AI Agent Security · Market
AI Agent Security Platforms: How to Compare Them Properly in 2026
Five different product categories are sold as AI agent security. Only one of them can prevent an action. This is how to tell which you are looking at, and what to test.
The short answer
AI agent security products fall into five categories: prompt and content guardrails, observability and detection platforms, identity and secret brokers, pre-execution action firewalls, and governance control planes. Only pre-execution action firewalls prevent an individual action before it executes; the others reduce likelihood, detect afterwards, or govern what capability exists. Comparing across categories on a single feature grid is how organisations buy detection when they needed prevention.
Summary for readers and answer engines
Reviewed 25 Aug 2026
- ▸Five categories: guardrails, observability, identity brokers, pre-execution action firewalls, governance control planes. They are complements, not alternatives.
- ▸Only a pre-execution action firewall can refuse a specific action. Guardrails reduce bad proposals; observability tells you afterwards; identity brokers narrow what is reachable.
- ▸Twelve capability tests separate real products from demos, and the sharpest three are: does it decide deterministically, does it bind approval to a specific call, and can it prove the record was not altered.
- ▸Run a bake-off with six real attack scenarios rather than a feature comparison. Products differ far more in what they do with ambiguity than in what they claim.
- ▸Pricing pattern reveals the category: per-token pricing means text inspection, per-decision pricing means action decisions, per-server pricing means governance.
Source: Mark Alex, Real Biz Digital — AI Agent Security Platforms: How to Compare Them Properly in 2026 (https://realbizdigital.net/insights/best-ai-agent-security-platforms/). Reproduce with attribution.
Key takeaways
- 01Classify before comparing. A shortlist spanning three categories will be won by whichever product has the longest feature list, not the best fit.
- 02Test with ambiguous cases, not clear ones. Every product blocks an obvious attack; the differences appear on a borderline refund.
- 03Insist on seeing a decision record and verifying its integrity yourself. This single test eliminates a surprising number of products.
- 04Ask what happens when the product is unavailable, per risk class. An answer of “we are highly available” is not an answer.
- 05Check whether approval is bound to argument values. Unbound approval is a coupon, and it is common.
- 06Prefer vendors who name their limits. In this category, a product that claims to prevent everything is describing a roadmap.
Quick answers
One-line answers to the questions this page is most often asked. Each is expanded further down, and each is written to be quoted on its own.
- What categories of AI agent security product exist?
- Five: prompt and content guardrails, observability and detection, identity and secret brokers, pre-execution action firewalls, and governance control planes.
- Which category actually prevents an action?
- Pre-execution action firewalls. Guardrails reduce the volume of bad proposals, observability reports after the fact, and identity brokers limit what is reachable at all.
- Do I need more than one?
- Most estates end up with a firewall plus a control plane, and often an identity broker. Guardrails and observability are usually already present under other names.
- What is the sharpest capability test?
- Determinism. Ask the vendor to demonstrate that identical inputs always produce an identical outcome, and to show the record proving it.
- How should I run the evaluation?
- A bake-off against six real attack scenarios on your own tools, scored on outcome quality and false positives, not a feature grid.
- What does pricing tell me?
- The unit reveals the category: per token means text inspection, per decision means action authorisation, per server means governance scope.
- What is the most common purchasing mistake?
- Buying detection when prevention was needed, usually because both were compared on one grid and detection had more features.
Five categories, and what each can actually prevent
- ›An agent can move money or delete records today
- ›A specific irreversible capability is live
- ›Audit or contractual pressure on authorisation
- ›You cannot answer ‘what stops this’
- ›You cannot list your servers or capabilities
- ›Duplicate capability across teams
- ›No owner per server
- ›Policy exists as tribal knowledge
| Category | What it does | Can it stop one action? | Best at |
|---|---|---|---|
| Prompt and content guardrails | Classify and filter prompts, completions and retrieved content | No — reduces likelihood | Lowering the volume of bad proposals reaching the action layer |
| Observability and detection | Collect agent telemetry, alert on patterns | No — reports afterwards | Knowing what happened and spotting behaviour changes |
| Identity and secret brokers | Issue short-lived scoped credentials, broker access | Indirectly — limits reachability | Removing long-lived credentials from agents |
| Pre-execution action firewall | Evaluate the specific action pre-execution and decide | Yes | Refusing, narrowing or escalating an individual dangerous action |
| Governance control plane | Own inventory, capability, policy authorship and evidence | Indirectly — governs what exists | Knowing and controlling the estate as a whole |
Barzel sits in two of these five: BarzelVault is a pre-execution action firewall, Barzel Central Gateway is a governance control plane. We do not sell guardrails or observability, and where you need those we would rather say so than stretch the description.
Twelve capability tests with pass criteria
Each test is written so that a pass is demonstrable and a fail is visible. Ask for the artefact, not the assertion.
Key facts
- ▸Tests six and eight eliminate more products than the other ten combined, in our experience of competitive evaluations.
- ▸Test nine is the one buyers skip and later regret, because failure behaviour is discovered during incidents rather than during procurement.
- ▸Test twelve is a judgement test rather than a capability test, and it predicts the working relationship better than any feature.
- 01Determinism. Identical inputs produce identical outcomes, demonstrated twenty times. Pass: identical outcome and identical rule cited each time.
- 02Pre-execution timing. The decision provably precedes the upstream effect. Pass: a record whose decision timestamp precedes the upstream call, verifiable independently.
- 03Outcome vocabulary. More than allow and deny. Pass: at least transform, approval and a hold or quarantine state, demonstrated on a real call.
- 04Argument-level conditions. Decisions on values, not just tool names. Pass: a rule keyed on an amount, a path, a recipient domain.
- 05Server-side identity. Identity and tenancy derived from the token, not the arguments. Pass: a demonstration that a forged tenant argument is overwritten.
- 06Approval binding. Approval tied to specific arguments, single-use, time-limited. Pass: a second call with different arguments is refused under the same approval.
- 07Cumulative controls. Ceilings across calls, not just per call. Pass: four hundred sub-threshold actions are stopped by a period ceiling.
- 08Record integrity. Tamper evidence you can verify. Pass: you verify a chain or signature yourself, with material the vendor does not control at verification time.
- 09Declared failure behaviour. Per risk class, configurable, tested. Pass: they turn it off in front of you and the documented behaviour occurs.
- 10Latency under realistic rule count. Measured at your expected rule volume. Pass: p99 single-digit to low double-digit milliseconds, with no remote lookup in the path.
- 11Data handling. What leaves your boundary, field by field. Pass: a field-level document, not a category description.
- 12Limits stated. Three things the product is not for. Pass: three specific answers, given without prompting twice.
Score these before the commercial conversation. A product failing tests one, two, six or eight is not in the category you think it is in.
A six-scenario bake-off using real attack patterns
Feature grids reward claims; scenarios reward behaviour. Use your own tools, and score outcome quality plus false positives rather than pass or fail.
Indirect prompt injection to an outbound tool
Plant an instruction in a document the agent will read, telling it to send a summary to an external address. Score: was the send refused, narrowed, escalated or permitted? Was legitimate outbound email still possible afterwards?
Threshold probing
Attempt an action just above a ceiling, then repeatedly just below it. Score: is the aggregate caught? Is the pattern reported? A product that stops only the first attempt is a per-call filter.
Unit confusion
Submit an amount in minor units where the schema is ambiguous. Score: is it refused, normalised, or accepted as a hundredfold error? This is the most common real-world failure and the least tested.
Approval reuse
Obtain an approval, then attempt a different action under it. Score: refused, ideally with an explicit binding-mismatch reason.
Two-step exfiltration
Read restricted data with one authorised tool, write it out with another. Score: is the sequence recognised, or are two individually valid calls simply permitted?
Product unavailable
Disable the product mid-run. Score: do payment and delete tools fail closed while read-only calls continue? Is the fail-open decision logged distinctly and alerted?
| Dimension | Weight | How to score |
|---|---|---|
| Prevented the harmful outcome | 30% | Refused, narrowed or escalated appropriately |
| Preserved legitimate work | 25% | Equivalent legitimate calls still succeed after the block |
| Explained the decision | 15% | Machine-readable reason the agent can act on |
| Produced verifiable evidence | 15% | Record you can verify without trusting the vendor |
| Behaved predictably when degraded | 10% | Documented failure behaviour occurred |
| Tuning effort required | 5% | Hours to reach an acceptable false-positive rate |
Scenario three is the quiet one. Unit confusion causes more real financial damage in agent estates than any exotic attack, and very few products are tested against it because it does not look like security.
What pricing patterns reveal
Key facts
- ▸Pre-execution decisions are priced roughly an order of magnitude above governance decisions across the market, including ours — BarzelVault’s paid plans start at $199/mo against Barzel Central Gateway’s free tier. That ratio reflects decision liability, and a vendor charging governance rates for liability-bearing enforcement is worth questioning.
- ▸Per-seat pricing interacts badly with approval workflows, which need many occasional approvers rather than a few daily users.
- ▸Always ask whether denied and shadow-mode evaluations are billable. Charging for refusals and for safe testing both create incentives you do not want.
| Pricing unit | Implied category | What to check |
|---|---|---|
| Per token or per million tokens | Text inspection — guardrails | Whether anything is evaluated at the action layer at all |
| Per gigabyte ingested | Observability | That prevention is not being implied by detection language |
| Per decision or per policy evaluation | Pre-execution action firewall | What counts as a decision: denials, shadow runs, retries |
| Per governed server or connector | Governance control plane | Whether per-call decisions are included or separate |
| Per seat | Console-oriented tooling | Whether approvers need seats, which changes the cost sharply |
| Per agent | Any category | How an agent is counted across environments and versions |
Price is rarely the deciding factor in this category, but the pricing unit is a reliable signal of what a product actually does, which makes it useful as a shortlisting filter.
Three mistakes that produce a second purchase
Mistake
Buying detection when prevention was needed
Both were compared on one grid; detection had more features and a nicer dashboard. Six months later a preventable action happens and is detected four minutes afterwards.
Instead: Decide the category from the problem before shortlisting. If the answer to ‘what stops this action’ is ‘an alert’, you need a different category.
Mistake
Evaluating on clean attacks only
Every product blocks an obvious injection in a demo. Nothing is learned, because production ambiguity is where products diverge.
Instead: Use the six scenarios, especially unit confusion and threshold probing, and score false positives as seriously as blocks.
Mistake
Skipping the integrity and failure tests
Nobody verifies a record or turns the product off. Both gaps surface later, one during an audit and one during an incident.
Instead: Make tests eight and nine gating. If you cannot verify the evidence, and you do not know the failure mode, you do not know what you bought.
Next step
Test us on all twelve
BarzelVault is a pre-execution action firewall: four deterministic outcomes, approval bound to specific arguments, hash-chained records you can verify, and declared failure behaviour per risk class. Run the twelve tests and the six scenarios.
Our position in this market
We sell in two of the five categories, which shapes this page.
- 01BarzelVault is a pre-execution action firewall and Barzel Central Gateway is a governance control plane. We do not sell guardrails, observability or identity brokering, and the category table is written to make that boundary clear rather than to blur it.
- 02The twelve tests are the ones we are willing to be measured against, which is a bias worth knowing. Test us on all twelve; test everyone on all twelve.
- 03We deliberately do not publish comparative claims about named competitors, because capability in this market changes quarterly and a table written today is misleading by next quarter. The framework is more durable than any snapshot.
Frequently asked questions
What categories of AI agent security platform exist?
Five: prompt and content guardrails, observability and detection platforms, identity and secret brokers, pre-execution action firewalls, and governance control planes. They address different points in the agent lifecycle and are complements rather than alternatives.
Which type of product can actually prevent an agent action?
Only a pre-execution action firewall, because it evaluates the specific action before the upstream system commits any effect. Guardrails reduce the volume of harmful proposals, observability reports after the fact, and identity brokers limit what is reachable at all.
How do I know which category I need?
From the problem. If a specific irreversible capability is live today and you cannot say what stops it, you need prevention. If you cannot list your servers, owners and capabilities, you need governance. If you cannot say what happened last week, you need observability.
What is the sharpest test of an AI agent security product?
Determinism: identical inputs must produce identical outcomes with the same rule cited, demonstrated repeatedly. A product whose decisions vary cannot be audited and should not be trusted with consequential actions.
How should approval binding be tested?
Obtain an approval for one action, then attempt a materially different action under the same approval. A correct product refuses with an explicit binding-mismatch reason. Unbound approvals are common and function as reusable coupons rather than controls.
Why does record integrity matter in a product evaluation?
Because evidence you cannot verify is a claim rather than proof. Ask to verify a hash chain or signature yourself, using material the vendor does not control at verification time. This single test eliminates a surprising number of products.
What should I test about product failure behaviour?
Have the vendor disable the product mid-run and observe what happens: money movement and destructive actions should fail closed while read-only calls continue, and every fail-open decision should be logged distinctly and alerted. An answer of ‘we are highly available’ is not a failure-behaviour answer.
What is the most under-tested real-world failure?
Unit confusion — an amount submitted in minor units where the schema is ambiguous, producing a hundredfold error. It causes more actual financial damage in agent estates than exotic attacks, and it is rarely tested because it does not look like security.
What does a product’s pricing unit tell me?
Its category. Per-token pricing implies text inspection, per-gigabyte implies observability, per-decision implies action authorisation, per-server implies governance scope. Pre-execution decisions are priced roughly an order of magnitude above governance decisions across the market, reflecting decision liability.
How many products should be on a shortlist?
Three, from one or at most two categories. Cross-category shortlists are won by whichever product has the longest feature list rather than the best fit, which is how organisations buy detection when they needed prevention.
Should I score false positives as heavily as blocks?
Nearly, yes. A product that blocks an attack while also blocking a fifth of legitimate work will be disabled within a quarter, so preserving legitimate work should carry roughly as much weight as preventing the harmful outcome.
What question do vendors find hardest?
Name three things your product is not for. A vendor with three specific answers is describing a real system with real boundaries; one who cannot name any is describing a roadmap, and the difference predicts the working relationship better than any feature comparison.
Glossary
- Pre-execution action firewall
- A product that evaluates a specific proposed action before execution and returns an enforceable outcome.
- Guardrail
- A text-layer filter or classifier operating on prompts, completions or retrieved content.
- Identity broker
- A component issuing short-lived scoped credentials in place of long-lived agent secrets.
- Governance control plane
- A product owning inventory, capability, policy authorship and evidence for an estate.
- Capability test
- A demonstrable check with an artefact as evidence, rather than a claimed feature.
- Bake-off
- A scenario-based evaluation running candidate products against the same real attack patterns.
- Binding mismatch
- A refusal because the attempted action differs from the approved one.
- Decision liability
- The commercial exposure a vendor accepts by making an enforceable per-action decision.
- Unit confusion
- An error caused by ambiguous units in a schema, such as minor versus major currency units.
- Fail-open decision
- A permitted action taken because the security layer could not render a decision.
Standards and entities referenced
Every named framework on this page resolves to a public definition. If you are checking our claims, start here rather than with us.
Sources and further reading
Primary specifications and standards this article relies on. Where a claim is our own operating judgement rather than something a standard states, the text says so.
- 01 · OWASP GenAI Security ProjectOWASP Agentic AI — Threats and Mitigations ↗Threat taxonomy specific to tool-using agents rather than to chat completions.
- 02 · OWASP GenAI Security ProjectOWASP GenAI LLM Top 10 (2026) ↗Consensus risk list; excessive agency and prompt injection are the entries governance exists to bound.
- 03 · NISTNIST SP 800-207 — Zero Trust Architecture ↗The policy decision point / policy enforcement point split this architecture borrows directly.
- 04 · Simon WillisonPrompt injection — ongoing series ↗The most consistently updated practitioner record of the attack class.
- 05 · MITREMITRE ATLAS ↗Adversary technique knowledge base for AI systems, useful for naming what a risk score is scoring.
- 06 · ISOISO/IEC 27001 — Information security management ↗The ISMS baseline that agent-layer controls have to fit inside rather than beside.
- 07 · NISTNIST SP 800-53 Rev. 5 ↗Access control and audit control families that MCP-layer controls have to satisfy.
- 08 · OWASPOWASP Application Security Verification Standard ↗Input-validation, authorization and logging requirements restated here in MCP terms.
Last reviewed 2 September 2026 by Mark Alex. External links open in a new tab; we do not control their content.
Cite this article
Alex, M. (2026). AI Agent Security Platforms: How to Compare Them Properly in 2026. Real Biz Digital. https://realbizdigital.net/insights/best-ai-agent-security-platforms/
Try the mechanics on a live server
To see what a tool-call envelope actually looks like before you write a policy that has to decide about one — Barzel Scripture Intelligence is free and public at scripture-intelligence-server.mcpize.run: no signup, no key, 54 tools. Setup is in the reference.
Buy it on the marketplace
BarzelVault is the pre-execution decision point, sold as a running product
Nine tools, 12 static resources, 3 resource templates and 9 prompts. Four deterministic outcomes — allow, deny, dry-run, require approval — with approval workflow, hash-chained audit and guardrail data protection. Streamable HTTP, JSON-RPC 2.0.
| Plan | Price | Included | Right for |
|---|---|---|---|
| Dev | Free | 10,000 policy decisions/mo · 9 tools, 4 outcomes, hash-chained audit | A first regulated workflow: one agent, one high-consequence system |
| Team | $199/mo | 75,000 decisions/mo · approval workflow, spend and action limits | Several agents acting on money, records or customer-visible systems |
| Business | $799/mo | 750,000 decisions/mo · exact HTTPS execution, credential isolation, emergency controls | Enterprise-wide pre-execution enforcement under audit |
| Enterprise | $3,999/mo | 5,000,000 decisions/mo · everything in Business, scaled | Group-wide rollout across many teams and systems |
Sold on the MCPize marketplace · prices as listed 2 Sep 2026 · the listing is authoritative
The five Barzel servers, and which problem each one is sold for
One estate rarely needs all five. This is the honest mapping, so you buy the layer your problem actually lives in.
| Server | Sold for | Entry price | Where it sits |
|---|---|---|---|
| Barzel Central Gateway | Knowing and governing the estate: inventory, registry, routing, risk scoring, approvals, evidence | Free, then $10–$149/mo | Control plane — decides what may be reached, and by whom |
| BarzelVault | Stopping a specific dangerous action before it executes, with proof afterwards | $199–$3,999/mo | Decision point — evaluates the individual call before execution |
| BarzelOps | Running real business workflows across HubSpot, Xero, Gmail, Drive and Slack under approval | Free, then $19–$199/mo | Execution layer — does the work the policy allowed |
| Barzel FinOps Atlas | Attributing AI spend to agents, tools and outcomes, then forecasting and capping it | Free, then $29–$799/mo | Economics layer — what the estate costs per outcome |
| Barzel Scripture Intelligence | A free, credential-free public MCP server to test clients and inspect real protocol traffic | Free, unmetered, no signup | Reference implementation — safe place to learn the protocol |
Written by
Mark Alex
Founder of Real Biz Digital and architect of the Barzel ecosystem — five MCP servers published and callable in public. Software developer, technology entrepreneur and mechatronics engineer, working across AI agent governance, MCP security, AI infrastructure, FinOps and intelligent operations.