The problem is not a lack of controls. It is connecting them into one attack story.
The more time I spend with enterprise AI deployments, the clearer one thing becomes: AI security is incredibly fragmented.
There are LLM guardrails, AI gateways, MCP security tools, API security, endpoint controls, SASE, code scanning, and runtime detection. Each solves a real problem, but agentic systems do not experience them as separate layers, and neither do attackers.
An attack can start with a malicious prompt, manipulate a model, invoke an MCP tool, reach a downstream API, access sensitive data, and ultimately trigger a real business action. If every security control sees only its own piece, the team still does not understand what actually happened.
The attack is one story. Security often sees five different ones.
One attack, several security layers
Take a simple example from what we are announcing this week.
An attacker uses prompt injection against a billing agent. The compromised agent repeatedly calls a refund capability exposed through an MCP server. Behind that tool is a backend refund API, and an authorization weakness there turns the attack into exposure of customer information.
From the model layer, this looks like prompt injection. At the MCP layer, it looks like abusive tool usage. At the API layer, it looks like an authorization failure. To the business, it is one incident.
The labels change depending on which security tool you are looking at. The attack does not.

That is why context matters so much in Agentic Security. You need to know not only that the model was manipulated, but what that model could reach, which tools were invoked, which APIs sat behind those tools, what data was exposed, and what action ultimately took place.
Without that context, we are just producing more alerts.
Closing the model-layer gap
Today, Salt is announcing native AI Detection and Response, or AI-DR, as part of our Agentic Security Platform. It adds real-time LLM protection against direct and indirect prompt injection, jailbreak attempts, unsafe model behavior, and other runtime threats.
But for me, the more important point is what happens next.
We already had the Agentic Security Graph connecting agents to MCP servers, tools, downstream APIs, data, posture, and runtime behavior. Native AI-DR closes the last major runtime gap by extending that protection to the LLM layer itself.
Now security teams can connect what happened to the model with what followed across the agent, MCP, API, and business system, instead of investigating each layer as a separate event.
Prompt injection → compromised agent → MCP tool → backend API → business impact
One attack path, not five disconnected alerts.
Agentic security is a correlation problem
Protecting the model is important. Protecting MCP is important. Protecting APIs is important. None of them alone answers the question security teams actually care about: what can this agent reach, what happened, and what business system is now at risk?
That requires breadth and depth. Breadth means seeing the entire agentic path across models, agents, MCP servers, tools, APIs, applications, data and actions. Depth means understanding each component in context, including exposure, source code, configuration, permissions, sensitive data, and runtime behavior.

That combination is what the Agentic Security Graph is designed to provide. The goal is not another isolated AI security control. It is a connected view of the environment and the attack path.
The visibility gap today is significant. In our 2H 2026 State of Agentic AI and API Security survey, 49.8% of organizations said they had confirmed or suspected that an AI agent took an action they did not intend, expect, or authorize in the past year. Only 12.5% said they could consistently trace the full path from the initial prompt through the MCP servers and APIs the agent reached.
That gap is what concerns me.
Keep what works. Connect what is missing.
Enterprises already have AI protections. Some use cloud guardrails, some use AI gateways, others rely on endpoint or SASE controls, and managed AI platforms bring protections of their own. Those investments should stay.
The problem is inconsistency. One agent may sit behind an AI gateway, while another homegrown agent running in Kubernetes has no equivalent control. Security teams need to understand what is protected, what is not, and how it all connects.
That is the approach we are taking. Salt brings existing guardrails and gateways into the Agentic Security Graph, while native AI-DR can provide protection where coverage is missing. Customers can keep the infrastructure and security products they already use.
The end goal is context
This announcement matters to me because it closes the last major runtime gap in the path. We can now connect what happens at the model to what happens next across agents, MCPs, APIs, data and business systems.
AI security will continue to produce more specialized controls, and many of them will be useful. But if those controls remain disconnected, security teams will still be left reconstructing attacks from fragments.
An attack on an AI model can become an attack on the systems that run the business. Security needs to see the entire journey.
Want to know exactly what your AI agents can reach, and where the gaps are? Explore Salt's Agentic Security Platform or request a demo to see your Agentic Security Graph in action.
