[July 2026 Release] Real-time Guardrails for Claude Cowork, Kiro CLI, Human-in-the-Loop Overrides & More. Learn more->

[July 2026 Release] Real-time Guardrails for Claude Cowork, Kiro CLI, Human-in-the-Loop Overrides & More. Learn more->

[July 2026 Release] Real-time Guardrails for Claude Cowork, Kiro CLI, Human-in-the-Loop Overrides & More. Learn more->

Akto Named a Sample Vendor for AI Security Testing in the 2026 Gartner® Hype Cycle™ for AI Services

Akto is listed as a Sample Vendor for AI Security Testing in the 2026 Gartner® Hype Cycle™ for AI Services. Here’s what the report says about the AI testing gap, why security teams can’t wait for the market to mature, and how Akto helps to close the gap.

Krishanu

Krishanu

Akto Named Sample Vendor for AI Security Testing
Akto Named Sample Vendor for AI Security Testing

Gartner published the Hype Cycle for AI Services, 2026 on 30 July. Akto is listed as a Sample Vendor for AI Security Testing.

We are glad to be on the list. And the most important takeaway from the report?

Gartner's warning about the gap between AI adoption and AI testing, because that gap is where your next agent ships.

Where AI Security Testing (AI-ST) actually sits

AI Security Testing (AI-ST)

Gartner places AI Security Testing, or AI-ST, On the Rise: Emerging maturity, a Moderate benefit rating, 5% to 20% market penetration, and 5 to 10 years to mainstream adoption.

Gartner also finds that the enablement and governance layer, which it counts as AI literacy, AI observability, AI governance, AI TRiSM, and AI Security Testing (AI-ST), is falling behind the AI capabilities it exists to cover. That gap produces operational, financial, and regulatory risk.

So the testing layer is five to ten years from maturity, and the lag is already a risk. We agree with the diagnosis. The timeline is the part security teams cannot plan around, because the agents are already running. Teams are shipping copilots, internal agents, and MCP servers into production this quarter, not in 2033.

What AI Security Testing covers

The AI-ST profile, written by Jeremy D'Hoinne, Dionisio Zumerle, and Dennis Xu, covers finding vulnerabilities and exposures in AI-enabled systems and applications.

Gartner splits it into two halves: offensive work, meaning automated generation and execution of adversarial prompts, and scanning of AI components such as model repositories, libraries, frameworks, and notebooks. The analysts note AI-ST can run standalone or sit inside AI security and application security tooling.

How Gartner Defines AI-ST

Five drivers show up in the profile, and they will look familiar to anyone who has tried to sign off on an external-facing agent:

  • Frameworks such as the NIST AI Risk Management Framework are pushing organizations toward AI-specific testing practices rather than reused AppSec checks.

  • Stakeholders want evidence of resistance to attack and misuse before a chatbot or goal-driven agent is approved for external deployment.

  • GenAI applications carry risks that come from probabilistic input handling and output generation, so data leakage, prompt injection, and compromised outputs land harder than they do in deterministic software.

  • AI applications change too fast for manual testing cadence, so security teams want automation and frequent retests.

  • Models pulled from specialized repositories bring their own formats and metadata, where a configuration mistake or tampered metadata can change how the application behaves.

The six obstacles, and how Akto addresses them

Gartner lists six obstacles to adoption. Here is each one, and how Akto addresses it.

  1. Teams cannot see all their AI assets, especially locally downloaded models, which caps how far AI-ST can scale. This is the one that decides whether everything downstream works. Akto discovers AI agents, MCP servers, tools, and connected resources across cloud environments, employee endpoints, browsers, and internal infrastructure through 50+ connectors, and builds an AI Agent Context Graph across agents, tools, resources, permissions, prompts, and action paths. You cannot test an inventory you do not have.

  2. Responsibility for AI-ST is unclear because multiple teams are involved, some outside traditional app development, so AI applications reach preproduction untested. Our answer is to make testing a pipeline event rather than a team decision. Tests run against agents and LLM-connected workflows continuously, so nothing depends on someone remembering to file a security review.

  3. The nondeterministic nature of both AI applications and the attacks against them makes results hard to benchmark, and teams struggle to define a passing result. A single adversarial prompt that fails once proves very little. Repeated runs across a large probe library produce a signal you can reason about, which is why we maintain 4,000+ prebuilt and customizable test cases covering prompt injection, tool misuse, privilege escalation, data exfiltration, and unsafe multi-step behavior.

  4. Many AI-ST providers are startups without the visibility or track record to inspire confidence. Akto was founded in 2022 by Ankita Gupta and Ankush Jain, and was the first to ship MCP security in June 2025, when the protocol was about four months old. Over 1,000 AppSec teams use the platform, and we are backed by Accel. Judge the track record, not the funding announcement.

  5. Not all providers offer complete coverage. Many do offensive testing only, skip model testing, or support few modalities. This is the most important question in the report, and we're the only vendor with a truly holistic AI Agent Security platform. Akto runs discovery, automated red teaming, agentic posture management, agent identity, and runtime guardrails through two products: ATLAS for the employee AI layer, and ARGUS for internally built agentic systems, which intercepts MCP traffic inline and enforces what agents can access, invoke, and execute. Ask us where the edges are, and we will tell you.

  6. Testing is not a one-time activity, but AI-ST tools rarely handle retesting or result analysis well. Retesting is the whole point when the application under test changes weekly. Our tests are built to run again on every change rather than as a point-in-time assessment.

What to do before your next agent ships

Gartner's user recommendations for AI-ST are worth acting on regardless of which vendor you pick. Paraphrasing the ones we see teams skip most often:

  1. Run AI-ST inside a structured AI TRiSM program instead of as a standalone tool purchase.

  2. Fix the AI asset inventory first, including local and remote models and edge deployments, because the testing program depends on it.

  3. Write automated testing requirements into your CI/CD pipelines.

  4. Test for cybersecurity risks such as prompt injection and data leakage, and also for harmful or toxic behavior, and favor tools that support continuous testing and flexible retesting.

  5. Check whether deployment options, on-premises against privately hosted against SaaS, match your requirements before you get to procurement.

  6. Look at how any AI-ST tool feeds runtime guardrails, since testing that stops at a report leaves the runtime problem unsolved.

Follow us for more updates

Experience enterprise-grade Agentic Security solution