Blog
min read
Pillar Security Named a Pioneer in the 2026 Gartner® Emerging Market Quadrant for AI Application Security
.png)
Gartner recognized Pillar as a Pioneer among startup vendors protecting enterprise AI applications and agents, from discovery and red teaming to runtime defense.
Gartner has named Pillar Security a Pioneer in the 2026 Gartner® Emerging Market Quadrant for AI Application Security — Startup Vendors.
When we started Pillar, most security teams had never seen an AI agent inside their environment. Today they are finding them in code repositories, CI/CD pipelines, SaaS tools, and on employee laptops, alongside the customer-facing chatbots, copilots, and internal AI applications those same teams shipped over the past two years, often without knowing who deployed them or what they can reach.
Gartner now tracks the vendors securing those agents as a market of its own, and it has placed Pillar among the startups it evaluated in that market. For a company that has spent its short life arguing that agents need their own security layer, that is a milestone worth marking.
If this is the first time you are hearing about us: Pillar Security helps enterprises find, test, and protect the AI agents and AI applications they build and run. Security practitioners founded the company in 2024; we have headquarters in Miami and Tel Aviv, and our research team has published some of the first documented real-world attacks on production AI agents.
Why AI applications & agents need their own security layer
For decades, insider risk programs rested on a few quiet assumptions: people work at human speed, they face personal consequences, and their behavior is mostly predictable. AI apps and agents break every one of those. They run around the clock, they scale the moment someone copies a config file, and they hold legitimate credentials to sensitive systems.
The attack surface is different too. A poisoned web page, README file, email, or tool description can redirect an agent while it continues to use approved credentials and tools. To a firewall, EDR, or identity provider, nothing looks wrong. A trusted process is doing permitted actions. The harm is in the intent behind the sequence of actions, and nobody designed the existing controls to see that.
How Pillar rebuilds insider defense for a workforce of agents
You cannot manage an agent like an employee. You won’t send it to security awareness training or count on it to hesitate. But the logic of insider defense still holds if you rebuild each piece for software that acts on its own. Below is how we rebuilt each one.
Start with a complete inventory of every agent and what it can reach
Every company can produce a list of its employees. Very few can produce a list of their AI applications, let alone their agents. Pillar discovers AI applications and agents across endpoints, source-code repositories, CI/CD pipelines, cloud platforms, SaaS applications, and no-code builders, then maps each one to its owner, permissions, tools, data, and memory. Without that inventory, every other control starts blind.
Stop harmful actions before they execute
An agent can do in seconds what a human insider would need days to pull off, so a log entry after the fact is not a control. Pillar's runtime protection evaluates AI application and agent activity as it happens and can alert on or block a dangerous action before it runs. Guardrails cover prompt injection, sensitive data leakage, tool misuse, and unsafe commands across the agents, MCP servers, and tools in a workflow, and findings reach the SOC through existing SIEM and ticketing integrations.
Red-team your agentic workflows continuously, before an attacker does it for you
Enterprises have run phishing simulations against employees for years. Agents need the same adversarial discipline, applied continuously. RedGraph Suite is itself an autonomous agent. It plans and runs adversarial campaigns against complete agentic workflows, probing for goal hijacking, indirect prompt injection, tool misuse, memory poisoning, and privilege escalation, and adapting its next move based on how the target responds. Static prompt libraries cannot keep up with systems that reason; you cannot protect AI without AI.
Validated findings feed straight into runtime controls. Runtime activity updates the asset map and shapes the next assessment. A discovered attack path becomes a policy, and Pillar retests the policy to prove the risk is closed.
We built the platform around that loop from the start. Most teams still run red-team exercises as a one-off project and hand the findings to whoever owns the guardrails, and by the time the fix ships, the agent has changed. In Pillar, the finding and the fix live in the same system, so when RedGraph shows an attack path today, the runtime policy that blocks it follows directly from the finding, and the next test run confirms it holds.
The SAIL Framework: Turning controls into a program
Technology is only part of the answer. Someone has to own each agent, decide how much autonomy it gets, choose which controls come first, and get security, engineering, AI, legal, and compliance working from the same plan. So we built the open-source SAIL framework with AI and cybersecurity practitioners.
Practitioners have downloaded SAIL more than 50,000 times. SAIL 2.0 maps 91 risks across the agent lifecycle and turns them into roadmaps, assessments, control requirements, and compliance checklists that teams can actually run.
Original research is where our detections come from
The attacks are new and the defensive playbook barely exists, so agentic security has to come from original research. Pillar's research team published the Rules File Backdoor, which showed how attackers can silently compromise AI coding assistants such as GitHub Copilot and Cursor, and the first production agent-to-agent privilege escalation exploit, along with dozens of other critical findings across the agent stack.
The work does not stay in the lab. Pillar contributes to the OWASP GenAI Security Project and its Agentic Top 10, and we help shape emerging standards such as the Agent Control Standard. Every finding also flows back into the product: an attack our researchers discover becomes a guardrail or detection rule our customers get.
How the AI application security market maps to what Pillar built
AI application security is the market Gartner evaluated Pillar in. In practice, the category covers three connected jobs: finding and inventorying the AI applications and agents an enterprise builds and runs, testing them adversarially before attackers do, and defending them at runtime by detecting and blocking harmful activity as it happens. Those three jobs are the platform described above.
The Pillar platform includes the testing, discovery, and inventory that form the exposure management, and runtime protection is the defense. We did not build Pillar to match a category definition, but it is a good sign when the analysts describing a new market land on the same shape.
Gartner explains the Emerging Market Quadrant series on its Emerging Market Quadrant page, and Gartner clients can read the full report in their Gartner account.
Thank you
Building in a new category takes researchers uncovering attack paths that did not exist a year ago, engineers turning those findings into controls that hold up in production, customers willing to deploy agents and secure them with us, and practitioners helping define what good looks like. To everyone at Pillar, and to every customer, partner, contributor, and investor who has backed this mission: thank you. We are building the security foundation for the agentic workforce together.
Talk to us.
If your organization is building AI applications, deploying AI agents, or trying to find the ones already running, we would like to show you how Pillar discovers, tests, and protects them. Schedule a demo with our team.
About Pillar Security
Pillar Security is an AI and agentic security company headquartered in Miami and Tel Aviv. The Pillar platform discovers AI agents and applications across the enterprise, continuously red-teams them with RedGraph, and enforces runtime guardrails that block harmful actions before they execute. Pillar's research team has disclosed some of the first real-world attacks on production AI agents, and Pillar maintains SAIL, the open-source framework for securing AI agents across their lifecycle.
Disclaimers:
Gartner, Emerging Market Quadrant for AI Application Security — Startup Vendors, Meghan Hollis, Dionisio Zumerle, Dennis Xu, Marissa Schmidt, 16 September 2026.
GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and is used herein with permission. All rights reserved.
Gartner does not endorse any company, vendor, product or service depicted in its publications and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner's business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.
FAQs
What is Pillar Security?
Pillar Security is an AI security company that helps enterprises discover, test, and protect the AI agents and AI applications they build and run. Its platform combines agent discovery and inventory, continuous AI red teaming (RedGraph), and runtime protection, and it maintains the open-source SAIL framework for AI agent security governance.
What did Gartner recognize Pillar Security for?
Gartner named Pillar Security a Pioneer in the 2026 Gartner Emerging Market Quadrant for AI Application Security, Startup Vendors, published 16 September 2026.
What is the Gartner Emerging Market Quadrant?
The Emerging Market Quadrant is a Gartner research series covering new, fast-moving technology markets. Gartner evaluates startup vendors and established vendors in separate quadrants and places the vendors it assesses into four groups: Market Shapers, Pace Setters, Pioneers, and Specialists. Gartner describes the series on its Emerging Market Quadrant page: https://www.gartner.com/en/products/emerging-market-quadrant
What is AI application security?
AI application security protects the AI applications and agents an enterprise develops and runs. It combines discovery and inventory of AI assets, adversarial security testing, and runtime defense that detects and blocks threats such as prompt injection, data leakage, and rogue agent actions.
How does Pillar Security secure AI applications and agents?
Pillar discovers AI applications and agents across code, pipelines, cloud, SaaS, and endpoints; maps their permissions, tools, and data; continuously red-teams agentic workflows with RedGraph; and enforces runtime guardrails that alert on or block dangerous actions before they execute. The open-source SAIL framework helps organizations turn those controls into a governance program.
Where can I read the Gartner report?
Gartner clients can access Emerging Market Quadrant for AI Application Security — Startup Vendors (16 September 2026) through their Gartner subscription.
Subscribe and get the latest security updates
Back to blog
.webp)
%20(1).webp)
.webp)









