Market analysis

Who Watches the Agents?

As you probably know, a few weeks ago, OpenAI agents escaped the environment in which they were being tested, and tried to hack HuggingFace. After that another case surfaced where agents used a German wiki to share information about how to get around sandbox restrictions (bots don’t stop).

If agents can work around their own constraints, companies will need a separate layer to control what they can do and keep an independent record of what actually happened (we cannot trust them to self report). It turns out that there is already a whole ecosystem of pure players doing that as well as existing security software incumbents moving there. Below is the analysis of the different categories and you can find the mapping on the right.

Tool & MCP Security

What is this category about?

  • This category is abbout security products that control which external tools an AI agent can use and under what conditions. The security problem changes once an agent stops only producing information and begins interacting with software. A tool can give the agent access to internal data or let it change something in another system. Tool and MCP security creates an independent layer between the agent and those capabilities.

  • The first problem is simply knowing what agents are connected to. Employees can install MCP servers or give coding agents access to new tools without going through the normal software procurement process. Some of this infrastructure runs directly on employee devices, which makes it particularly difficult for central security teams to see. The result is a new form of shadow IT where the unknown component is not only the AI application but also everything the agent has been allowed to use.

  • Another problem is that connecting a tool creates a new software supply chain. A tool can look legitimate when it is approved and later change. A compromised component can also return information designed to manipulate the agent into doing something else. Security teams therefore need to evaluate what an agent connects to before it is trusted and continue watching the relationship afterwards.

  • Permission becomes more difficult when software decides for itself when to use it. Traditional access control assumes that a human or an application makes a relatively predictable request. An agent can choose a tool dynamically and decide what parameters to send based on natural language. The objective is therefore to move authorization outside the agent itself, so a separate system can decide whether an action should actually be allowed.

What do products in this category do?

  • One group of products starts by creating an inventory of the agent infrastructure already inside the company. The logic is that security teams cannot apply policy until they know which agents exist and what those agents can reach. Anomity focuses heavily on this problem at the employee endpoint, where it identifies MCP servers and other agent components that may have been installed locally. Lasso extends the same idea into cloud environments and software repositories so teams can understand the agent attack surface before something runs in production.

  • Another approach treats tools as a software supply chain that needs to be vetted before an agent can use it. Instead of allowing employees to connect arbitrary components, the security layer evaluates them and can create a trusted path for approved tools. AIR is the clearest example. Its scanner examines skills and MCP related components for security problems, while AIR Marketplace is designed to become a controlled source for components that organizations are willing to trust. Runlayer follows a similar logic with a governed catalog that lets companies expose approved capabilities to employees without opening access to everything.

  • A third product model puts a gateway directly between the agent and the tools it wants to call. The purpose is to create one enforcement point where security policy can be applied independently of the model. Runlayer's MCP Gateway controls requests before they reach external systems. NeuralTrust uses its Agent Gateway as a similar control layer, while Operant applies security at the MCP gateway and surrounding runtime. This model is particularly useful when many agents need access to the same internal systems because companies can govern that traffic centrally rather than configuring every agent separately.

  • The newest products are moving beyond deciding whether a tool is allowed and are starting to evaluate what the agent is actually trying to do with it. An approved tool can still be used in a dangerous way. Operant's Semantic Firewall evaluates agent intent before an action is executed. Lasso's LEAP similarly adds low latency inspection around requests and actions. The product direction is therefore moving from static permission toward contextual enforcement, where the same tool call can be accepted or rejected depending on what the agent is trying to accomplish.

How is tool and MCP security evolving?

  • The first wave focused on putting a controlled gateway in front of agent access. Lasso launched its MCP security gateway in April 2025, while Runlayer came out of stealth later that year around the same basic problem. The early product assumption was that MCP would become an important connection layer for agents, so securing the protocol itself could create a natural enforcement point.

  • During 2026 the products started moving further upstream because companies realized that controlling known connections was not enough. Lasso added repository analysis and cloud agent discovery. Pillar extended its security layer into agentic CI/CD. The problem was becoming less about securing one MCP request and more about finding the agent infrastructure before security teams had even approved it.

  • The latest releases are moving enforcement closer to the meaning of the action itself. NeuralTrust's Runtime Security Mesh extends control across different agent environments, while Operant's Semantic Firewall evaluates intent in real time. Lasso is moving in the same direction with LEAP. The category is therefore gradually shifting from securing connections toward deciding whether an autonomous action should be trusted.

What types of customers are using these products?

  • Large companies rolling agents out to employees are one of the clearest customer groups. Runlayer says Gusto deployed its platform across more than 3,000 knowledge workers and manages 84 MCP servers through it. Its customer material also names Jane App and Homebase. Earlier launch material included companies such as Instacart and Opendoor. In these deployments, the buyer is typically the security or platform team trying to make broad employee access possible without letting every user connect agents directly to company systems.

  • Regulated industries appear particularly receptive because they already have strong requirements around access and auditability. AIR says it has more than 20 customers and that demand is strongest in financial services and pharmaceuticals. NeuralTrust shows a similar pattern. Its public customers include AirEuropa and Iberia, while its financial services deployments include Abanca and Banc Sabadell. The product is not only blocking attacks here. It gives security teams a way to allow agents into sensitive workflows without losing control over what they can access.

  • Government is also emerging as a distinct market. Lasso names the U.S. Department of Homeland Security as a customer and created Lasso Federal specifically to sell into the public sector. This makes sense because autonomous software creates an unusually difficult procurement problem for organizations that need strong accountability around every system action.

  • The number of agents inside companies is increasing extremely quickly. Microsoft says active agents in its Microsoft 365 ecosystem grew 15 times year over year, and growth reached 18 times in large enterprises. This matters for security because the problem changes once agents move from isolated experiments into normal employee workflows. A company can manually review a few agents. It cannot manage thousands of tool connections that way.

  • MCP is becoming sufficiently large that security around the protocol can support its own infrastructure layer. Anthropic says MCP recently passed 400 million monthly SDK downloads and that more than 950 MCP servers are available through Claude's connector directory. The July 2026 specification also strengthened authorization. As MCP becomes a common way for agents to reach software, companies gain a shared point where access can be inspected and controlled.

  • The security discussion is moving from unsafe model output toward unsafe agent actions. OWASP now documents MCP specific problems such as tool poisoning and excessive permissions, where the danger comes from what an agent can do after receiving malicious context. NIST reached a similar conclusion in its 2026 work on agent security, finding broad agreement that existing cybersecurity practices need to be adapted for autonomous systems and that security concerns are already limiting adoption. This is important for the category because security is becoming an enabler of agent deployment rather than something added after the agent is built.

How does the funding environment look?

  • Venture capital is arriving unusually early for such a new security category. Four of the seven companies in the landscape raised rounds of at least $20 million in 2026. AIR is the most extreme example: it disclosed $50 million across two seed rounds as it came out of stealth. Runlayer raised a $30 million Series A only seven months after announcing its $11 million seed. This suggests investors are funding the control layer before the market structure has fully settled.

  • The recent rounds are no longer supported only by a thesis about future agent adoption. Lasso reported more than 500% revenue growth over the previous year when it raised another $30 million in September. NeuralTrust said its ARR in the first quarter of 2026 was already twice its ARR for all of 2025 before announcing its $20 million seed. There is still plenty of category excitement in the valuations and round sizes, but some companies are beginning to show that enterprises are actually buying these products.

  • Investors also seem comfortable funding companies before it is clear which exact product layer will win. Some companies started with MCP gateways while others came from broader AI security. Their products are now converging around control of agent access. The founding teams tend to have strong security or enterprise infrastructure backgrounds, which probably helps explain why these companies have been able to sell to large security teams relatively early.

  • I would classify Tool & MCP Security as strongly VC compatible and currently “trending fast,” but not hype yet. Large rounds are happening in parallel and most companies in the landscape are expanding rather than standing still. The main investment risk is not whether enterprises will need control over agent tool use. It is whether that control remains a standalone software category or eventually becomes a standard feature inside larger security platforms.

Published Sep 08, 2026 Updated Sep 08, 2026