as shared control objectives.
A question worth separating out:
Q: Should organisations rethink API controls when AI systems rely on them?
A: Yes. When AI systems depend on APIs, those interfaces become part of the AI control plane and inherit higher trust, higher volume, and more complex failure paths. Organisations should re-evaluate authentication, token scope, auditability, and sensitive-operation policy before expanding AI integrations. Otherwise, AI adoption quietly broadens the access surface faster than governance can keep up.
👉 Read our full editorial: API security leadership is shifting toward full-lifecycle protection