AI security is changing quickly.
The first phase of the market focused heavily on browser-based AI usage, visibility, and data protection. But as AI agents move into developer environments, employee endpoints, SaaS applications, and first-party systems, the security problem is becoming much broader.
Latio’s 2026 AI Security Market Report captures that shift. The report describes a market moving from controlling AI usage in the browser toward securing agents that can act across endpoints, applications, cloud infrastructure, and enterprise systems.
Akto’s placement across the report reflects the same evolution.
Rather than appearing in only one narrow category, Akto is represented across application testing, application-layer runtime protection, and protection for agents across SaaS, endpoints, and first-party environments. Latio ultimately places Akto in its Broader AI Security category.

That breadth reflects how we think AI security should be built. We believe looking at application security, workforce AI, agent security, runtime protection, agent identity, and testing in isolation creates blind spots between them. Akto’s vision is to bring these layers together in one platform, so security teams can protect the AI they build and the AI their employees use with shared visibility, controls, and context.
Akto was building in AI security before the 2026 endpoint wave
Latio’s market evolution timeline places Akto in Foundations: AI Security, 2024 and Earlier, before the report’s 2026 wave of endpoint-focused AI security vendors.
Akto started with the proxy and API layer. At the time, APIs were a natural control point for discovering AI traffic, testing AI applications, and applying security controls to model interactions.
The architecture has since expanded.
AI now runs in homegrown applications, SaaS products, coding agents, employee endpoints, MCP servers, skills, plugins, and cloud environments. An agent can move across several of these in one session.
Akto expanded with that architecture.
Latio’s Mapping by Starting Technological Approach places Akto under Network Proxy and API Approaches, while noting that the map reflects where vendors started, not the full scope of where they operate today.
Akto now extends beyond its original proxy and API approach with support for agent hooks and endpoint-based coverage, giving security teams multiple control points across the AI stack.
One platform for first-party and third-party AI
The clearest view of Akto’s coverage comes from Latio’s separate guides for first-party and third-party agents.
In the Guide to Securing First-Party Agents, Akto appears among AI Vendors with Application Testing and Application Layer Runtime Protection.
In the Guide to Securing Third-Party Agents, Akto appears under Protection for Agents across SaaS, Endpoints, and First Party.
Together, those placements reflect the two sides of enterprise AI adoption: the AI organizations build, and the AI employees use.
Securing first-party and homegrown AI
First-party AI includes the applications and agents an organization builds itself. These systems can connect to internal APIs, enterprise data, cloud services, tools, and identities.

They need security before and after deployment.
Akto helps teams discover AI applications and their attack surface, test them for vulnerabilities and unsafe behavior, and enforce controls once they are running. Security teams can test for issues such as prompt injection and unintended agent behavior, then apply runtime guardrails to prompts, responses, tool calls, and agent actions.
Runtime traces add the context needed after a policy fires: the instructions involved, tools called, models used, requests made, results returned, and the policy that was triggered.
For homegrown AI, the security lifecycle becomes:
Discover → Test → Protect → Investigate
Latio’s application testing placement captures one part of that lifecycle. Its Application Layer Runtime Protection map captures another, and Akto appears there as well.
Securing third-party agents
Third-party AI creates a different operational problem.

Security teams do not build these agents, but employees can give them access to local files, repositories, SaaS applications, credentials, MCP servers, skills, plugins, and internal systems.
A coding agent on an employee laptop can have a very different blast radius from a browser-based AI chat. The security team needs to know which agents are being used, where they run, what extends them, what they can access, and what they do during a session.
Latio places Akto under Protection for Agents across SaaS, Endpoints, and First Party in its third-party agent guide.
Akto Atlas provides discovery and visibility across workforce AI usage, including agents, MCP servers, skills, plugins, models, and the environments where they run. Runtime controls and traces add enforcement and investigation once those agents begin taking actions.
This gives security teams coverage for AI they did not build, without treating endpoint agents as an isolated problem.
Why first-party and third-party AI cannot stay separate
The boundary between the two is already blurry.
A homegrown agent may call a third-party model. An employee coding agent may interact with an internally built API. The same MCP server can be used from a developer endpoint and a production AI application. Both first-party and third-party agents may rely on the same enterprise identity or reach the same sensitive data.
Consider one coding-agent session.
An employee sends a prompt. The agent loads a skill, invokes an MCP server, accesses a repository, reads credentials from the environment, calls an internal API, and sends a result to another service.
A gateway can see the model request. An endpoint product can see local activity. An application security product can see the internal application. A DLP product can detect sensitive data.
The security team still needs to connect those events into one execution path.
That is why Akto combines discovery, testing, runtime enforcement, and traces rather than treating each as a separate AI security program.
Broader AI Security is the category Akto has been building toward
For us, Broader AI Security is not about adding more point features. It is about closing the gaps between them. A prompt can move through an agent, a skill, an MCP server, an API, an identity, and an external action in one session. If each layer is secured separately, security teams are left stitching together partial views of the same event.
Akto is building one platform across those layers so discovery, testing, runtime enforcement, and investigation share the same context.
Akto’s goal is to cover the full AI security lifecycle in one platform, across first-party and third-party AI. We believe this reduces the blind spots created when each part of AI security is handled in isolation.
Experience enterprise-grade Agentic Security solution


