ASAI Security ResearchIndependent public-source research
Public reviewread only

Standards and framework research

OWASP Top 10 for Agentic Applications — research view

Agentic failure-mode lens covering autonomy, tools, identity, memory, multi-agent communication, cascading effects, and oversight.

Scope

All-market research view

This page includes every security requirement connected to OWASP Top 10 for Agentic Applications. Vendor counts, alphabetical examples, and public-support findings come from the current 66-vendor research set; this is not a vendor-specific assessment.

Version2026Current source
Connected requirements13security questions in this research
Security requirements18used consistently across vendors
References31identifiers, clauses, safeguards, or categories

How to use this map

Framework connections help structure your evaluation

Each connection shows how a security requirement relates to this framework. Public vendor claims are shown separately, and deployed effectiveness still requires confirmation or testing.

Contributes
7
Closely aligned
6

Requirement connections

From framework reference to testable evidence

Each row shows how the security requirement relates to the framework, the current public-support findings, and what to verify.

ContributesSpecific reference

AI usage inventory

Maintain an inventory of AI tools, services, models, agents, software as a service (SaaS) AI capabilities, data flows, and provider relationships.

Framework references

ASI04

Lifecycle

Govern · Identify · Monitor

Vendors with public support

66 of 66 vendors reviewed

Foundational security requirementUnapproved AI use discovery

Discover and monitor workforce AI tools, accounts, prompts, domains, models, users, and usage outside approved controls.

Strong public support
44
Limited public support
7
No supporting claim found
15
Research incomplete
0
Question to verify

An unmanaged AI app used by a test user appears in discovery inventory with user, app or domain, and timestamp.

Review claims →
Foundational security requirementAI-feature discovery in business applications

Inventory software as a service (SaaS) applications that embed AI features, expose enterprise data to AI capabilities, or create AI-driven data movement.

Strong public support
20
Limited public support
11
No supporting claim found
35
Research incomplete
0
Question to verify

A software as a service (SaaS) app with an embedded AI feature appears in the software as a service (SaaS) AI inventory with app, provider, and feature context.

Review claims →
Foundational security requirementApproved AI usage monitoring

Monitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.

Strong public support
37
Limited public support
23
No supporting claim found
6
Research incomplete
0
Question to verify

Approved AI workspace activity appears with user, workspace or tenant, model or provider, and timestamp.

Review claims →
How this could be implemented

AI asset inventory · vendor/provider inventory · AI app discovery · model/application programming interface (API)/provider catalog

Alphabetical examples with related public support

Aembit · AIM Security / Cato Networks · Akamai API Security · Akto · Apex Security / Tenable

Showing up to 5 alphabetically; 66 vendors have related public support.
Why this connection is included

Use this for inventory/discovery claims. Do not infer control or blocking from visibility-only language. ISO 42001 excerpt: A.4.2 "identify and document relevant resources"; A.4.3 "data resources utilized"; A.4.4 "tooling resources utilized".

ContributesSpecific reference

AI usage monitoring

Monitor AI usage, user activity, prompts, responses, provider calls, runtime actions, and anomalous behavior.

Framework references

ASI08 · ASI10

Lifecycle

Monitor · Detect · Operate

Vendors with public support

66 of 66 vendors reviewed

Foundational security requirementUnapproved AI use discovery

Discover and monitor workforce AI tools, accounts, prompts, domains, models, users, and usage outside approved controls.

Strong public support
44
Limited public support
7
No supporting claim found
15
Research incomplete
0
Question to verify

An unmanaged AI app used by a test user appears in discovery inventory with user, app or domain, and timestamp.

Review claims →
Foundational security requirementApproved AI usage monitoring

Monitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.

Strong public support
37
Limited public support
23
No supporting claim found
6
Research incomplete
0
Question to verify

Approved AI workspace activity appears with user, workspace or tenant, model or provider, and timestamp.

Review claims →
Foundational security requirementAction-taking agent monitoring

Observe and govern agent plans, memory, tool calls, delegated tasks, autonomy, runtime decisions, and outcomes.

Strong public support
49
Limited public support
13
No supporting claim found
4
Research incomplete
0
Question to verify

A test agent run captures plan, steps, tool calls, outcome, and timestamps.

Review claims →
How this could be implemented

prompt logs · user activity · provider telemetry · agent step tracing · tool call logging

Alphabetical examples with related public support

Aembit · AIM Security / Cato Networks · Akamai API Security · Akto · Apex Security / Tenable

Showing up to 5 alphabetically; 66 vendors have related public support.
Why this connection is included

Monitoring claims should identify what is monitored and where the telemetry comes from. ISO 42001 excerpt: 9.1 "what needs to be monitored"; A.6.2.6 "system and performance monitoring"; A.6.2.8 "event logs should be enabled".

ContributesSpecific reference

unapproved AI control

Enforce policy against unapproved AI tools or unsafe AI interactions through blocking, coaching, allowlists, or runtime controls.

Framework references

ASI01 · ASI02 · ASI10

Lifecycle

Protect · Deploy · Operate

Vendors with public support

64 of 66 vendors reviewed

Foundational security requirementControls for unapproved AI use

Block, coach, redirect, or contain non-approved AI use and policy-violating AI interactions.

Strong public support
37
Limited public support
14
No supporting claim found
15
Research incomplete
0
Question to verify

A policy blocks, coaches, redirects, or contains a test interaction with an unapproved AI destination.

Review claims →
Additional security requirementBrowser and business-application controls

Apply session-level controls in browser and software as a service (SaaS) workflows, including uploads, downloads, copy/paste, sharing, and identity-aware access decisions.

Strong public support
19
Limited public support
10
No supporting claim found
37
Research incomplete
0
Question to verify

A session-level policy controls upload, download, copy, paste, sharing, or form submission in a browser or software as a service (SaaS) workflow.

Review claims →
Additional security requirementGenerative AI application security

Protect enterprise-built large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, application programming interfaces (APIs), model calls, tools, and production runtime behavior.

Strong public support
39
Limited public support
17
No supporting claim found
10
Research incomplete
0
Question to verify

A test large language model (LLM) application event records prompt, application programming interface (API), model, retrieval, or tool interaction context.

Review claims →
How this could be implemented

blocking · allowlists · browser enforcement · policy coaching · large language model (LLM) firewall · tool allowlists

Alphabetical examples with related public support

Aembit · AIM Security / Cato Networks · Akamai API Security · Akto · Apex Security / Tenable

Showing up to 5 alphabetically; 64 vendors have related public support.
Why this connection is included

Distinguish hard blocking from warning, coaching, logging, or after-the-fact reporting. ISO 42001 excerpt: A.9.2 "processes for the responsible use"; A.9.3 "objectives to guide"; A.9.4 "intended uses".

ContributesSpecific reference

AI data protection

Prevent sensitive data exposure through prompts, responses, files, retrieval, memory, embeddings, or AI-connected workflows.

Framework references

ASI03 · ASI06

Lifecycle

Protect · Operate · Monitor

Vendors with public support

65 of 66 vendors reviewed

Foundational security requirementSensitive-data protection for generative AI

Detect, classify, redact, or block sensitive data in prompts, responses, files, retrieval, memory, and AI-connected workflows.

Strong public support
43
Limited public support
15
No supporting claim found
8
Research incomplete
0
Question to verify

Sensitive prompt, response, or file test data is detected and classified during an AI interaction.

Review claims →
Additional security requirementGenerative AI application security

Protect enterprise-built large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, application programming interfaces (APIs), model calls, tools, and production runtime behavior.

Strong public support
39
Limited public support
17
No supporting claim found
10
Research incomplete
0
Question to verify

A test large language model (LLM) application event records prompt, application programming interface (API), model, retrieval, or tool interaction context.

Review claims →
Foundational security requirementApproved AI usage monitoring

Monitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.

Strong public support
37
Limited public support
23
No supporting claim found
6
Research incomplete
0
Question to verify

Approved AI workspace activity appears with user, workspace or tenant, model or provider, and timestamp.

Review claims →
How this could be implemented

data loss prevention (DLP) · redaction · sensitive data detection · output filtering · memory scoping · data-in-use protection

Alphabetical examples with related public support

Aembit · AIM Security / Cato Networks · Akamai API Security · Akto · Apex Security / Tenable

Showing up to 5 alphabetically; 65 vendors have related public support.
Why this connection is included

Require source language that ties data protection to AI use, not generic encryption alone. ISO 42001 excerpt: A.7.3 "acquisition and selection"; A.7.4 "requirements for data quality"; A.7.5 "recording the provenance"; A.7.6 "data preparation methods".

Closely alignedSpecific reference

generative AI application security

Secure large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, tool calls, application programming interfaces (APIs), model interactions, and runtime behavior.

Framework references

ASI01 · ASI02 · ASI05 · ASI06

Lifecycle

Develop · Test · Release · Deploy · Operate

Vendors with public support

65 of 66 vendors reviewed

Additional security requirementGenerative AI application security

Protect enterprise-built large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, application programming interfaces (APIs), model calls, tools, and production runtime behavior.

Strong public support
39
Limited public support
17
No supporting claim found
10
Research incomplete
0
Question to verify

A test large language model (LLM) application event records prompt, application programming interface (API), model, retrieval, or tool interaction context.

Review claims →
Foundational security requirementSensitive-data protection for generative AI

Detect, classify, redact, or block sensitive data in prompts, responses, files, retrieval, memory, and AI-connected workflows.

Strong public support
43
Limited public support
15
No supporting claim found
8
Research incomplete
0
Question to verify

Sensitive prompt, response, or file test data is detected and classified during an AI interaction.

Review claims →
Foundational security requirementControls for unapproved AI use

Block, coach, redirect, or contain non-approved AI use and policy-violating AI interactions.

Strong public support
37
Limited public support
14
No supporting claim found
15
Research incomplete
0
Question to verify

A policy blocks, coaches, redirects, or contains a test interaction with an unapproved AI destination.

Review claims →
Foundational security requirementAI gateway, tool-connection, and runtime controls

Mediate model, agent, tool, application programming interface (API), connector, and Model Context Protocol (MCP) traffic through an enforcement point that applies identity-aware policy, content controls, routing, rate limits, and auditable allow or deny decisions.

Strong public support
42
Limited public support
19
No supporting claim found
5
Research incomplete
0
Question to verify

A model, agent, tool, or Model Context Protocol (MCP) request passes through a named policy enforcement point.

Review claims →
How this could be implemented

prompt injection defense · large language model (LLM) app scanning · retrieval-augmented generation (RAG) security · guardrails · model/application interaction security

Alphabetical examples with related public support

Aembit · AIM Security / Cato Networks · Akamai API Security · Akto · Apex Security / Tenable

Showing up to 5 alphabetically; 65 vendors have related public support.
Why this connection is included

Use for large language model (LLM) application controls. Separate from employee AI usage governance when possible. ISO 42001 excerpt: A.6.2.4 "verification and validation measures"; A.6.2.5 "deployment plan"; A.6.2.6 "ongoing operation"; A.6.2.8 "event logs".

ContributesSpecific reference

AI governance, risk, and compliance operations

Maintain accountable AI inventory, policy, risk assessments, approvals, exceptions, regulatory mappings, third-party oversight, and audit evidence across the AI lifecycle.

Framework references

ASI04 · ASI10

Lifecycle

Govern · Identify · Assess · Approve · Monitor

Vendors with public support

66 of 66 vendors reviewed

Foundational security requirementAI governance, risk, and compliance

Inventory AI systems and owners, translate policy and regulatory obligations into governed workflows, assess risk, manage approvals and exceptions, and retain audit evidence across the AI lifecycle.

Strong public support
36
Limited public support
20
No supporting claim found
10
Research incomplete
0
Question to verify

A test AI system is registered with owner, intended use, risk tier, lifecycle state, and applicable obligations.

Review claims →
Foundational security requirementApproved AI usage monitoring

Monitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.

Strong public support
37
Limited public support
23
No supporting claim found
6
Research incomplete
0
Question to verify

Approved AI workspace activity appears with user, workspace or tenant, model or provider, and timestamp.

Review claims →
Foundational security requirementAI-feature discovery in business applications

Inventory software as a service (SaaS) applications that embed AI features, expose enterprise data to AI capabilities, or create AI-driven data movement.

Strong public support
20
Limited public support
11
No supporting claim found
35
Research incomplete
0
Question to verify

A software as a service (SaaS) app with an embedded AI feature appears in the software as a service (SaaS) AI inventory with app, provider, and feature context.

Review claims →
How this could be implemented

AI system registry · risk tiering · policy workflow · regulatory mapping · approval and exception workflow · audit evidence

Alphabetical examples with related public support

Aembit · AIM Security / Cato Networks · Akamai API Security · Akto · Apex Security / Tenable

Showing up to 5 alphabetically; 66 vendors have related public support.
Why this connection is included

Governance evidence must show accountable workflow or decision evidence, not technical inventory alone. ISO 42001 excerpt: A.9.2 "processes for the responsible use"; A.9.3 "objectives to guide"; A.10.2 "allocated between".

Closely alignedSpecific reference

AI assurance, red teaming, and supply-chain security

Test models, applications, retrieval-augmented generation (RAG) systems, agents, coding workflows, and AI artifacts before release and continuously thereafter, with reproducible findings and remediation gates.

Framework references

ASI01 · ASI02 · ASI04

Lifecycle

Develop · Test · Release · Monitor

Vendors with public support

57 of 66 vendors reviewed

Foundational security requirementAI assurance and adversarial testing

Test models, applications, retrieval-augmented generation (RAG) systems, and agents before release and continuously thereafter using adversarial probes, evaluation suites, attack simulation, and security release gates.

Strong public support
24
Limited public support
3
No supporting claim found
39
Research incomplete
0
Question to verify

A controlled test campaign exercises an AI model, application, or agent against named AI attack classes.

Review claims →
Foundational security requirementAI model and supply-chain security

Discover, inventory, scan, validate, and monitor models, datasets, model artifacts, registries, dependencies, and AI development assets for tampering, unsafe serialization, provenance gaps, or malicious content.

Strong public support
13
Limited public support
28
No supporting claim found
25
Research incomplete
0
Question to verify

A test model or AI artifact appears in inventory with origin, version, hash or provenance, and deployment context.

Review claims →
Additional security requirementAI coding-agent and workstation security

Discover and govern AI coding agents, integrated development environment (IDE) assistants, command-line agents, skills, hooks, extensions, Model Context Protocol (MCP) tools, filesystem access, commands, network activity, secrets, and software-supply-chain actions on developer workstations and build environments.

Strong public support
14
Limited public support
27
No supporting claim found
25
Research incomplete
0
Question to verify

A test coding agent and its skills, hooks, extensions, or Model Context Protocol (MCP) tools appear in an attributable inventory.

Review claims →
How this could be implemented

AI red teaming · attack simulation · continuous evaluation · model scanning · AI bill of materials (AI-BOM) · coding-agent policy · release gate

Alphabetical examples with related public support

AIM Security / Cato Networks · Akto · Apex Security / Tenable · Aurascape · Backslash Agentic AI Endpoint Security

Showing up to 5 alphabetically; 57 vendors have related public support.
Why this connection is included

Keep pre-deployment testing, artifact integrity, and coding-agent controls distinguishable from runtime blocking. ISO 42001 excerpt: A.6.2.4 "verification and validation measures"; A.6.2.5 "deployment plan"; A.6.2.6 "ongoing operation".

Closely alignedSpecific reference

Third-party and software as a service (SaaS) AI risk

Understand and monitor AI risk introduced by external software as a service (SaaS), AI providers, embedded AI features, and supplier services.

Framework references

ASI04

Lifecycle

Govern · Identify · Detect

Vendors with public support

51 of 66 vendors reviewed

Foundational security requirementAI-feature discovery in business applications

Inventory software as a service (SaaS) applications that embed AI features, expose enterprise data to AI capabilities, or create AI-driven data movement.

Strong public support
20
Limited public support
11
No supporting claim found
35
Research incomplete
0
Question to verify

A software as a service (SaaS) app with an embedded AI feature appears in the software as a service (SaaS) AI inventory with app, provider, and feature context.

Review claims →
Foundational security requirementUnapproved AI use discovery

Discover and monitor workforce AI tools, accounts, prompts, domains, models, users, and usage outside approved controls.

Strong public support
44
Limited public support
7
No supporting claim found
15
Research incomplete
0
Question to verify

An unmanaged AI app used by a test user appears in discovery inventory with user, app or domain, and timestamp.

Review claims →
Platform contextApproved AI platform context

Where a vendor's public claims appear to complement, overlap with, or sit outside native controls in approved enterprise AI deployments.

Strong public support
0
Limited public support
0
No supporting claim found
0
Research incomplete
66
Question to verify

The pilot documents where platform-native controls stop and where the external control begins.

Review claims →
How this could be implemented

third-party AI inventory · supplier AI service monitoring · software as a service (SaaS) AI detection · provider activity monitoring

Alphabetical examples with related public support

AIM Security / Cato Networks · Akto · Apex Security / Tenable · Astrix Security / Cisco · Aurascape

Showing up to 5 alphabetically; 51 vendors have related public support.
Why this connection is included

Third-party sources are only allowed in the project if one source class covers at least 80 percent of vendors. ISO 42001 excerpt: A.10.2 "allocated between"; A.10.3 "provided by suppliers aligns".

Closely alignedSpecific reference

Agentic telemetry and behavior monitoring

Observe agent steps, plans, goals, memory, delegation, tool use, and anomalies during runtime.

Framework references

ASI02 · ASI06 · ASI08 · ASI10

Lifecycle

Operate · Monitor · Detect

Vendors with public support

63 of 66 vendors reviewed

Foundational security requirementAction-taking agent monitoring

Observe and govern agent plans, memory, tool calls, delegated tasks, autonomy, runtime decisions, and outcomes.

Strong public support
49
Limited public support
13
No supporting claim found
4
Research incomplete
0
Question to verify

A test agent run captures plan, steps, tool calls, outcome, and timestamps.

Review claims →
Foundational security requirementAgent-to-agent communication security

Authorize, log, and control agent-to-agent, agent-to-tool, Model Context Protocol (MCP), connector, and tool-chain handoffs.

Strong public support
12
Limited public support
34
No supporting claim found
20
Research incomplete
0
Question to verify

An agent, tool, connector, or Model Context Protocol (MCP) handoff logs source identity, destination, and authorization decision.

Review claims →
Foundational security requirementNon-human identity and service-account security

Inventory, least privilege, credential hygiene, monitoring, and lifecycle management for non-human identities, workloads, service accounts, application programming interface (API) keys, and machine credentials.

Strong public support
14
Limited public support
19
No supporting claim found
33
Research incomplete
0
Question to verify

A test service account, agent identity, or non-human identity appears in inventory with owner and privileges.

Review claims →
How this could be implemented

agent traces · goal drift detection · memory mutation monitoring · tool execution logs · anomalous delegation

Alphabetical examples with related public support

Aembit · AIM Security / Cato Networks · Akto · Apex Security / Tenable · Astrix Security / Cisco

Showing up to 5 alphabetically; 63 vendors have related public support.
Why this connection is included

Require explicit agent language. Generic chatbot monitoring is not enough. ISO 42001 excerpt: 9.1 "monitoring and measuring"; A.6.2.6 "system and performance monitoring"; A.6.2.8 "event logs should be enabled".

Closely alignedSpecific reference

Agent-to-agent and tool communication security

Secure trust, authorization, message flows, tool access, and communication between agents, tools, application programming interfaces (APIs), and external services.

Framework references

ASI02 · ASI04 · ASI07 · ASI08

Lifecycle

Identify · Protect · Deploy · Monitor

Vendors with public support

66 of 66 vendors reviewed

Foundational security requirementAgent-to-agent communication security

Authorize, log, and control agent-to-agent, agent-to-tool, Model Context Protocol (MCP), connector, and tool-chain handoffs.

Strong public support
12
Limited public support
34
No supporting claim found
20
Research incomplete
0
Question to verify

An agent, tool, connector, or Model Context Protocol (MCP) handoff logs source identity, destination, and authorization decision.

Review claims →
Foundational security requirementAction-taking agent monitoring

Observe and govern agent plans, memory, tool calls, delegated tasks, autonomy, runtime decisions, and outcomes.

Strong public support
49
Limited public support
13
No supporting claim found
4
Research incomplete
0
Question to verify

A test agent run captures plan, steps, tool calls, outcome, and timestamps.

Review claims →
Additional security requirementGenerative AI application security

Protect enterprise-built large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, application programming interfaces (APIs), model calls, tools, and production runtime behavior.

Strong public support
39
Limited public support
17
No supporting claim found
10
Research incomplete
0
Question to verify

A test large language model (LLM) application event records prompt, application programming interface (API), model, retrieval, or tool interaction context.

Review claims →
Foundational security requirementAI gateway, tool-connection, and runtime controls

Mediate model, agent, tool, application programming interface (API), connector, and Model Context Protocol (MCP) traffic through an enforcement point that applies identity-aware policy, content controls, routing, rate limits, and auditable allow or deny decisions.

Strong public support
42
Limited public support
19
No supporting claim found
5
Research incomplete
0
Question to verify

A model, agent, tool, or Model Context Protocol (MCP) request passes through a named policy enforcement point.

Review claims →
How this could be implemented

agent-to-agent (A2A) registry · mutual TLS (mTLS) · inter-agent authorization · connector contracts · tool schemas · message logs

Alphabetical examples with related public support

Aembit · AIM Security / Cato Networks · Akamai API Security · Akto · Apex Security / Tenable

Showing up to 5 alphabetically; 66 vendors have related public support.
Why this connection is included

Do not map agent-to-agent (A2A) unless a source mentions agents, tools, connectors, protocols, or machine-to-machine authorization. ISO 42001 has no direct agent-to-agent (A2A) security control. ISO 42001 excerpt: A.6.2.4 "verification and validation measures"; A.6.2.8 "event logs"; A.10.2 "allocated between".

Closely alignedSpecific reference

non-human identity (NHI) and AI-agent identity governance

Manage identities, credentials, privileges, secrets, service accounts, and lifecycle for AI agents and other non-human identities.

Framework references

ASI03 · ASI07

Lifecycle

Govern · Protect · Deploy · Operate

Vendors with public support

60 of 66 vendors reviewed

Foundational security requirementNon-human identity and service-account security

Inventory, least privilege, credential hygiene, monitoring, and lifecycle management for non-human identities, workloads, service accounts, application programming interface (API) keys, and machine credentials.

Strong public support
14
Limited public support
19
No supporting claim found
33
Research incomplete
0
Question to verify

A test service account, agent identity, or non-human identity appears in inventory with owner and privileges.

Review claims →
Foundational security requirementAI agent identity and permissions

Register AI agents as accountable identities, bind them to owners and delegating users, authorize task- and tool-level access, issue short-lived credentials, review access, and revoke or suspend agent authority.

Strong public support
15
Limited public support
39
No supporting claim found
12
Research incomplete
0
Question to verify

A test agent is registered with a unique identity, accountable owner, purpose, and permitted resources.

Review claims →
Foundational security requirementAgent-to-agent communication security

Authorize, log, and control agent-to-agent, agent-to-tool, Model Context Protocol (MCP), connector, and tool-chain handoffs.

Strong public support
12
Limited public support
34
No supporting claim found
20
Research incomplete
0
Question to verify

An agent, tool, connector, or Model Context Protocol (MCP) handoff logs source identity, destination, and authorization decision.

Review claims →
Foundational security requirementAI-feature discovery in business applications

Inventory software as a service (SaaS) applications that embed AI features, expose enterprise data to AI capabilities, or create AI-driven data movement.

Strong public support
20
Limited public support
11
No supporting claim found
35
Research incomplete
0
Question to verify

A software as a service (SaaS) app with an embedded AI feature appears in the software as a service (SaaS) AI inventory with app, provider, and feature context.

Review claims →
How this could be implemented

non-human identity (NHI) inventory · AI service accounts · least privilege · credential rotation · scoped tokens · privilege review

Alphabetical examples with related public support

Aembit · AIM Security / Cato Networks · Akto · Apex Security / Tenable · Astrix Security / Cisco

Showing up to 5 alphabetically; 60 vendors have related public support.
Why this connection is included

Separate AI-agent identity claims from generic human identity and access management (IAM) unless the vendor explicitly spans service accounts or NHIs. ISO 42001 has no direct non-human identity (NHI) identity control. ISO 42001 excerpt: A.4.2 "relevant resources"; A.10.2 "responsibilities".

ContributesSpecific reference

AI FinOps and cost accountability

Attribute AI usage and spend to accountable owners, workflows, agents, models, and business units while enforcing budget, rate-limit, and routing controls.

Framework references

ASI02 · ASI08

Lifecycle

Govern · Operate · Optimize

Vendors with public support

66 of 66 vendors reviewed

Additional security requirementAI cost and usage controls

Visibility, attribution, budgeting, rate limiting, anomaly detection, and optimization for AI usage and spend across models, agents, workflows, and owners.

Strong public support
5
Limited public support
9
No supporting claim found
46
Research incomplete
6
Question to verify

A controlled AI usage event is attributed to user, team, model, workflow, or owner with cost or token metrics.

Review claims →
Foundational security requirementApproved AI usage monitoring

Monitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.

Strong public support
37
Limited public support
23
No supporting claim found
6
Research incomplete
0
Question to verify

Approved AI workspace activity appears with user, workspace or tenant, model or provider, and timestamp.

Review claims →
Foundational security requirementAction-taking agent monitoring

Observe and govern agent plans, memory, tool calls, delegated tasks, autonomy, runtime decisions, and outcomes.

Strong public support
49
Limited public support
13
No supporting claim found
4
Research incomplete
0
Question to verify

A test agent run captures plan, steps, tool calls, outcome, and timestamps.

Review claims →
Foundational security requirementNon-human identity and service-account security

Inventory, least privilege, credential hygiene, monitoring, and lifecycle management for non-human identities, workloads, service accounts, application programming interface (API) keys, and machine credentials.

Strong public support
14
Limited public support
19
No supporting claim found
33
Research incomplete
0
Question to verify

A test service account, agent identity, or non-human identity appears in inventory with owner and privileges.

Review claims →
How this could be implemented

AI spend attribution · runaway token burn detection · budget enforcement · rate limits · model routing · owner-based cost reporting

Alphabetical examples with related public support

Aembit · AIM Security / Cato Networks · Akamai API Security · Akto · Apex Security / Tenable

Showing up to 5 alphabetically; 66 vendors have related public support.
Why this connection is included

Keep this separate from licensing. Require source language about operational usage, spend, budgets, rate limits, model routing, or owner attribution. ISO 42001 excerpt: A.9.2 "responsible use of AI systems"; A.9.3 "objectives to guide".

ContributesSpecific reference

Enterprise AI platform context

Show whether vendor claims complement, overlap with, or sit outside native controls in approved enterprise AI platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini Enterprise, Gemini for Google Cloud, Microsoft Copilot, Vertex AI, or an internal AI gateway.

Framework references

ASI04

Lifecycle

Architecture context

Vendors with public support

0 of 66 vendors reviewed

Platform contextApproved AI platform context

Where a vendor's public claims appear to complement, overlap with, or sit outside native controls in approved enterprise AI deployments.

Strong public support
0
Limited public support
0
No supporting claim found
0
Research incomplete
66
Question to verify

The pilot documents where platform-native controls stop and where the external control begins.

Review claims →
How this could be implemented

outside approved AI · native-platform complement · gateway overlap · provider coverage · browser/software as a service (SaaS)/application programming interface (API) layer

Alphabetical examples with related public support

Showing up to 5 alphabetically; 0 vendors have related public support.
Why this connection is included

This is an enterprise architecture context view. Keep it separate from vendor factual claims.

This page organizes research. Audit conclusions, certification assessments, control implementation statements, and vendor endorsements require separate evidence.