At 2:13 in the morning, an AI agent borrows a developer’s authority, opens a customer database, calls a tool through MCP and changes a production system. In the seconds before a human notices, it crosses four security empires. CrowdStrike can see the process; Zscaler can see the traffic; Okta can see the token; Rubrik can see the data change. Every one of them can truthfully say it secures AI. None of those truths is the whole story.
This is why the sudden flood of “AI security platforms” is confusing. The companies are not all selling the same product. They are extending the control point they already own—endpoint, network, cloud, data, identity or the security operations centre—into a new agentic attack surface. The right question is therefore not “who has AI security?” It is where does each vendor sit in the chain, what can it actually stop there, and which risks remain somebody else’s problem?
First, separate the two markets
AI for security means using models and agents to defend the enterprise: triaging alerts, writing queries, investigating incidents and executing approved response. CrowdStrike Charlotte AI, SentinelOne Purple AI and Microsoft Security Copilot live primarily in this market.
Security for AI means protecting the AI estate itself: discovering shadow AI, scanning models and code, controlling agent identities, inspecting prompts and tool calls, preventing data leakage, testing behaviour and reversing harmful changes. Zscaler AI Guard, Prisma AIRS, Cisco AI Defense and the identity and data products discussed below live primarily here.
The categories are converging, but they are not interchangeable. A SOC agent can investigate an incident without governing the identity that caused it. An inline gateway can block a dangerous request without knowing whether an entitlement was approved. A recovery product can undo a supported change without removing the authority that allowed it.
The market map
| Company | Inherited control point | Principal AI-security offer | Strategic position—and boundary |
|---|---|---|---|
| CrowdStrike | Endpoint, XDR and SOC telemetry | Charlotte AI for agentic investigation; AIDR for prompt, app, agent and MCP protection | Strong evidence-to-response loop where Falcon is deployed; does not replace durable identity governance, data entitlement management or recovery. |
| SentinelOne | Endpoint, cloud runtime and AI-SIEM | Purple AI plus Prompt Security for workforce, application and agent controls | A direct endpoint-to-prompt strategy; the test is how completely recently acquired capabilities operate as one policy and telemetry plane. |
| Zscaler | Inline zero-trust and SASE traffic | AI Guard for prompt/response inspection, DLP and AI-specific threat controls | A natural enforcement chokepoint for workforce and workload AI traffic; cannot govern every identity lifecycle or reverse an application change. |
| Netskope | CASB, SSE and data loss prevention | AI Gateway, Agentic Broker, Guardrails and AI Red Teaming | Close to Zscaler, with a data- and app-context-heavy approach to MCP and AI transactions; not an endpoint or recovery platform. |
| Cloudflare | Application edge, developer platform and global network | AI Gateway, Cloudflare One, Firewall for AI and MCP controls | Well placed when AI applications and model requests already traverse Cloudflare; not a substitute for SOC, IGA or privileged-access depth. |
| Palo Alto Networks / Idira | Network, cloud, SOC and privileged identity | Prisma AIRS across model, app and agent security; Idira for human, machine and agent privilege | The broadest architectural consolidation attempt; value depends on successful integration, licensing clarity and feature maturity across acquired platforms. |
| Cisco | Network, cloud enforcement and security telemetry | AI Defense for discovery, supply-chain scanning, red teaming and runtime protection | Strong network-layer enforcement and model-security technology; agent identity is a newer part of the portfolio. |
| Microsoft | Identity, productivity data, cloud and SOC | Security Copilot; Agent 365; Entra Agent ID; Purview, Defender and Foundry controls | Unmatched native context and distribution inside Microsoft estates; capability is spread across products, licences and mixed GA/preview states. |
| Rubrik | Protected data, immutable state and recovery | Agent Cloud and Agent Rewind | Distinctive focus on tracing and reversing agent-caused damage; reversibility must be validated application by application. |
| Varonis | Data classification, entitlements and activity | Atlas inventory, AI-SPM, testing and runtime guardrails | Strong pre-action context around what sensitive data an agent can reach; the wider AI platform is newly launched. |
| SailPoint | Identity governance and administration | Agentic Fabric and Agent Identity Security | Best aligned to ownership, certification, lifecycle and compliance; needs runtime, endpoint and recovery partners. |
| Okta | Authentication, authorization and application identity | Okta for AI Agents, Agent Gateway and Cross App Access | Targets live agent-to-tool authority with short-lived credentials and policy; does not inspect every semantic threat or recover side effects. |
Endpoint and SOC: see what the agent actually did
CrowdStrike
CrowdStrike begins with the Falcon sensor and the security telemetry already used to investigate endpoints, identities, cloud and network activity. Charlotte AI coordinates agentic investigations and governed response, while AIDR extends prompt-layer protection across endpoints, applications, agents, MCP servers, gateways and cloud—moving CrowdStrike from “AI for security” into “security for AI,” but not turning it into an identity-governance or recovery system.
SentinelOne
Purple AI is an agentic SOC analyst that reasons over normalized endpoint, cloud, identity and third-party security data; acquired Prompt Security adds shadow-AI discovery, data controls and guardrails for prompts, applications, agents and MCP. The combination gives SentinelOne a coherent endpoint-to-interaction story, although buyers should test how completely the newer Prompt policy and telemetry plane is integrated across non-SentinelOne infrastructure.
Inline policy: decide before the request crosses the boundary
Zscaler
Zscaler’s advantage is architectural: the Zero Trust Exchange already sits inline between users, workloads, SaaS applications and the internet. AI Guard can inspect prompts and responses for prompt injection, jailbreaks, malicious links, invisible text and sensitive data, making it a strong “should this interaction pass?” control—but not the owner of agent lifecycle, endpoint execution or recovery.
Netskope
Netskope attacks the same market from CASB, SSE and data-loss prevention, adding a generally available Agentic Broker that decodes MCP traffic, plus a private AI Gateway, guardrails and red teaming. Its strongest claim is transaction context—user, app instance, data, model and tool—so it competes directly with Zscaler for the inline control point while still depending on other systems for host response, durable entitlement governance and rollback.
Cloudflare
Cloudflare straddles the public application edge, workforce access and the developer’s model-request path: AI Gateway supplies provider-neutral logging, DLP, guardrails, authentication and cost controls, while Cloudflare One and its MCP controls govern access. That is compelling for applications already built behind Cloudflare, but its own DLP documentation illustrates why architecture matters—inspection scope, caching and streamed-response buffering create constraints that a broad “AI security” label conceals.
The platform plays: secure the AI lifecycle
Palo Alto Networks—and Idira
Prisma AIRS makes the broadest purpose-built claim, covering model and repository scanning, AI posture, automated red teaming, runtime firewall/API, AI Gateway and agent protection; the Protect AI acquisition deepened its development and model layers. Palo Alto then completed its CyberArk acquisition in February 2026 and launched Idira, adding privileged, machine and agent identity—an unusually complete architecture whose main risk is now integration and execution, not lack of ambition.
Cisco
Cisco AI Defense combines Robust Intelligence’s model testing and AI-firewall technology with Cisco’s network and cloud enforcement, discovering AI assets and MCP systems, scanning the model-and-tool supply chain, red-teaming applications and inspecting prompts, responses and tool calls at runtime. Its network position and Talos intelligence are real assets; identity-aware authorization for agents is a newer layer that Cisco is still assembling through its zero-trust portfolio and acquisitions.
Microsoft
Microsoft can join more native context than almost anyone: Security Copilot and specialist agents improve defence, while Entra Agent ID, Conditional Access, Agent 365, Purview, Defender and Foundry secure agent identities, data and applications. Its distribution advantage is formidable, especially inside Microsoft 365 and Azure, but the official release record shows a portfolio split across products, licences and a mixture of generally available and preview capabilities.
Data: prevent the exposure—or reverse the damage
Rubrik
Rubrik starts where prevention ends: immutable data state and recovery. Agent Cloud adds discovery and intent-based guardrails, while Agent Rewind traces prompts through plans and tools and aims to restore supported files, databases, configurations and repositories; the idea is differentiated, but buyers must verify connector by connector which side effects are genuinely reversible.
Varonis
Varonis approaches the data problem before the destructive change occurs: its core value is classifying sensitive data, mapping effective access and finding overexposure. Atlas, generally available since May 2026, adds AI inventory, posture management, live testing and runtime guardrails; the strategic differentiator is not another prompt filter but knowing what valuable data the agent can reach and reducing that reach before it acts.
Identity: ownership is not the same as authorization
SailPoint
SailPoint’s Agentic Fabric extends identity governance to agents: discover them, assign accountable owners, map human-to-agent-to-data access, certify entitlements, manage lifecycle and apply least-privilege policy when tools are invoked. Its natural question is durable governance—who approved this authority, why does the agent have it and should it still exist?—so it complements rather than replaces semantic runtime inspection, endpoint defence or recovery.
Okta
Okta starts closer to authentication and live authorization: Okta for AI Agents discovers and registers agents, assigns owners, issues short-lived credentials, governs lifecycle and can revoke access, while Agent Gateway places identity directly in the tool-call path. Its defining question is immediate—should this agent receive authority for this connection now?—which makes it more transactional than SailPoint, although both companies are rapidly moving into each other’s territory.
What will decide the market
The winner will not be determined by who can place the most boxes on an “end-to-end” diagram. The durable advantage is owning an enforcement point through which the relevant action already passes—and enriching that decision with context from the other planes. CrowdStrike and SentinelOne have execution truth; Zscaler and Netskope have traffic truth; Varonis has data truth; SailPoint, Okta and Idira have different forms of identity truth; Rubrik has recovery state. Palo Alto, Cisco and Microsoft are trying to join enough of those truths to become the system of control.
This also explains the acquisition race. Palo Alto bought Protect AI and CyberArk; Cisco built AI Defense around Robust Intelligence; SentinelOne bought Prompt Security. The incumbents did not begin with all the controls required for agentic AI. They are purchasing the missing layers and using their installed bases to distribute them.
Six questions buyers should ask
- Where is the enforcement point? Browser, endpoint, SASE proxy, application API, model gateway, MCP gateway, identity provider and data platform see different parts of the same action.
- Can it block the tool call, or only report it? Observability is useful; prevention requires the control to be in the path, resilient and difficult to bypass.
- Can it preserve the delegation chain? The audit record should connect human sponsor, agent identity, credential, tool, data and resulting side effect.
- Does policy understand the data? A generic secret pattern is not the same as knowing that a specific file is sensitive and that this agent’s access is excessive.
- What happens after prevention fails? Test endpoint containment, identity revocation and application-level recovery—including external actions that cannot simply be “rewound.”
- What is generally available in the exact environment? Contract against the clouds, models, agent frameworks, MCP transports and application connectors actually in use, not a roadmap slide.
Bottom line
“AI security” will become a real budget, but it will not settle into one neat product category. Agentic systems turn a prompt into identity use, network traffic, data access, code execution and lasting side effects. Each step creates a different place to observe, authorize, block or recover.
The sensible architecture is therefore layered. Use identity to bound who the agent can become, inline policy to restrict what it can send and call, data controls to limit what it can reach, runtime protection to stop what it executes, SOC automation to investigate what slipped through and recovery to undo what can still be undone. The company that owns one of those layers may become very valuable. The company that claims one layer is the entire answer should be treated with much more caution.