Salt Security has expanded its Agentic Security Platform with native AI Detection and Response (AI-DR) capabilities designed to connect attacks targeting large language models with subsequent activity across MCP servers, tools and APIs.
The new capabilities provide real-time protection against direct and indirect prompt injection, jailbreak attempts, unsafe model behaviour and other threats that emerge while AI systems are running.
Prompt injection remains the highest-ranked risk in the OWASP Top 10 for LLM Applications 2026. However, Salt Security argues that the risk extends beyond manipulating the model itself. As AI agents gain access to business tools and systems, a malicious prompt can potentially lead to unauthorised actions or expose sensitive information through the infrastructure connected to an agent.
The launch follows Salt Security research which found that 92% of organisations lacked the advanced security maturity required to protect agentic environments.
The survey of over 300 security leaders found that 66% had experienced API growth of more than 50% during the previous year, driven partly by automation and AI adoption. Nearly half of organisations had delayed production releases because of API security concerns, while 32% had experienced an API security incident.
Despite 79% of boards and executive teams increasing their scrutiny of AI security risks, only 18% of respondents were extremely confident in their ability to detect attacks involving generative AI.
Following attacks across the agentic path
Salt’s AI-DR capabilities are built into its existing Agentic Detection and Response platform, extending runtime protection to the LLM layer.
The company’s Agentic Security Graph maps the relationships between AI agents, models, Model Context Protocol servers, tools and downstream APIs. This allows security teams to view an attack against a model alongside any subsequent MCP or API activity within the same platform.
For example, an attacker could manipulate a billing agent into revealing information about a refund tool hosted on an MCP server and the API supporting it. The attacker could then attempt to exploit that API, either through the agent or by targeting the API directly, to issue unauthorised refunds.
Salt said its platform would connect these stages, helping defenders understand how the attack began, which systems were targeted and which business processes may be at risk.
The company’s wider Agentic Security Platform combines Agentic Detection and Response with Agentic Security Posture Management. The posture management component is intended to help organisations identify their AI agents and associated security gaps, while the detection and response capabilities monitor attacks across agents and the systems they use.
Bringing existing AI controls into one view
Salt has also designed the platform to work alongside AI guardrails already deployed through cloud services, endpoint products, SASE platforms, AI gateways and managed AI services.
Through the Agentic Security Graph, security teams can view these different controls and the agents they protect in one place. Salt said this could help organisations identify inconsistencies or areas where runtime protection is missing.
Where existing tools do not provide coverage, including homegrown AI agents running in Kubernetes environments, organisations can apply Salt’s native AI-DR capabilities while retaining their current security products and gateways.
“An attack on an AI model can become an attack on the systems that run the business,” said Roey Eliyahu, co-founder and CEO of Salt Security.
“Our native AI-DR protects LLM interactions and connects what happens at the model to the tools and APIs downstream. Teams can see the full attack, understand what is at risk, and fill protection gaps while keeping the guardrails they already use.”
The native AI-DR capabilities are now available within Salt Agentic Detection and Response as part of the Salt Agentic Security Platform.





