Sweet Security launches AI blocking for rogue agents
Thu, 30th Jul 2026 (Today)
Sweet Security has launched Agentic AI Blocking, a feature designed to stop rogue AI agent behaviour in live production.
The launch expands the company's runtime enforcement product from cloud environments to AI agents, which can access data, use tools and act with a degree of autonomy inside businesses.
The new controls can terminate unauthorised tool calls and sessions at runtime, stop secrets, personally identifiable information and other sensitive data from leaving through an agent, and block prompt injection attempts before they alter an agent's actions.
Sweet is positioning the product around what it sees as a gap in current security tools, which often focus on detection and alerts rather than direct intervention once an AI agent begins to act. The argument reflects a wider debate in the cyber security market over whether monitoring systems are sufficient as businesses deploy more autonomous software.
According to Sweet, many companies are already operating as what it describes as AI enterprises, with agents taking on identities, accessing sensitive information and carrying out tasks on their own. The company argues that these systems need verification that their behaviour matches their creators' intent.
Runtime focus
At the centre of the launch is Sweet's emphasis on runtime analysis. Its reasoning layer reviews more than one billion runtime events each day to learn what applications and agents are intended to do, allowing it to decide when actions should be blocked without interrupting legitimate operations.
The approach is part of what Sweet calls its Learning Loop, a cycle of attacking, fixing and defending systems. The model is intended to enforce a simple rule for software and agents: do only what the creator intended.
The same platform enforces security across both cloud systems and AI agents. That single-platform approach is aimed at organisations trying to secure conventional applications and newer AI-driven workflows at the same time.
Industry analysts have increasingly argued that runtime inspection and enforcement are becoming necessary for AI agent security, particularly as autonomous systems are given broader access to internal tools and data. Sweet argues that the market is moving towards products that prevent risky behaviour automatically rather than adding more dashboards and alerts for security teams to review.
Founded in 2023, Sweet has raised USD $120 million from Evolution Equity Partners, Munich Re Ventures, Glilot Capital Partners and Key1 Capital. The company says it already deploys its enforcement technology at large scale in customer environments.
One example is Zoomd, where Sweet says its platform protects tens of thousands of cloud applications. It cited the customer as evidence that runtime blocking can operate in environments where disruption carries direct commercial consequences.
"AI has collapsed the cost of attack, and it has put autonomous software inside the enterprise. Someone has to decide, in the moment, what an agent is allowed to do," said Dror Kashti, Chief Executive Officer and Co-Founder of Sweet Security.
"When an agent reaches for data it shouldn't touch, Sweet stops the action red-handed and provides the team one line: here is what we found, and here is how we stopped it. Nothing bad happened, and nothing is waiting in a queue. That is what lets an enterprise adopt AI with confidence," Kashti said.
Zoomd also commented on the deployment.
"Sweet gave us the confidence to adopt AI across the business," said Niv Sharoni, Chief Technology Officer of Zoomd.
"With most tools, you find out about bad behavior in a report after the damage is done. With Sweet, it's blocked in runtime, the moment it happens. That's the difference between monitoring risk and actually removing it," Sharoni said.