MSSP, MSP, AI/ML, AI benefits/risks, Application security, API security, Data Security, Identity

WitnessAI Extends Its LLM Protections to AI Agents

Close-up of Hands Typing on Keyboard with AI Graphics and Symbols Representing Technology, Innovation, and Digital Communication

A push is on in the cybersecurity industry to address the inherent risks that come with autonomous AI agents, which operate with little if any human intervention as they make decisions and access data from external sources, creating what WitnessAI executives call a “Manchurian candidate” scenario if a bad actor compromises an agent.

A key problem is that, while companies and MSSPs understand the new risks that come with AI in general – and AI agents in particular – they can underestimate the extent of the risks, from the velocity to the variety, Dan Graves, chief product officer at WitnessAI, told MSSP Alert.

“The challenge isn't awareness,” Graves said. “It's that legacy security tools were built for predictable traffic patterns, not conversational AI operating across thousands of applications with constantly changing context.”

Agentic AI only adds to the complexity and the security concerns.

“Agents fundamentally change the security equation because they execute immediately with every permission their identity possesses, without the judgment that constrains human behavior,” he said. “When you combine agentic execution with MCP [Model Context Protocol] servers connecting to internal systems, external APIs, and third-party tools, you've created pathways for prompt injection to cascade through your infrastructure before anyone intervenes.”

Graves added that “traditional security tools are architecturally blind to agents invoking tool calls.”

New Agent Security Functions

The Mountain View, California, startup this week is extending the capabilities of its platform, which already lets security teams protect AI applications, uncover shadow AI, and ensure the safe use of AI, to AI agents.

The move coincides with the company securing $58 million in strategic funding, led by Sound Ventures – which was an early investor in cybersecurity vendor SentinelOne and AI companies OpenAI and Anthropic – with participation from Fin Capital, Qualcomm Ventures, Samsung Ventures, and Forgepoint Capital Partners.

With WitnessAI Agentic Security, the vendor does this in two ways. Similar to how the platform tracks large language model (LLM) activity, the new capabilities monitor which agents are active, the MCP servers and tools they’re accessing, and the data they’re sharing. It can view what the agent is doing for an employee or customers, connect human and agent identities, and can explain an agent’s actions by capturing its decision-making context at runtime, including the agent’s state and execution commands.

“WitnessAI automatically discovers agentic activity across the highest-risk vectors in enterprise environments: Claude Desktop and Claude plugins, VSCode with AI extensions, ChatGPT with enabled plugins, and local agents running on developer machines (including LangChain, LlamaIndex, CrewAI, AutoGPT, and custom implementations),” the company wrote in a blog post.

Distinguishing Agentic AI Activity

The platform can also distinguish standard chat sessions from those of agents.

“When a client requests access to external MCP servers, the platform classifies the session as agentic,” they wrote. “This classification lets security teams permit approved AI interactions while still keeping visibility into connections to unverified tools.”

The new capabilities, which will be available this month, also extend the platform’s tools for protecting AI models to agents, including blocking attacks and malicious prompts before they reach an agent. Its policy control relies on behavioral intent to understand the meaning of any prompt.

From Experimental to Operational

WitnessAI’s new agentic AI security functions come as organizations begin to turn their attention to the emerging technology. According to a survey released by McKinsey and Co. in November 2025, there is a “high curiosity in AI agents,” with 62% of respondents saying their companies are at least experimenting with them.

“Twenty-three percent of respondents report their organizations are scaling an agentic AI system somewhere in their enterprises (that is, expanding the deployment and adoption of the technology within a least one business function), and an additional 39 percent say they have begun experimenting with AI agents,” the global consultancy wrote. “But use of agents is not yet widespread: Most of those who are scaling agents say they’re only doing so in one or two functions.”

That will change quickly, WitnessAI’s Graves said.

“By January 2027, agents won't be experimental,” he said. “They'll be operational infrastructure where agents handle routine tasks, and humans focus on strategic decisions. The security challenge scales with adoption. Today we're securing hundreds of agent sessions; next year we'll be securing millions, with increasingly sophisticated attacks designed specifically to exploit agentic workflows.”

MSSPs' Opportunity

Given that, the rush to security agents is on. Exabeam, this month, unveiled its connected system for AI agent behavioral analytics and insights into a company’s AI security posture. Other vendors, from CrowdStrike and Hack The Box to Skyhawk Security, Netskope, and TrojAI, are adding agentic AI into their AI security offerings for both companies and MSSPs.

“MSSPs and MSPs have an enormous opportunity as their clients deploy AI faster than internal security teams can adapt,” Graves said. “WitnessAI provides AI agent observability and AI model and agent security guardrails that can be delivered and managed by MSSPs and MSPs on behalf of their customers, as an extension of their security services. AI security has become a critical service offering in any MSSP's capability set.”

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.
Jeffrey Burt

Jeffrey Burt has been a journalist for almost 40 years, moving from general-circulation newspapers to IT news sites in 2000. He’s an expert analyst and writer on cybersecurity, data center infrastructure, AI, and a host of other subjects for a range of organizations, including CyberRisk Alliance, eWEEK, Techstrong Group, The Next Platform, and The Register.

You can skip this ad in 5 seconds