Gartner published the Hype Cycle for AI Services, 2026 on 30 July. Akto is listed as a Sample Vendor for AI Security Testing, alongside Adversa AI, Check Point Software, Enkrypt AI, F5, HiddenLayer, Mindgard, Palo Alto Networks, Pillar Security, and SentinelOne.
We are glad to be on the list. And the most important takeaway from the report?
Gartner's warning about the gap between AI adoption and AI testing, because that gap is where your next agent ships.
Where AI Runtime Defense actually sits

Gartner places AI Runtime Defense at the Peak of Inflated Expectations: Emerging maturity, a High benefit rating, 5% to 20% market penetration, and 2 to 5 years to mainstream adoption.
Two of the report's strategic planning assumptions explain the climb. Gartner expects that by 2028, loss of control, meaning agents pursuing misaligned goals or acting outside their constraints, will be the top concern for 40% of Fortune 1000 organizations. And by 2029, enterprises implementing AI governance will outperform ungoverned competitors in AI adoption by 25%.
So expectations are running ahead of what deployed products can currently do, and the deadline is two to five years out. We agree with the diagnosis. Sitting at the peak is not a compliment, and pretending the category is finished helps nobody, because the obstacles Gartner lists are the same ones our customers raise in evaluations.
What AI Runtime Defense covers
The AI Runtime Defense profile, written by Jeremy D'Hoinne, Avivah Litan, and Dionisio Zumerle, covers intent-based policy enforcement and anomaly detection for AI applications and models.
In practice, that means inspecting content for AI application abuse and attacks such as prompt injection, and detecting intent or content anomalies such as toxicity and hallucination. The analysts note these tools are evolving to protect AI agents, and that runtime defense is frequently offered as part of an AI application security suite that also includes AI security testing.
Gartner lists six drivers behind the adoption of AI runtime defense:

Cybersecurity teams now understand the impact and requirements of AI runtime defense, and application teams are collaborating to integrate controls as projects approach production.
As enterprise agent projects proliferate, runtime defense is more often a mandatory requirement rather than an optional control.
AI applications need monitoring to stay compliant, avoid abuse, and prevent malicious activity.
Runtime defense increasingly integrates with AI security testing from the same provider, which improves efficacy because controls are tuned on adversarial results.
Chatbots turning into agents adds automation, which raises the stakes and brings demands for low latency and even lower false positive rates.
The EU AI Act, several US laws, insurance requirements, and existing enterprise policy are pushing preventative controls and monitoring onto high-risk AI systems.
The obstacles, and how Akto addresses them
Gartner lists the following obstacles to adoption. Here is each one, and how Akto addresses it.
AI runtime defense has not expanded enough to handle AI agents, especially autonomous ones. Low latency, low tolerance for false positives, and new attack vectors require control and behavior baselining algorithms that are not available yet. This is the central gap in the category, and the reason we built ARGUS around agent behavior rather than around prompts. Akto builds an AI Agent Context Graph across agents, tools, resources, permissions, prompts, and action paths, then enforces on what an agent can access, invoke, and execute. A prompt filter cannot see a privilege escalation that unfolds across four tool calls.
Real-time security alerts on text-based inputs are noisy and prone to false positives, and lessons from SQL injection and XSS detection indicate that reaching good-enough accuracy will take time. The comparison is fair, and those took years to tune. Our position is that runtime accuracy comes from adversarial testing rather than from a better classifier alone, which is why we run 4,000+ prebuilt and customizable test cases against your agents and feed the results into runtime enforcement.
Deployment form factor influences what the controls can see. Deployed in front of the application, they see only user inputs and application outputs, and multimodal applications may need multiple entry points. Front-door inspection misses the part of agentic systems where the damage happens. Akto intercepts MCP traffic inline, so enforcement applies at the tool and resource layer rather than only at the chat window.
Organizations may have privacy concerns about inspecting application input and output, especially when it means sharing sensitive content with the provider's SaaS platform. A reasonable objection, and one that should be settled before the technical evaluation rather than after. Akto deploys on-premises, in your cloud, or as a hybrid, so prompts and model outputs can stay inside your own environment.
Many providers are small and growing, and the effectiveness of their product remains unproven. Akto was founded in 2022 by Ankita Gupta and Ankush Jain, started in open-source API security, and shipped MCP security in June 2025 when the protocol was about four months old. Over 1,000 AppSec teams use the platform, and we are backed by Accel.
A growing number of providers are being acquired, and their integration into broader ecosystems and product portfolios is still lagging. Worth weighing during procurement. Roadmap control is what you lose when your runtime vendor becomes a line item inside a larger platform, and in a category moving this fast, a stalled roadmap is a security gap.
New AI control tools are difficult to integrate with existing security and monitoring systems, and often require new playbooks and triage capabilities, especially for nonsecurity events such as legal, compliance, and acceptable use. We connect through 50+ connectors across agent builders, AI gateways, and cloud platforms, and cover both layers where these events originate: ATLAS for the employee AI layer, and ARGUS for internally built agentic systems. Acceptable-use and compliance events land in the same place as security events rather than in a separate queue nobody owns.
What to do before your next agent ships
Gartner's user recommendations for AI runtime defense are worth acting on regardless of which vendor you pick. Paraphrasing the ones we see teams skip most often:
Ground your risk understanding in AI TRiSM research and industry frameworks such as the OWASP Top 10s for Large Language Model and Agentic Applications.
Get the cybersecurity team AI-ready through literacy initiatives and proper resourcing, because underinformed teams write weak requirements.
Mandate integration with AI security testing to evaluate the benefits of runtime defense before any AI application or agent deploys.
Request benchmarks, test data, and test results from every provider, then estimate false positive and false negative rates yourself.
Build checklists and test plans that keep evaluating whether the controls catch new attacks.
Scrutinize real differentiators, such as access to system prompts and raw model outputs, and whether a provider can serve multiple AI security use cases rather than input and output monitoring alone.
Experience enterprise-grade Agentic Security solution


