
22 Sep 2026
Salt Security adds native AI Detection and Response for LLM runtime
Salt Security announced native AI Detection and Response inside its Agentic Security Platform, adding real-time LLM protection against prompt injection and jailbreaks while linking those hits to MCP tools and APIs the agent reaches.
SOFTWARE desk — agents that call tools turn a bad prompt into a payment-API problem. Runtime that sees the whole path is the control plane that matters: the place a team can watch the attack move and stop it.
What the release says the new layer watches. AI-DR gives real-time protection against direct and indirect prompt injection, jailbreak attempts, unsafe model behavior, and other threats while the model is running. Real time means during the request, not in a review the next day. Prompt injection is hidden instructions inside something the model reads, so it follows those instructions instead of the person’s. Direct means the person types them. Indirect means they sit in a page, an email, or a file the agent opens. A jailbreak is a prompt meant to push the model past the rules its maker set. The release says prompt injection is the top-ranked risk in the OWASP Top 10 for LLM Applications 2026, and that AI-DR detects both the direct and the indirect kind as they happen. OWASP is the Open Worldwide Application Security Project. Its Top 10 is a public list of the risks teams watch. That ranking sentence is Salt’s. This desk did not reorder the list.
Where AI-DR sits in the product. It is built into Salt Agentic Detection and Response, shortened to AG-DR, and it extends that product’s runtime protection to the LLM layer. Runtime means while the agent is acting. The Salt Agentic Security Graph connects an agent to its models, its Model Context Protocol servers, its tools, and the downstream APIs those tools call. MCP, the Model Context Protocol, is the plug an agent uses to call a tool on a server. An API, an application programming interface, is the connection a program uses to ask another system to do something, such as issue a refund. Downstream means the next system in that chain. With native AI-DR, the release says a team can connect an attack on the model to the MCP and API attacks that follow, in the same platform. A graph, here, is that map of connections. File the map as the company’s. This desk did not trace a live agent.
The survey line, and whose numbers they are. In Salt Security’s 2H 2026 State of Agentic AI and API Security survey, nearly half of organizations, 49.8 percent, confirmed or suspected that an AI agent took an action they did not intend, expect, or authorize in the past year. Only 12.5 percent can consistently trace an agent’s full path from the first prompt through the MCP servers and APIs it reaches. 49.8 percent is just under half. 12.5 percent is one in eight. The release says security teams need to see how an attack moves across these layers to know what is at risk. The page does not print how many organizations answered, or who fielded the questionnaire. Do not invent a sample size. These figures are Salt’s. This desk did not run the survey.
The payment example is a could, not a case this desk logged. The release says an attacker could trick a billing agent into revealing a refund tool on an MCP server and the API behind it, then try unauthorized refunds, either directly or through the agent. What began as a bad prompt has become an attack on a payment system. Salt says it shows those steps together, from the prompt injection through the MCP server to the API, including when the attacker leaves the agent and hits the API directly. The product image on the wire draws that path: a billing agent marked for prompt injection, a refund tool on an MCP server, a refund API, and emails, addresses, and phone numbers as what the path can expose. The image labels the host www.victim.com and stamps example times on 12 Aug 2026. That host is a placeholder on the graphic. It is not a company this desk confirmed was breached, and 12 Aug is not this announcement.
The gap the company says it is filling. Companies already use AI guardrails across cloud platforms, endpoint tools, SASE services, AI gateways, and managed AI services. A guardrail is a check that blocks a risky prompt or action. A gateway is a middle box the traffic passes through. SASE is a network-security bundle a company buys from the cloud. Each control covers only the interactions it sees, so teams are left to find the holes. AG-DR and Agentic Security Posture Management, shortened to AG-SPM, together are the Salt Agentic Security Platform. AG-SPM is the view of which agents exist and where protection is thin. Through AG-SPM and the graph, Salt says it puts those existing guardrail settings, and the agents they cover, in one view. Where protection is missing, including homegrown agents running in Kubernetes, native AI-DR inside AG-DR can fill the gap. Homegrown means the company built the agent itself. Kubernetes is the system many companies use to run that software. The release says customers can keep the gateways and security products they already use. File that as the company’s. This desk did not inventory a customer’s agents.
The quote, as the company’s, not as a count. Roey Eliyahu, co-founder and chief executive, said an attack on an AI model can become an attack on the systems that run the business. He said native AI-DR protects LLM interactions and connects what happens at the model to the tools and APIs downstream. He said teams can see the full attack, understand what is at risk, and fill protection gaps while keeping the guardrails they already use. File the name, the title, and those sentences as the release’s. A quote is not a measured breach, and it is not a customer count.
Availability, and what the page leaves blank. Native AI-DR capabilities are available within Salt AG-DR as part of the Salt Agentic Security Platform. The release points readers to salt.security/demo-request. It does not print a price. Do not add one. It does not name a customer who turned the feature on today. Do not add one.
The about box, and where the boast stops. Salt calls itself the leader in agentic and API security. Leader is the company’s word. This desk did not rank vendors. The box says AI is shifting from chatbots that answer to agents that act, and that Salt secures the path from AI-generated code to runtime, across models, MCP servers, tools, and downstream APIs. Founded in 2016. Backed by Sequoia Capital, S Capital, Tenaya Capital, Salesforce Ventures, Advent International, and other investors the page calls leading. That list is the company’s. This desk did not check the cap table.
Plain English for the rest of the card: AI-DR = AI Detection and Response, the new runtime check on the model. LLM = large language model. prompt injection = hidden instructions in what the model reads. jailbreak = a prompt meant to get past the model’s rules. MCP = Model Context Protocol, the plug an agent uses to call a tool. API = the connection that lets one program ask another system to act. AG-DR = Agentic Detection and Response, the runtime product AI-DR is built into. AG-SPM = Agentic Security Posture Management, the view of agents and gaps. graph = the map from agent to model to tool to API. runtime = while the action is happening. guardrail = a check that blocks a risky step. gateway = a middle box. 49.8 percent and 12.5 percent are Salt’s survey figures. www.victim.com is a label on the product image, not a victim this desk named. This filing is the 22 Sep announcement.
PRIMARY here: Salt Security’s 22 Sep 2026 PR Newswire release, “Salt Security Extends Its Agentic Security Platform with Native AI Detection and Response,” stamped 08:00 ET and datelined Palo Alto — Tier A PRIMARY, the company’s own record. The AI-DR name, the real-time detection of direct and indirect prompt injection, jailbreaks, and unsafe model behavior, the OWASP top-ranked sentence, the build into AG-DR, the Agentic Security Graph, the 49.8 percent and 12.5 percent survey lines, the billing-agent illustration, the one view of existing guardrails, the Kubernetes gap line, the Eliyahu title and quote, the availability inside AG-DR, the demo path, the 2016 founding, and the investor list are the release’s. The billing-agent labels, the refund tool, the refund API, the emails, addresses, and phone numbers, and the www.victim.com placeholder are the product image on that wire. NOT claimed: that this desk installed AI-DR, ran the survey, counted the 49.8 percent, ranked prompt injection, confirmed a real billing breach, treated www.victim.com as a real victim, treated 12 Aug on the image as the announcement, found a price, a stock tip, or investment advice. Distinct from the already-filed lumos-mcp-governance, cisco-talos-cairn, and secure-passage-truman-2.
RELATED
On 22 Sep 2026, Salt Security announced native AI Detection and Response, shortened to AI-DR, inside the Salt Agentic Security Platform. The page stamp is Sep 22, 2026, 08:00 ET. The dateline is Palo Alto, Calif. The subhead says the new large-language-model runtime protection connects prompt injection to downstream MCP and API attacks, and helps close gaps in the AI protection a company already has. A large language model, shortened to LLM, is the software that reads a prompt and writes a reply. Agentic, here, means the software takes steps with tools, not only a chat answer. These lines are the company’s. This desk did not install the product.