16 Best AI Security Tools and Platforms in 2026
TL;DR
- App and agent security, for the AI feature you built: Mindgard, Zenity, Lasso Security.
- AI-SPM, an inventory of the AI you run: Wiz, Microsoft Defender for Cloud, Noma Security, Trent.
- AI data security, if the data your AI reads must not leak: Cyera, CrowdStrike AI security.
- Model and supply chain security, if you pull in outside weights and packages: Prisma AIRS, HiddenLayer, Chainguard.
- AI usage control, for tools staff picked themselves: Prompt Security, inside SentinelOne.
- LLM guardrails, if you need blocking in the request path: Lakera, F5 AI Guardrails, Cloudflare.
- Open source to start: Garak probes your model, promptfoo keeps those checks in CI.
- Six of the 16 changed hands in two years.
What is an AI security tool?
An AI security tool protects the AI apps, agents, models and data you run from attacks like prompt injection and data leaks. It is a different product from an AI-powered tool that helps a security team do its existing job, and the two share one search term. The section below separates them.
Five things get protected here: the apps you ship, the agents that hold credentials and reach tools and MCP servers, the models you pull in, the data those systems read and put into prompts, and the AI tools your staff picked without asking. Few products cover more than two of the five well, which is why this list is grouped, not ranked. Our explainer on agentic AI security sets out the wider problem.
A new category
Trent is an AI Security Engineer
Most security tools cover one layer: code, cloud, data or AI. Attackers don’t stay in one layer. They chain a weak config, a vulnerable function and an over-permissioned agent into one path. An AI Security Engineer works the way a security engineer does. It reviews your code, cloud configuration and AI agents together, follows the chain between them, and hands back a fix.
How we chose
Of course Trent is on this list, and not only because you are reading the Trent blog. So we grouped this list by category instead of ranking it. We state who owns each tool today, and we name the cases where another tool is the more logical choice.
Four tests, in order.
- It protects AI rather than using AI to do security work.
- It is a shipping product with a current vendor page, not a research project.
- Its capability is documented by the vendor or the repo, not inferred from a review site.
- Ownership is verifiable, with a date.
Documentation means published openly, or available to customers behind a login: of the 15 external tools, eleven publish open docs, two are login-gated (Noma Security and Cyera), and two publish marketing pages we could not confirm as backed by open docs (Wiz AI-SPM and Prompt Security).
We did not run these tools against a shared test application: this list compares what each does, who owns it and where it fits, not how well it performs. We checked every fact on primary vendor pages, filings and the GitHub API in September 2026.
Comparison table: 16 AI security tools at a glance
Owners, deployment and documentation state (checked September 2026).
| Tool | Category | Owner today | Where it runs | Documentation | Best for |
|---|---|---|---|---|---|
| Mindgard | App and agent | Independent, $30M Aug 2026 | SaaS, plus CI/CD | Public | Pre-release red teaming |
| Zenity | App and agent | Independent, $125M Aug 2026 | SaaS with connectors | Public, partly gated | Limiting an agent’s reach |
| Lasso Security | App and agent | Independent, $30M Sep 2026 | Inline proxy or gateway | Public API | Inline traffic classification |
| Wiz AI-SPM | AI-SPM | Google, closed 11 Mar 2026 | Cloud connector, agentless | Not verified | AI posture inside a CNAPP |
| Microsoft Defender for Cloud | AI-SPM | Microsoft, in house | Cloud connector, multicloud | Public | Azure and multicloud |
| Noma Security | AI-SPM | Independent, active Sep 2026 | SaaS or self-hosted | Login-gated | Enterprise agent risk mapping |
| Trent | AI-SPM | Trent AI | SaaS | Public pages | Teams that want code, cloud and agents reviewed together |
| Cyera | Data security | Independent, $600M Jun 2026 | Cloud connector, agentless | Login-gated | Sensitive data discovery |
| CrowdStrike AI security (Pangea) | Data security | CrowdStrike, closed 26 Sep 2025 | API and SDK, inline | Public | Data-leakage guardrails |
| Palo Alto Networks Prisma AIRS | Supply chain | Palo Alto Networks | Gateway, SDK, connector | Public | AI security on an existing estate |
| HiddenLayer | Supply chain | Independent, $100M Sep 2026 | Python SDK, cloud connector | Public | Model scanning, AIBOM output |
| Chainguard | Supply chain | Independent, $356M Apr 2025 | Registry, container images, pip | Public | Hardened AI images and packages |
| Prompt Security (SentinelOne) | Usage control | SentinelOne, closed 5 Sep 2025 | Browser, endpoint, gateway | Not verified | Shadow AI inventory |
| Lakera (Check Point AI Security) | LLM guardrails | Check Point, closed 22 Oct 2025 | Inline API or gateway | Public | Prompt injection screening |
| F5 AI Guardrails (CalypsoAI) | LLM guardrails | F5, closed 26 Sep 2025 | Inline at inference | Public API | Inference-layer screening |
| Cloudflare AI security suite | LLM guardrails | Cloudflare, in house | Gateway, edge-hosted | Public | Teams already on Cloudflare |
AI application and agent security
Everything here protects the AI app or agent you built. The AI agent security tools below split along one line: attack it before release, or control what it can reach once it is running. Our page on AI application security goes into the code side. Ownership and funding facts (checked September 2026).
1. Mindgard. Automated adversarial red teaming that maps, plans and runs multi-step agentic attack workflows against your AI app. Testing is black box: an inference or API endpoint is enough. It runs as SaaS and in CI/CD via a GitHub Action. Still independent, with a $30 million Series A announced 12 August 2026, total funding around $42 million. No public price. To fence in a deployed agent, Zenity is the more logical choice.
2. Zenity. Security and governance built around AI agents, in three parts: Observe, Govern and Defend. It reads an agent’s whole execution path: tool calls, memory access and data flows, not prompt text alone. Norwest led a $125 million Series C announced August 2026, and Zenity is independent.
3. Lasso Security. No acquirer so far, and a $30 million round led by ClearSky announced 2 September 2026. It puts an inline layer over genAI and agent traffic at the proxy, API or AI gateway: a documented POST /classify endpoint scores prompts for injection, jailbreak and PII, returning BLOCK, WARN or AUTO_MASKING. Its open-source MCP Gateway inspects tool-call traffic (see our post on MCP security). Its own pricing URL returns 404, and its detection figures are vendor-reported.
Prompt injection is a reach problem
An injected prompt only matters if the agent can do something with it. Trent maps what each agent can read, write and run.
AI security posture management (AI-SPM)
AI security posture management is an inventory of the models, agents, AI services and MCP servers you already run, and of what each can reach. An AI security scanner that reads traffic will not tell you what exists. Three of the four below discover by connecting to a cloud account (checked September 2026), so they come before the one that discovers from source code: a mechanism difference, not a ranking.
4. Wiz AI-SPM. Wiz has sat inside Google Cloud since the acquisition closed on 11 March 2026 at $29.5 billion, the closing figure not the announced one, and it kept its own brand. It finds where your AI systems can expose sensitive data and flags publicly exposed inference endpoints, using the Wiz Security Graph across infrastructure, identity, models, data and applications. Workload Explainer surfaces models, agents, tools and data flows that your configuration never documented.
5. Microsoft Defender for Cloud (AI security posture). The Defender CSPM plan secures generative AI applications and AI agents, the agent side in preview, with attack path analysis that flags data exposed during grounding and fine-tuning. It connects to Azure, AWS and GCP, plus hybrid estates through Azure Arc. One catch: from 1 July 2026, AI agent discovery and posture for Microsoft Foundry and third-party cloud agents need a Microsoft Agent 365 licence, previously bundled into Defender CSPM.
6. Noma Security. Discovers, governs and protects the AI and agents across your estate, from homegrown AI to SaaS agents and coding assistants, with a module named AI-SPM at its centre. Noma had not been acquired as of its most recent confirmed activity, 28 September 2026, and has raised about $132 million. Its Agentic Risk Map lays out each agent’s connections, tools, identities and data sources, so risky combinations stand out.
7. Trent. Trent is an AI Security Engineer. The three tools above connect to a cloud account and inventory what runs there. Trent works from the other end: point it at your source and it reconstructs the architecture from the real code and configuration, then inventories every component from traditional services and DBs to agents, tools, skills and MCP servers, tagging each by what it can do: Read, Write, Execute, Egress. It draws the capability graph and traces each attack chain through your components, mapped to MITRE ATLAS. Trent proposes the fix, your coding agent applies it, and Trent confirms it landed. Trent is a SaaS application with a web UI, and MCP-compatible agents like Claude Code, Codex and Cursor can also connect to its remote MCP server. The boundary: Trent reads your source, not your runtime. It is not a guardrail, proxy, DLP tool or pen test, and it blocks nothing in the request path. If you need an inventory of what already runs in a cloud account, Wiz, Microsoft Defender for Cloud or Noma Security is the more logical choice. Access and pricing available on request. Request access.

AI data security
The data feeding AI is the subject here: training sets, vector stores, retrieval sources and whatever ends up inside a prompt. Both entries carry pricing facts checked September 2026. Our explainer on RAG security takes the retrieval side. Trent is absent here on purpose: it flags data stores your agents can reach and grades the exposure, but it does not classify data at rest, this category’s core job.
8. Cyera. A data security company applied to AI: context on where your data sits, who can reach it and how it moves. Cyera claims the classification engine auto-learns and reaches 95% accuracy, a vendor-reported figure with no independent benchmark. The company is still independent, and closed a $600 million round at a $12 billion valuation in June 2026. Its pricing page asks for a custom quote.
9. CrowdStrike AI security (Pangea). Inline guardrail calls you add to a genAI application through an API and SDK, covering data-leakage prevention and jailbreak defence. CrowdStrike announced an agreement to acquire Pangea on 16 September 2025 and closed it on 26 September 2025. It now sells as the interaction layer of CrowdStrike’s AI detection and response inside Falcon, not as a standalone Pangea product. Reported deal figures differ between trade press and the SEC filing, so we print neither.
Model and supply chain security
The weights, model files and packages you pull in are code you did not write, loaded by a process that trusts it. Two of the tools here scan those artefacts and record what went into a model, and Chainguard rebuilds the packages and images from source. Our research on the OpenClaw skill supply chain finds the same problem in agent skills. Ownership facts (checked September 2026).
10. Palo Alto Networks Prisma AIRS. Palo Alto Networks’ own product, covering AI applications, models, agents and infrastructure from development through governance. It sits here because Palo Alto completed its acquisition of Protect AI on 22 July 2025 and folded Guardian model scanning into Prisma AIRS. Protect AI is no longer a standalone purchase. No deal price was disclosed. API Intercept names granular detection categories, from prompt injection and sensitive data loss to malicious code and secure MCP.
11. HiddenLayer. Detection and response for generative and traditional AI models, covering prompt injection, adversarial attacks and digital supply chain weaknesses. Every scanned model gets an auto-generated AIBOM, the vendor’s equivalent of a software SBOM, with stated coverage of more than 35 model formats. Still independent on more than $155 million raised, most recently a $100 million Series B led by Delta-v Capital announced 2 September 2026.
12. Chainguard. Rebuilds the open source your AI stack pulls in and serves it from its own registry: hardened AI and ML container images such as PyTorch and TensorFlow, and Python libraries, including the data science and CUDA stack, built from source with signatures, SBOMs and provenance. It does not scan model files you already have. For that, HiddenLayer is the more logical choice. Still independent, with a $356 million Series D led by Kleiner Perkins and IVP announced 23 April 2025 at a $3.5 billion valuation. Catalog containers start at $19,000 for a team of 10. The libraries are quote only.
AI usage control (shadow AI)
Shadow AI is the chatbots and coding assistants your staff signed up for without telling anyone, and the company data that goes into them. The category was crowded two years ago, and most of it folded into larger suites, so one entry stands here instead of four, with its ownership facts checked September 2026.
13. Prompt Security (SentinelOne). SentinelOne signed to acquire it on 5 August 2025 and closed on 5 September 2025, and it now ships inside SentinelOne Singularity, with per-user SKUs by quote. It inventories every AI tool and code assistant in use, including unsanctioned ones, redacts sensitive data and enforces policy at the point of use. The vendor states coverage of more than 15,000 AI services, which we could not verify independently. For governing employee AI use, this is the more logical choice than any code-reading assessment tool, Trent included.
LLM guardrails and red teaming
A guardrail sits in your request path and screens what goes into a model and what comes back, blocking or rewriting whatever breaks policy. Our explainer on what LLM guardrails are covers the mechanics. Red teaming is the mirror image, attacking the app before release, and all three here sell both. The category overlaps the wider set of LLM security tools, with owner facts checked September 2026.
14. Lakera (Check Point AI Security). Lakera Guard is an inline API that screens your LLM traffic for prompt injection, jailbreaks and data leakage. Lakera Red is a separate red-teaming product. Check Point announced an agreement on 16 September 2025 and closed on 22 October 2025 for about $190 million in net cash consideration, per its own earnings release. No public price for the product, and detection figures are vendor-reported.
15. F5 AI Guardrails (CalypsoAI). It screens at the inference layer, paired with F5 AI Red Team for automated adversarial testing, through a documented REST API and Python SDK. F5 announced an agreement to acquire CalypsoAI on 11 September 2025 for a stated $180 million in purchase consideration and closed on 26 September 2025. Its SEC 10-Q reportedly records $145.2 million in cash at close, a different measure. No public price for the product.
16. Cloudflare AI security suite. Firewall for AI detects prompt injection attempts and topic abuse in front of LLM API calls at Cloudflare’s edge, and AI Gateway’s firewall adds DLP scanning of requests. General DLP categories come with Zero Trust at no extra cost. Custom profiles need an upgraded plan with no published figure. If the job is stopping a bad prompt mid-flight, you want a guardrail, not an assessment tool. Trent does not do this.
AI security tools vs AI-powered security tools
Two product categories answer the phrase “AI security tools”, and about half the results mean the other one.
| What the phrase means | The job it does | Who buys it |
|---|---|---|
| Tools that secure AI (this list) | Inventory an app’s agents and MCP servers, trace the path from a customer message to a shell tool | The team that shipped the AI feature: application security, platform engineering, the ML lead |
| Tools that use AI to do security (another list) | Triage a SOC alert queue, or review a pull request with a model | The team defending the company: SOC analysts, detection engineers, the CISO |
One question sorts them: is AI the thing you are protecting, or the thing doing the protecting? Engineers who just shipped an agent that can send email and query a database want the top row. Analysts drowning in alerts want the bottom.
What changed in AI security since 2024
Google closed its acquisition of Wiz on 11 March 2026. It was announced on 18 March 2025 at about $32 billion and closed at $29.5 billion after purchase price adjustments, the largest deal touching this list and the most recent to complete. Wiz joined Google Cloud and kept its own brand: being acquired does not always mean the product name survives. Lakera, CalypsoAI, Pangea and Protect AI all lost theirs.
Dates and owners (checked September 2026). Palo Alto Networks completed Protect AI on 22 July 2025 and folded Guardian into Prisma AIRS. SentinelOne closed Prompt Security on 5 September 2025. CrowdStrike closed Pangea and F5 closed CalypsoAI, both on 26 September 2025. Check Point closed Lakera on 22 October 2025. OpenAI announced an agreement to acquire promptfoo on 9 March 2026. As of 29 September 2026 no public source confirms it has closed.
Six of the 16 tools here changed hands in the last two years, seven are still independent, and three were built inside a large vendor. Shop from a list published a year ago and you will shortlist vendors that no longer sell under their own name.
What can your agents actually reach?
Trent maps each agent to its tools and data, then traces the attack chains a prompt injection could follow.
Request accessOpen source AI security tools
You can start without a budget. Six open-source projects do real AI security work, and all six were updated in September 2026. Here is what each one is for.
Garak (NVIDIA) attacks your model the way an outsider would. Point it at a live model and it tries prompt injection, jailbreaks, data leaks and false answers, then reports what got through. Start here if you want to know whether your model has a problem at all.
PyRIT (Microsoft) is for teams that write their own red-team attacks and want to run them again after every change. If you follow an older tutorial, check the link: Microsoft archived the old Azure repo, and the current one is microsoft/PyRIT.
NeMo Guardrails (NVIDIA) lets you write the rules for what your chatbot may and may not say as code, so a reviewer can read and approve them like any other change.
Guardrails AI checks what goes into a model and what comes out. You combine small named checks, called validators, into one guard.
ModelScan (Protect AI) checks a model file for hidden code before you load it. A downloaded model can carry code that runs the moment you open it. ModelScan is the open-source engine behind Guardian, the product Palo Alto Networks now owns.
promptfoo runs tests and red-team checks on your AI app inside your CI pipeline, so a change that makes the app easier to attack shows up before it ships. OpenAI agreed to acquire promptfoo on 9 March 2026, and promptfoo says the project stays open source.
| Project | GitHub repo | Licence | GitHub stars |
|---|---|---|---|
| promptfoo | promptfoo/promptfoo | MIT | about 25,500 |
| Garak | NVIDIA/garak | Apache-2.0 | about 9,400 |
| Guardrails AI | guardrails-ai/guardrails | Apache-2.0 | about 7,500 |
| NeMo Guardrails | NVIDIA-NeMo/Guardrails | Apache-2.0 | about 7,200 |
| PyRIT | microsoft/PyRIT | MIT | about 4,600 |
| ModelScan | protectai/modelscan | Apache-2.0 | about 780 |
All free to use. Licences and stars from GitHub, checked September 2026.
The no-cost path costs your own time: no support contract, no SLA, and no one on call when a probe suite breaks before a release.
How to choose an AI security tool
If you have a security team. Choose by what you are protecting and what you already own: the AI security solutions you can deploy this quarter matter more than the ideal ones you cannot. Already running Wiz or Defender for Cloud as your CNAPP? Turn on its AI posture coverage before buying anything new. Sensitive data across the stores AI systems read: Cyera. Model files from outside: HiddenLayer or Prisma AIRS. Open source packages and images your AI stack pulls in: Chainguard. What staff paste into chatbots: Prompt Security. Code, cloud and the agents your engineers built, reviewed together: Trent.
If you have no security staff. Start with what your AI apps and agents can reach, because that is the risk you cannot see and cannot undo. Write down every agent, tool, skill and MCP server, and what each can read, write, execute and reach outward. Then add one open-source probe: Garak against the model you ship, promptfoo to keep those checks in CI. If your traffic already crosses Cloudflare, its AI suite is the shortest route into the request path. Our post on build versus buy covers what rolling your own costs.
Three cases where you want something other than Trent: blocking a bad prompt in flight, which is Lakera, F5 AI Guardrails or Cloudflare. Then classifying sensitive data at rest, which is Cyera, and seeing what employees paste into chatbots, which is Prompt Security.
Where to start

Do the inventory before you shop. Write down every AI app, agent, tool, skill and MCP server you run, and what each can read, write, execute and reach outward. That list names which of the six categories above is your problem, usually one. Then run Garak against the model you ship: an afternoon’s work that tells you whether there is a problem worth a budget.
Reviewed by Zack Rossman Head of Engineering at Trent AI
See the attack chain, not just the bug
Trent shows how findings connect into a real path, and which single fix breaks it.
FAQ
What are the best AI security tools?
It depends which of the five surfaces you are protecting. The app or agent you built: Mindgard, Zenity, Lasso Security. An inventory of the AI you run: Wiz, Microsoft Defender for Cloud, Noma Security, Trent. Data: Cyera. Model files and packages: HiddenLayer, Prisma AIRS, Chainguard. The request path: Lakera, F5 AI Guardrails, Cloudflare.
What are the top AI security risks?
Prompt injection, sensitive data disclosure, excessive agency where an agent can do more than its task needs, and supply chain risk from models and packages you did not write. The agentic set is covered in our post on the OWASP Top 10 for agentic applications.
Are there free AI security tools?
Yes. Garak, PyRIT, NeMo Guardrails, Guardrails AI, ModelScan and promptfoo are open source under Apache-2.0 or MIT, with licences and stars above. Garak plus promptfoo will carry a small team through a quarter. You pay in your own time, with no support and no SLA.
What is the difference between AI security tools and AI-powered security tools?
AI security tools protect AI systems: apps, agents, models and data. AI-powered security tools use AI to do security work a team already did, such as triaging alerts or reviewing code. Same phrase, opposite jobs.