{"id":65168,"date":"2026-07-29T10:40:34","date_gmt":"2026-07-29T14:40:34","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=65168"},"modified":"2026-07-29T10:40:34","modified_gmt":"2026-07-29T14:40:34","slug":"sweet-security-agentic-ai-blocking","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/sweet-security-agentic-ai-blocking\/","title":{"rendered":"Sweet Security Brings Autonomous Protection with Agentic AI Blocking"},"content":{"rendered":"<p>LAS VEGAS \u2014 July 29, 2026 \u2014 <a href=\"https:\/\/www.sweet.security\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Sweet Security<\/a> today announced <a href=\"https:\/\/overcentral.com\/en\/agentic-ai-ransomware-langflow\/\" title=\"Agentic AI Executes Ransomware Attack via Langflow Vulnerability\" data-iacss-internal=\"1\">Agentic AI<\/a> Blocking, a proactive runtime enforcement capability that stops rogue <a href=\"https:\/\/overcentral.com\/en\/mit-ai-agents-build-virtual-worlds-to-train-robots\/\" title=\"MIT AI Agents Build Virtual Worlds to Train Robots\" data-iacss-internal=\"1\">AI agents<\/a> in live production before they can execute unauthorized actions. As enterprises race to deploy autonomous agents that interact with sensitive data and systems, the security industry has largely relied on detection and alerts \u2014 a model that leaves organizations reacting after damage has already occurred. Sweet Security\u2019s new capability flips that paradigm, blocking malicious or misaligned agent behavior in real time using a continuous learning loop that understands what each agent is intended to do. With eighty percent of the world\u2019s businesses already operating as AI enterprises, the need for runtime enforcement rather than post-incident notification has become acute.<\/p>\n<h2>The New Frontier of AI Security: Runtime Blocking for Rogue Agents<\/h2>\n<p>AI agents have fundamentally changed the enterprise attack surface. These autonomous software entities take on identities, reach sensitive data, and act on their own. They operate at machine speed, making and executing decisions in milliseconds. Yet the security tools designed to protect them have remained stuck in a detection-and-alert paradigm: they observe suspicious behavior, generate an alert, and wait for a human team to respond. By the time the team reads the alert, the agent has already acted \u2014 potentially exfiltrating secrets, modifying critical data, or executing unauthorized tool calls.<\/p>\n<p>Sweet Security\u2019s Agentic AI Blocking addresses this gap head-on. Instead of detecting and alerting, it intercepts and terminates rogue behavior at runtime, before any damage occurs. The company\u2019s CEO and co-founder, Dror Kashti, framed the challenge succinctly: \u201cAI has collapsed the cost of attack, and it has put autonomous software inside the enterprise. Someone has to decide, in the moment, what an agent is allowed to do.\u201d<\/p>\n<h2>How Agentic AI Blocking Works at Runtime<\/h2>\n<h3>What is Agentic AI Blocking?<\/h3>\n<p>Agentic AI Blocking is a runtime enforcement technology that stops AI agents from performing unauthorized actions in real time. It terminates tool calls, sessions, and data flows that deviate from intended behavior, blocks the exfiltration of secrets or personally identifiable information, and prevents prompt injections from steering agents off course \u2014 all before any harm occurs. The system relies on continuous self-learning rather than static rules.<\/p>\n<p>The core engine behind this capability is the Sweet Learning Loop, which continuously Attacks, Fixes, and Defends. Sweet\u2019s runtime reasoning layer analyzes over one billion runtime events every day, learning what every application and agent is intended to do. This deep contextual understanding allows Sweet to set a simple but powerful bar: \u201cdo exactly what your creator intended and nothing more.\u201d Because the system knows the expected behavior, it can enforce decisively without breaking live production or generating false positives that would erode trust.<\/p>\n<p>This approach stands in sharp contrast to traditional security models that rely on predefined signatures or behavioral baselines that take weeks to tune. Sweet\u2019s automated learning adapts as agents evolve, ensuring that protection remains current without manual intervention.<\/p>\n<h2>Key Capabilities: Stopping Unauthorized Actions, Data Leakage, and Prompt Injections<\/h2>\n<p>Agentic AI Blocking delivers three specific enforcement capabilities at runtime:<\/p>\n<ul>\n<li><strong>Terminates unauthorized tool calls and sessions<\/strong> \u2013 When an agent attempts to invoke a tool, API, or system function that falls outside its designated scope, Sweet blocks the call instantly. The session is terminated without allowing any data to pass.<\/li>\n<li><strong>Stops secrets, PII, and sensitive data from leaving through an agent<\/strong> \u2013 Agents often have access to credentials, customer information, or intellectual property. Sweet inspects outbound data flows and prevents exfiltration, even if the agent\u2019s actions appear legitimate on the surface.<\/li>\n<li><strong>Blocks prompt injections live<\/strong> \u2013 Prompt injection attacks attempt to trick an agent into ignoring its instructions and executing malicious commands. Sweet identifies these attacks as they happen and blocks them before the agent deviates from its intended behavior.<\/li>\n<\/ul>\n<p>Each of these capabilities operates autonomously, requiring no human decision-making at the moment of enforcement. The security team receives a concise report: here is what we found, and here is how we stopped it. Nothing bad happened, and nothing is waiting in a queue.<\/p>\n<h2>The Sweet Learning Loop: Continuous Self-Improvement Through Runtime Reasoning<\/h2>\n<p>The intelligence behind Agentic AI Blocking comes from Sweet\u2019s proprietary runtime reasoning layer and the Sweet Learning Loop. This loop operates in three phases: Attack, Fix, and Defend. In the Attack phase, the system continuously probes for vulnerabilities and deviations in agent behavior. The Fix phase automatically adjusts the enforcement policies based on what was learned. The Defend phase applies those policies in real time, blocking any actions that violate the intended behavior.<\/p>\n<p>This self-improving cycle is critical because AI agents are not static. Their behavior changes as they interact with new data, tools, and environments. A rule-based system that blocks a specific API call today may miss a new attack vector tomorrow. Sweet\u2019s runtime reasoning layer, which ingests over one billion runtime events daily, allows the system to detect subtle shifts in agent behavior that indicate a compromise or misuse.<\/p>\n<p>The bar Sweet uses \u2014 \u201cdo exactly what your creator intended and nothing more\u201d \u2014 is deliberately simple. It does not require complex policy documents or manual whitelisting. Instead, it relies on the system\u2019s ability to learn the baseline from observing normal agent operations. This makes it scalable across thousands of agents and tens of thousands of applications, as evidenced by Sweet\u2019s deployment at companies like Zoomd.<\/p>\n<h2>Market Convergence: Analysts and Enterprises Demand Proactive Enforcement<\/h2>\n<p>The market is converging on the same conclusion that Sweet Security has been advocating. Leading industry analysts now describe runtime inspection and enforcement as a mandatory capability for securing AI agents. They expect the winners in agent security to be products that automatically prevent risky agent behavior rather than surfacing more dashboards and alerts that security teams cannot keep up with.<\/p>\n<p>Sweet goes further by enforcing across both cloud and AI in a single platform. This unified approach is significant because AI agents do not operate in isolation; they interact with cloud infrastructure, databases, and third-party services. A security tool that protects agents but ignores the underlying cloud environment leaves critical gaps. Sweet\u2019s platform covers both, providing consistent enforcement from the runtime of the agent to the runtime of the cloud applications it accesses.<\/p>\n<p>The company\u2019s funding and backing \u2014 $120 million from Evolution Equity Partners, Munich Re Ventures, Glilot Capital Partners, and Key1 Capital \u2014 reflects investor confidence in this proactive approach. Founded in 2023 by veterans of the IDF\u2019s most elite cyber units, Sweet Security is built on a thesis that the security industry\u2019s reliance on detection is not just insufficient but dangerous in the age of autonomous AI.<\/p>\n<h2>Customer Proof Point: Zoomd Blocks Risk at Scale<\/h2>\n<p>Sweet already enforces protection at extreme scale, including at Zoomd, where the platform protects tens of thousands of cloud applications in an environment where disruption is measured in market impact. Niv Sharoni, CTO at Zoomd, described the difference Agentic AI Blocking makes: \u201cWith most tools, you find out about bad behavior in a report after the damage is done. With Sweet, it\u2019s blocked in runtime, the moment it happens. That\u2019s the difference between monitoring risk and actually removing it.\u201d<\/p>\n<p>Zoomd\u2019s experience underscores a critical point: in high-velocity environments, traditional alerting creates a backlog that security teams cannot clear. Automated blocking removes the need for triage, freeing professionals to focus on strategic threats rather than reviewing logs of already-compromised systems.<\/p>\n<h2>Demonstration and Availability at Black Hat USA 2026<\/h2>\n<p>Sweet Security will demonstrate Agentic AI Blocking live at Black Hat USA 2026, Booth 5721. Attendees can see how the system stops rogue agents in real time, from unauthorized tool calls to prompt injection attacks. The demonstration will highlight the Sweet Learning Loop in action, showing how the system adapts to new agent behaviors without manual configuration. More information is available at hi.sweet.security\/black-hat-2026.<\/p>\n<h2>About Sweet Security<\/h2>\n<p>Sweet Security delivers proactive runtime enforcement for cloud and AI. While the rest of the industry detects and alerts, Sweet blocks bad behavior before anything bad happens, where intent turns into action: in runtime. Through the Sweet Learning Loop, organizations continuously Attack, Fix, and Defend, driving every application and <a href=\"https:\/\/overcentral.com\/en\/openai-ai-agent-escapes-sandbox-hacks-hugging-face\/\" title=\"OpenAI AI agent escapes sandbox and hacks Hugging Face platform\" data-iacss-internal=\"1\">AI agent<\/a> toward maximal immunity. Founded in 2023 by veterans of the IDF\u2019s most elite cyber units and backed by $120 million from Evolution Equity Partners, Munich Re Ventures, Glilot Capital Partners, and Key1 Capital, Sweet protects the world\u2019s most demanding enterprises. Learn more at www.sweet.security.<\/p>\n<p>The arrival of Agentic AI Blocking marks a fundamental shift in how enterprises can approach AI security. Instead of hoping that detection tools will catch a rogue agent before it causes irreversible damage, organizations can now deploy autonomous protection that acts in the moment. As AI agents become more autonomous, more connected, and more capable, the ability to enforce intended behavior at runtime will separate companies that adopt AI with confidence from those that are forced to operate in constant fear of the next breach. Sweet Security\u2019s technology puts that confidence within reach \u2014 not through more alerts, but through decisive, automated enforcement.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>LAS VEGAS \u2014 July 29, 2026 \u2014 Sweet Security today announced Agentic AI Blocking, a proactive runtime enforcement capability that stops rogue AI agents in live production before they can execute unauthorized actions. As enterprises race to deploy autonomous agents that interact with sensitive data and systems, the security industry has largely relied on detection [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":84043,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/65168.png","fifu_image_alt":"Sweet Security Brings Autonomous Protection with Agentic AI Blocking","footnotes":""},"categories":[349],"tags":[],"class_list":["post-65168","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/65168.png","fifu_image_alt":"Sweet Security Brings Autonomous Protection with Agentic AI Blocking","fifu_redirection_url":"https:\/\/www.linkedin.com\/pulse\/agentic-ai-security-how-protect-autonomous-systems-from-ashish-kots-2ioic","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/65168","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=65168"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/65168\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/84043"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=65168"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=65168"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=65168"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}