Layer 4 · Agentic AI Security

Agentic AI Security Tools — Capability Coverage Map

Layers 1–3 govern a prompt-and-response transaction. An agent is a different object: it loops, calls tools, holds memory, takes actions and talks to other agents. These six capabilities are derived from the OWASP Top 10 for Agentic Applications (ASI01–ASI10, 2026), not from the input/output model — the agentic risks have no cell to land in on the other three maps. Select vendors (or a preset) to see combined coverage — green where covered once, amber where duplicated, red where you have a gap.

Capability Venn — combined coverage of selected vendors

Nothing selected — showing how many vendors cover each capability. Click vendors below to build a stack.

Covered (once) Duplicate coverage Partial only Gap — not covered

Select vendors to compare

Coverage verdict

Full capability matrix — vendors plotted against every capability

How vendors were selected — methodology

Inclusion. A vendor appears here if it meets at least one of three gates, and the gate is recorded: (A) Dominant — named a market leader or material enterprise presence in independent, non-vendor coverage; (B) OWASP-listed — appears in the OWASP GenAI Security Project AI Security Solutions Landscape (Q2 2026); (C) New innovator — launched or materially funded within roughly the last twelve months. At least one open-source option is retained per capability cluster where one exists, and acquired vendors are named by acquirer.

Read this before relying on "OWASP-listed." The OWASP Solutions Landscape is a self-submitted directory. Vendors nominate themselves through a submission form, and entries are grouped by sponsorship tier. Appearing in it means submitted and accepted — not independently assessed, benchmarked, or ranked by market share. Treat it as evidence of participation in the community, not of product quality.

Deliberate exclusion. AI gateways (Kong, Cloudflare, Portkey, LiteLLM) are left out by design: a gateway is where policy is enforced, not the engine that decides. That is a judgment call, not an oversight.

Scoring. Placement reflects publicly documented or vendor-claimed capability as of August 2026 — not independent testing. ● full or native · ◐ partial or add-on · — not covered. A mark means a capability is claimed to exist, not that it is strong or sufficient for your requirements. Open-source agentic security tooling is still sparse, which is itself a finding rather than an omission.

Governance plane, added Aug 2026, expanded Aug 22. Gartner published its first Magic Quadrant for AI Governance Platforms on June 16, 2026 — 13 of 100+ evaluated vendors qualified against 8 mandatory capabilities (discovery/registry, risk management, policy enforcement, dynamic risk scoring, evidence collection, interoperability, workflow/approvals, audit trail). Alongside Alation, all 13 Gartner-qualified vendors are now on this map, gated MQ-Leader / MQ-Visionary / MQ-Challenger / MQ-Niche by Gartner's own placement rather than the A/B/C scheme used elsewhere on this map — MQ inclusion is itself an independent analyst-verified signal, not self-submission. These are system-of-record platforms: strong on oversight/policy, thin-to-none on tool-execution control, goal-hijack detection, or memory integrity — the runtime agentic risks stay with the agent-native and carried-over security vendors above. SAP (AI Agent Hub) is the one governance-plane entry scored with some tool-control coverage, reflecting its position inside an agent-orchestration product rather than a pure GRC platform. Scoring for the 11 added Aug 22 is a first pass from public positioning, not vendor documentation — thinner evidence than the rest of this map. Full detail: internal note `AI-GOV~1.MD` §2a.

Maintenance. Reviewed quarterly against the OWASP landscape and current vendor documentation. Last review: August 2026.