Blog

min read

Pillar Security Named an AI Security Technical Innovator in the Latio 2026 AI Security Market Report

By

Dor Sarig & Ziv Karliner

and

September 17, 2026

min read

Latio named Pillar Security an AI Security Technical Innovator in its 2026 AI Security Market Report, a badge reserved for vendors with a larger vision for AI security and the highest scores within an assessment area. The report places Pillar in the Broader AI Security category covering endpoints, SaaS, and first-party agents, and lists Pillar among the vendors buyers should evaluate for protecting agents across all three. That placement reflects how we built the platform: one system that secures AI agents, the endpoints they run on, the applications being used, and the ability to continuously test them.

Another signal in a strong year

The Latio badge lands on top of a run of independent recognition in 2026. Gartner named Pillar a 2026 Cool Vendor in AI Software Security in July, citing Red Graph's attack-graph modeling of live AI environments. CRN listed Pillar among its 10 Hottest AI Security Startups of 2026. OWASP's Agentic AI Security work covers Pillar in 8 of 9 categories. And our research team's disclosures this year, including the Week of Sandbox Escapes across Cursor, Codex, Gemini CLI, and Antigravity and a critical RCE in n8n, have been picked up across the security press and cited by the vendors we reported to.

Each of those recognitions looked at a different slice of the platform. Latio's evaluated the whole of it, and it confirms a single platform that handles AI security from the code an agent is built from to the workstation it runs on, so enterprises can adopt AI technologies and deploy agents quickly without assembling a patchwork of point tools.

Where Pillar appears in the report

Latio maps every vendor by outcome, and Pillar sits in Broader AI Security (Endpoints, SaaS, and First Party). The report defines that category as runtime monitoring across different types of agents, including endpoint agents, with an emphasis on securing AI across the entire environment rather than one slice of it.

In the Buyer's Guide, Pillar is listed under Protection for Agents across SaaS, Endpoints, and First Party for teams securing third-party agents, and under AI Vendors with Application Testing for teams securing first-party agents. Pillar also appears in the report's posture-and-testing and cloud-posture-for-AI-services groupings for homegrown agents.

In the Innovative Capabilities section, Pillar is highlighted in three areas: Employee App and Agent Builders, where Latio cites Pillar as an example of runtime protection for applications employees build with tools like Replit and Lovable; Skills Detonation, the practice of executing a skill in a controlled environment at runtime to watch for network egress and process execution that static analysis misses; and Granular Permissions, where identities are mapped from local endpoints to their cloud counterparts so teams can govern what agents reach, from local file systems to cloud IAM roles.

Latio's evolution timeline also places Pillar among the foundational AI security vendors operating in 2024 and earlier. We have been building for this market since before the endpoint became its center of gravity.

What the report says about where AI security is heading

The 2026 report documents a market that changed shape in twelve months. Latio describes two eras of AI security. The first was about controlling how employees accessed AI in the browser: shadow AI visibility, data loss prevention, prompt injection detection at the proxy. The second, which Latio says began in 2026, focuses on controlling what AI agents do at the endpoint. Pillar was built for both, which is why it appears in the report's browser and SaaS groupings and in its endpoint groupings alike.

The survey data backs that up. Buyer demand shifted from 8% to 37% of teams with a dedicated AI security budget within one year. Asked to name their primary AI security concern, 45% of respondents pointed to endpoint agents such as Claude Code and Codex, 23% to first-party agents built on frameworks like LangChain and Crew, 22% to browser applications, and 10% to hosted agents.

Latio's conclusion is blunt: last year endpoint agents were not a priority for vendors to build, "but this year a platform is incomplete without one." The report also notes that no single integration point wins on its own, since network proxies lack visibility into local permissions, endpoint agents struggle with SaaS and first-party applications, and hooks and gateways cannot alter device settings. Latio's guidance is that "the right approach combines all three," which is the approach Pillar has taken from the start.

One platform for agents and the endpoints they run on

The breadth Latio recognized is the design principle behind the Pillar platform. Agents do not live in one place. The same enterprise runs coding agents on developer laptops, Copilot and Agentforce inside SaaS platforms, homegrown agents in the cloud, and MCP servers connecting all of them. Securing one surface and ignoring the rest leaves the gaps attackers use.

Pillar covers those surfaces from a single platform. Discovery and posture management build an inventory of every agent, model, MCP server, skill, plugin, and configuration across the fleet, including the shadow agents developers and business users create outside security's view, and flag excessive permissions, sensitive data access, and missing human-in-the-loop gates.

On the agentic endpoint specifically, that means discovering every AI coding agent, MCP server, and plugin on employee workstations, then monitoring them at runtime through a lightweight sensor that intercepts agent actions.

The sensor catches the behaviors that matter on a developer laptop: an agent modifying its own configuration, a sensitive file being uploaded to a public service, or a dangerous command executed right after the agent read from an untrusted external source.

Detection is tied to the risk an intent drift creates, so the alert fires when an agent reads a secret and posts it to Pastebin, and stays quiet when it wanders harmlessly.

Red Graph Suite, our comprehensive agentic red-teaming engine, maps how tools, prompts, and data combine into exploitable attack paths in each environment and proves what an attacker can execute, with video, action logs, and transcripts. Those findings tune adaptive runtime guardrails calibrated to each agent's business purpose, with taint analysis that traces PII, credentials, and secrets from source to destination and blocks unauthorized egress in real time. MCP servers and skills discovered from code, endpoints, and gateways roll into a single risk map, with sandbox execution to observe what a skill actually does, and high-risk ones blocked at the endpoint, the corporate gateway, or the agent's admin console. Governance sits across all of it: approved model lists, MCP allowlists, and compliance reporting mapped to the OWASP LLM and Agentic Top 10s, MITRE ATLAS, NIST AI RMF, and the EU AI Act.

Latio names three outcomes the second era of AI security must deliver: runtime monitoring and intent-driven analysis, governance and supply chain malware prevention for skills and MCP servers, and user permission and guardrail enforcement as the agent operates. Those three outcomes map to what Pillar already ships for endpoints, SaaS agents, and first-party applications, with one inventory, one set of policies, and one view for the security team.

Thank you

This recognition belongs to the customers who trust Pillar to protect their most critical systems and who push us to cover the agents they will run next year alongside the ones they run today. It also belongs to our research and engineering teams, who spent 2026 disclosing sandbox escapes in Cursor, Codex, Gemini CLI, and Antigravity and a critical RCE in n8n, and then turning that research into an even better product. Threats that did not exist a year ago are now defended by default.

Read the report and see the platform

Read the full Latio 2026 AI Security Market Report for the market analysis, buyer's guide, and vendor mappings.

To see how Pillar secures agents across endpoints, SaaS, and first-party applications from one platform, get a demo or contact sales@pillar.security.

FAQs

What is the Latio 2026 AI Security Market Report?

The Latio 2026 AI Security Market Report is an independent analysis of the AI security vendor market based on hands-on product testing, practitioner surveys, and customer feedback. Latio is the only analyst firm that tests the products it evaluates. The 2026 edition covers the shift from browser-based AI controls to securing agents on endpoints, maps vendors by outcome and integration approach, provides a buyer's guide for first-party and third-party agents, and awards four badges: Platform Leader, Endpoint Leader, Technical Innovator, and Market Disruptor.

What does the AI Security Technical Innovator badge mean?

Latio awards the Technical Innovator badge to vendors that offered larger visions for AI security alongside the highest scores within a particular assessment area of the report. Recipients have differentiated capabilities for specific use cases that make them a strong fit for certain teams. Pillar Security received the badge in the 2026 report, alongside placement in the Broader AI Security category covering endpoints, SaaS, and first-party agents.

Why is Latio different from other analyst firms?

Latio evaluates products by using them. Where most analyst coverage relies on vendor briefings and slide decks, Latio runs hands-on testing, collects feedback from customers, and surveys practitioners on what they need. The report itself advises buyers to test vendors' runtime detection engines directly because "many runtime detection engines are not as powerful as promised." That posture is why security teams use Latio's reports to build shortlists.

How does Pillar secure AI agents on endpoints?

Pillar discovers every AI coding agent, MCP server, plugin, skill, and configuration across employee workstations, including unauthorized ones, then assesses permissions and risk for each. At runtime, a lightweight sensor intercepts agent actions and blocks the dangerous ones: self-modification of agent configuration, exfiltration of sensitive files, and command execution triggered by untrusted external content. It also enforces MCP allowlists and approved model lists and logs tool invocations across every session. Endpoint coverage is part of the same platform that secures SaaS agents, AI gateways, and homegrown applications, so teams get one inventory and one policy set.

What is the difference between securing first-party and third-party agents?

First-party agents are applications an organization builds itself, typically with frameworks like LangChain or Crew and hosted in the cloud, and are usually owned by product, application, or cloud security teams. Third-party agents are tools employees adopt, such as Claude Code, Codex, or Copilot, and are usually owned by IT and enterprise security. Latio's buyer's guide separates the two because the controls differ: application testing and runtime guardrails for first-party, endpoint governance and permission control for third-party. Pillar is listed for both.

Subscribe and get the latest security updates

Back to blog

MAYBE YOU WILL FIND THIS INTERSTING AS WELL

Best AI Red Teaming Providers for Enterprise AI Agents and GenAI Apps (2026): A Buyer's Comparison

By

Dor Sarig

and

September 16, 2026

Guides
The Audit Window: What the EU AI Act's Deferral Actually Bought You

By

Dor Sarig

and

September 9, 2026

Blog
Valid, But Never Issued: Session Spoofing and SSRF in Grafana MCP

By

Ariel Fogel

and

September 2, 2026

Research