OWASP Agentic AI Security Solutions Landscape — research view
Market and lifecycle lens for agentic AI, agent-to-agent (A2A), tool, memory, non-human identity (NHI), and runtime controls.
Scope
All-market research view
This page includes every security requirement connected to OWASP Agentic AI Security Solutions Landscape. Vendor counts, alphabetical examples, and public-support findings come from the current 66-vendor research set; this is not a vendor-specific assessment.
VersionQ2/Q3 2026Informational source
Connected requirements12security questions in this research
Security requirements18used consistently across vendors
References31identifiers, clauses, safeguards, or categories
How to use this map
Framework connections help structure your evaluation
Each connection shows how a security requirement relates to this framework. Public vendor claims are shown separately, and deployed effectiveness still requires confirmation or testing.
Contributes
5
Closely aligned
6
Related context
1
Requirement connections
From framework reference to testable evidence
Each row shows how the security requirement relates to the framework, the current public-support findings, and what to verify.
ContributesFramework section
AI usage inventory
Maintain an inventory of AI tools, services, models, agents, software as a service (SaaS) AI capabilities, data flows, and provider relationships.
Framework references
Agentic Registry · Register all agents in an internal trust registry
Lifecycle
Govern · Identify · Monitor
Vendors with public support
66 of 66 vendors reviewed
Foundational security requirementUnapproved AI use discovery
Discover and monitor workforce AI tools, accounts, prompts, domains, models, users, and usage outside approved controls.
Strong public support
44
Limited public support
7
No supporting claim found
15
Research incomplete
0
Foundational security requirementAI-feature discovery in business applications
Inventory software as a service (SaaS) applications that embed AI features, expose enterprise data to AI capabilities, or create AI-driven data movement.
Strong public support
20
Limited public support
11
No supporting claim found
35
Research incomplete
0
Foundational security requirementApproved AI usage monitoring
Monitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.
Strong public support
37
Limited public support
23
No supporting claim found
6
Research incomplete
0
Closely alignedFramework section
AI usage monitoring
Monitor AI usage, user activity, prompts, responses, provider calls, runtime actions, and anomalous behavior.
Foundational security requirementUnapproved AI use discovery
Discover and monitor workforce AI tools, accounts, prompts, domains, models, users, and usage outside approved controls.
Strong public support
44
Limited public support
7
No supporting claim found
15
Research incomplete
0
Foundational security requirementApproved AI usage monitoring
Monitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.
Foundational security requirementControls for unapproved AI use
Block, coach, redirect, or contain non-approved AI use and policy-violating AI interactions.
Strong public support
37
Limited public support
14
No supporting claim found
15
Research incomplete
0
Additional security requirementBrowser and business-application controls
Apply session-level controls in browser and software as a service (SaaS) workflows, including uploads, downloads, copy/paste, sharing, and identity-aware access decisions.
Strong public support
19
Limited public support
10
No supporting claim found
37
Research incomplete
0
Additional security requirementGenerative AI application security
Protect enterprise-built large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, application programming interfaces (APIs), model calls, tools, and production runtime behavior.
Strong public support
39
Limited public support
17
No supporting claim found
10
Research incomplete
0
ContributesFramework section
AI data protection
Prevent sensitive data exposure through prompts, responses, files, retrieval, memory, embeddings, or AI-connected workflows.
Foundational security requirementSensitive-data protection for generative AI
Detect, classify, redact, or block sensitive data in prompts, responses, files, retrieval, memory, and AI-connected workflows.
Strong public support
43
Limited public support
15
No supporting claim found
8
Research incomplete
0
Additional security requirementGenerative AI application security
Protect enterprise-built large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, application programming interfaces (APIs), model calls, tools, and production runtime behavior.
Strong public support
39
Limited public support
17
No supporting claim found
10
Research incomplete
0
Foundational security requirementApproved AI usage monitoring
Monitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.
Strong public support
37
Limited public support
23
No supporting claim found
6
Research incomplete
0
Related contextFramework section
generative AI application security
Secure large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, tool calls, application programming interfaces (APIs), model interactions, and runtime behavior.
Framework references
Validate connector contracts · Sandboxed testing of tool calls
Lifecycle
Develop · Test · Release · Deploy · Operate
Vendors with public support
65 of 66 vendors reviewed
Additional security requirementGenerative AI application security
Protect enterprise-built large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, application programming interfaces (APIs), model calls, tools, and production runtime behavior.
Strong public support
39
Limited public support
17
No supporting claim found
10
Research incomplete
0
Foundational security requirementSensitive-data protection for generative AI
Detect, classify, redact, or block sensitive data in prompts, responses, files, retrieval, memory, and AI-connected workflows.
Strong public support
43
Limited public support
15
No supporting claim found
8
Research incomplete
0
Foundational security requirementControls for unapproved AI use
Block, coach, redirect, or contain non-approved AI use and policy-violating AI interactions.
Strong public support
37
Limited public support
14
No supporting claim found
15
Research incomplete
0
Foundational security requirementAI gateway, tool-connection, and runtime controls
Mediate model, agent, tool, application programming interface (API), connector, and Model Context Protocol (MCP) traffic through an enforcement point that applies identity-aware policy, content controls, routing, rate limits, and auditable allow or deny decisions.
Strong public support
42
Limited public support
19
No supporting claim found
5
Research incomplete
0
ContributesFramework section
AI governance, risk, and compliance operations
Maintain accountable AI inventory, policy, risk assessments, approvals, exceptions, regulatory mappings, third-party oversight, and audit evidence across the AI lifecycle.
Foundational security requirementAI governance, risk, and compliance
Inventory AI systems and owners, translate policy and regulatory obligations into governed workflows, assess risk, manage approvals and exceptions, and retain audit evidence across the AI lifecycle.
Strong public support
36
Limited public support
20
No supporting claim found
10
Research incomplete
0
Foundational security requirementApproved AI usage monitoring
Monitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.
Strong public support
37
Limited public support
23
No supporting claim found
6
Research incomplete
0
Foundational security requirementAI-feature discovery in business applications
Inventory software as a service (SaaS) applications that embed AI features, expose enterprise data to AI capabilities, or create AI-driven data movement.
Strong public support
20
Limited public support
11
No supporting claim found
35
Research incomplete
0
Closely alignedFramework section
AI assurance, red teaming, and supply-chain security
Test models, applications, retrieval-augmented generation (RAG) systems, agents, coding workflows, and AI artifacts before release and continuously thereafter, with reproducible findings and remediation gates.
Framework references
Sandboxed testing of tool calls · Validate connector contracts
Lifecycle
Develop · Test · Release · Monitor
Vendors with public support
57 of 66 vendors reviewed
Foundational security requirementAI assurance and adversarial testing
Test models, applications, retrieval-augmented generation (RAG) systems, and agents before release and continuously thereafter using adversarial probes, evaluation suites, attack simulation, and security release gates.
Strong public support
24
Limited public support
3
No supporting claim found
39
Research incomplete
0
Foundational security requirementAI model and supply-chain security
Discover, inventory, scan, validate, and monitor models, datasets, model artifacts, registries, dependencies, and AI development assets for tampering, unsafe serialization, provenance gaps, or malicious content.
Strong public support
13
Limited public support
28
No supporting claim found
25
Research incomplete
0
Additional security requirementAI coding-agent and workstation security
Discover and govern AI coding agents, integrated development environment (IDE) assistants, command-line agents, skills, hooks, extensions, Model Context Protocol (MCP) tools, filesystem access, commands, network activity, secrets, and software-supply-chain actions on developer workstations and build environments.
Strong public support
14
Limited public support
27
No supporting claim found
25
Research incomplete
0
ContributesFramework section
Third-party and software as a service (SaaS) AI risk
Understand and monitor AI risk introduced by external software as a service (SaaS), AI providers, embedded AI features, and supplier services.
Framework references
External services and tooling · Plugins · External APIs
Lifecycle
Govern · Identify · Detect
Vendors with public support
51 of 66 vendors reviewed
Foundational security requirementAI-feature discovery in business applications
Inventory software as a service (SaaS) applications that embed AI features, expose enterprise data to AI capabilities, or create AI-driven data movement.
Strong public support
20
Limited public support
11
No supporting claim found
35
Research incomplete
0
Foundational security requirementUnapproved AI use discovery
Discover and monitor workforce AI tools, accounts, prompts, domains, models, users, and usage outside approved controls.
Strong public support
44
Limited public support
7
No supporting claim found
15
Research incomplete
0
Platform contextApproved AI platform context
Where a vendor's public claims appear to complement, overlap with, or sit outside native controls in approved enterprise AI deployments.
Strong public support
0
Limited public support
0
No supporting claim found
0
Research incomplete
66
Closely alignedFramework section
Agentic telemetry and behavior monitoring
Observe agent steps, plans, goals, memory, delegation, tool use, and anomalies during runtime.
Observe and govern agent plans, memory, tool calls, delegated tasks, autonomy, runtime decisions, and outcomes.
Strong public support
49
Limited public support
13
No supporting claim found
4
Research incomplete
0
Foundational security requirementAgent-to-agent communication security
Authorize, log, and control agent-to-agent, agent-to-tool, Model Context Protocol (MCP), connector, and tool-chain handoffs.
Strong public support
12
Limited public support
34
No supporting claim found
20
Research incomplete
0
Foundational security requirementNon-human identity and service-account security
Inventory, least privilege, credential hygiene, monitoring, and lifecycle management for non-human identities, workloads, service accounts, application programming interface (API) keys, and machine credentials.
Strong public support
14
Limited public support
19
No supporting claim found
33
Research incomplete
0
Closely alignedFramework section
Agent-to-agent and tool communication security
Secure trust, authorization, message flows, tool access, and communication between agents, tools, application programming interfaces (APIs), and external services.
Framework references
Design inter-agent communication · A2A registry · Zero-trust policies between agents
Lifecycle
Identify · Protect · Deploy · Monitor
Vendors with public support
66 of 66 vendors reviewed
Foundational security requirementAgent-to-agent communication security
Authorize, log, and control agent-to-agent, agent-to-tool, Model Context Protocol (MCP), connector, and tool-chain handoffs.
Observe and govern agent plans, memory, tool calls, delegated tasks, autonomy, runtime decisions, and outcomes.
Strong public support
49
Limited public support
13
No supporting claim found
4
Research incomplete
0
Additional security requirementGenerative AI application security
Protect enterprise-built large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, application programming interfaces (APIs), model calls, tools, and production runtime behavior.
Strong public support
39
Limited public support
17
No supporting claim found
10
Research incomplete
0
Foundational security requirementAI gateway, tool-connection, and runtime controls
Mediate model, agent, tool, application programming interface (API), connector, and Model Context Protocol (MCP) traffic through an enforcement point that applies identity-aware policy, content controls, routing, rate limits, and auditable allow or deny decisions.
Strong public support
42
Limited public support
19
No supporting claim found
5
Research incomplete
0
Closely alignedFramework section
non-human identity (NHI) and AI-agent identity governance
Manage identities, credentials, privileges, secrets, service accounts, and lifecycle for AI agents and other non-human identities.
Foundational security requirementNon-human identity and service-account security
Inventory, least privilege, credential hygiene, monitoring, and lifecycle management for non-human identities, workloads, service accounts, application programming interface (API) keys, and machine credentials.
Strong public support
14
Limited public support
19
No supporting claim found
33
Research incomplete
0
Foundational security requirementAI agent identity and permissions
Register AI agents as accountable identities, bind them to owners and delegating users, authorize task- and tool-level access, issue short-lived credentials, review access, and revoke or suspend agent authority.
Strong public support
15
Limited public support
39
No supporting claim found
12
Research incomplete
0
Foundational security requirementAgent-to-agent communication security
Authorize, log, and control agent-to-agent, agent-to-tool, Model Context Protocol (MCP), connector, and tool-chain handoffs.
Strong public support
12
Limited public support
34
No supporting claim found
20
Research incomplete
0
Foundational security requirementAI-feature discovery in business applications
Inventory software as a service (SaaS) applications that embed AI features, expose enterprise data to AI capabilities, or create AI-driven data movement.
Strong public support
20
Limited public support
11
No supporting claim found
35
Research incomplete
0
ContributesFramework section
AI FinOps and cost accountability
Attribute AI usage and spend to accountable owners, workflows, agents, models, and business units while enforcing budget, rate-limit, and routing controls.
Framework references
Agent runtime governance · Tool and model access governance
Lifecycle
Govern · Operate · Optimize
Vendors with public support
66 of 66 vendors reviewed
Additional security requirementAI cost and usage controls
Visibility, attribution, budgeting, rate limiting, anomaly detection, and optimization for AI usage and spend across models, agents, workflows, and owners.
Strong public support
5
Limited public support
9
No supporting claim found
46
Research incomplete
6
Foundational security requirementApproved AI usage monitoring
Monitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.
Observe and govern agent plans, memory, tool calls, delegated tasks, autonomy, runtime decisions, and outcomes.
Strong public support
49
Limited public support
13
No supporting claim found
4
Research incomplete
0
Foundational security requirementNon-human identity and service-account security
Inventory, least privilege, credential hygiene, monitoring, and lifecycle management for non-human identities, workloads, service accounts, application programming interface (API) keys, and machine credentials.
Strong public support
14
Limited public support
19
No supporting claim found
33
Research incomplete
0
This page organizes research. Audit conclusions, certification assessments, control implementation statements, and vendor endorsements require separate evidence.