Model platform / coding agents2026 watchlist
OpenAI
OpenAI is shaping how enterprise teams think about coding agents, security workflows, and model-powered operations inside real software delivery environments.
What to verify
Review data handling options, workspace isolation, auditability, and whether agent permissions stay bounded when teams move from experiments to production.
Official siteModel platform / agentic coding2026 watchlist
Anthropic
Anthropic sits near the center of current debate around long-running agents, control boundaries, and what trustworthy model behavior should look like in higher-stakes environments.
What to verify
Look closely at permission models, session controls, logging, and how safely autonomous workflows degrade when tools or instructions go wrong.
Official siteEnterprise platform / identity / SOC2026 watchlist
Microsoft Security
Microsoft connects identity, endpoint, cloud, and Copilot-era controls in a way that strongly influences how enterprise AI security gets operationalized at scale.
What to verify
Focus on tenant separation, identity guardrails, plugin governance, and whether your detections keep up with new AI-assisted user and admin behaviors.
Official siteCloud security / threat intelligence / IR2026 watchlist
Google Cloud and Mandiant
Google Cloud and Mandiant continue to influence AI security thinking through cloud control-plane security, threat intelligence, and frontline incident response patterns.
What to verify
Check model-access logging, service account hygiene, and whether your cloud detections cover agent-to-agent and model-to-tool pathways.
Official siteAI SOC / endpoint / operations2026 watchlist
CrowdStrike
CrowdStrike is a useful signal for how AI gets blended into modern detection, triage, hunting, and response workflows without fully removing human judgment.
What to verify
Validate how enrichment, automated response, and analyst-facing AI features are governed, especially for high-impact actions.
Official siteNetwork / cloud / SOC platform2026 watchlist
Palo Alto Networks
Palo Alto influences enterprise architecture decisions across network, cloud, and SOC programs, so its AI-security positioning often becomes operational reality quickly.
What to verify
Look at policy consistency, platform integration depth, and whether AI-assisted actions preserve explainability for defenders under pressure.
Official siteCNAPP / cloud exposure / AI inventory2026 watchlist
Wiz
Wiz matters because AI projects usually expand the cloud attack surface first. Visibility into identities, workloads, and data paths often determines whether AI adoption stays controlled.
What to verify
Make sure AI infrastructure, model storage, secrets, and ephemeral compute all appear in the same exposure picture as the rest of your cloud estate.
Official siteCryptography / quantum readiness2026 watchlist
SandboxAQ
SandboxAQ is worth watching at the intersection of AI, cryptographic asset management, and post-quantum readiness, which is becoming more relevant for long-lived sensitive systems.
What to verify
Check whether cryptographic discovery ties back to concrete remediation workflows rather than just inventory, especially for hybrid and legacy environments.
Official siteDSPM / data security for AI2026 watchlist
Cyera
Cyera is a strong signal for where AI security meets data security, especially as teams realize the model is only as safe as the data paths it can touch.
What to verify
Review whether data classification, access controls, and AI-use governance are connected tightly enough to stop risky model exposure before runtime.
Official siteAI agent security / low-code governance2026 watchlist
Zenity
Zenity is one of the more direct bets on security and governance for AI agents themselves, which is exactly where more organizations will need visibility next.
What to verify
Look for lifecycle coverage across discovery, posture, detection, and response so agent security does not become another disconnected control plane.
Official siteAI guardrails / prompt injection defense2026 watchlist
Lakera / Check Point AI Security
Lakera is relevant because prompt injection, indirect injection, multilingual abuse, and runtime guardrails are moving from research topics into production AI application controls.
What to verify
Test false positives, latency, language coverage, tool-response screening, SIEM integration, and how enforcement works for multi-step agent workflows.
Official siteAI runtime security / model defense2026 watchlist
HiddenLayer
HiddenLayer is focused on AI discovery, AI supply-chain security, attack simulation, and runtime protection across generative and traditional AI systems.
What to verify
Confirm asset discovery depth, model and artifact coverage, replayable agent-session logs, response integrations, and support for your deployment patterns.
Official siteAI supply chain / model security2026 watchlist
Protect AI
Protect AI is worth tracking for model scanning, AI bill of materials ideas, ML pipeline security, and the security of AI artifacts before deployment.
What to verify
Verify model-source coverage, vulnerability prioritization, CI/CD integration, governance reporting, and whether findings map to remediable owners.
Official siteEnterprise AI governance / red teaming2026 watchlist
CalypsoAI
CalypsoAI sits in the governance and validation lane, useful for organizations that need structured testing and control evidence for AI adoption.
What to verify
Check policy customization, red-team methodology, model/provider coverage, reporting quality, and how controls integrate with existing GRC and security workflows.
Official siteAI security testing / adversarial evaluation2026 watchlist
Crucible
Crucible is relevant for teams trying to test agentic systems, eval environments, and AI applications before they become production risk.
What to verify
Look for reproducible test cases, scoped adversarial methods, secure handling of sensitive prompts, and evidence that maps to engineering fixes.
Official siteZero Trust / network / agent access2026 watchlist
Cisco
Cisco is important where AI security intersects with network enforcement, identity-aware access, and enterprise control planes that already sit in many environments.
What to verify
Validate agent identity patterns, policy enforcement consistency, telemetry portability, and how AI features affect existing network and access assumptions.
Official siteIdentity security / non-human identity2026 watchlist
Okta
AI agents turn identity into the first control plane. Okta is worth watching for how human, service, application, and agent identities are governed together.
What to verify
Check lifecycle governance for non-human identities, step-up controls, OAuth visibility, token hygiene, and incident recovery workflows.
Official site