Sweet Security Launches Agentic AI Blocking to Prevent Rogue AI Behavior in Real-Time
Sweet Security introduces Agentic AI Blocking, a new capability designed to autonomously stop unauthorized actions by AI agents in live production environments before damage occurs.

Sweet Security, a company focused on runtime enforcement for cloud and AI, has announced a significant expansion of its AI security offerings with the introduction of Agentic AI Blocking. This new capability aims to provide real-time protection against rogue AI agent behavior, extending Sweet Security's existing runtime enforcement from cloud infrastructure directly to the AI agents operating within enterprise environments.
The proliferation of AI in businesses, with an estimated eighty percent of global companies already adopting AI, has led to the deployment of autonomous agents that possess identities, access sensitive data, and operate independently. However, a critical gap exists in verifying that these agents perform only intended actions. Traditional security tools often operate on a detect-and-alert model, meaning that by the time a human team reviews an alert, the rogue agent may have already completed its harmful actions.
"AI has collapsed the cost of attack, and it has put autonomous software inside the enterprise. Someone has to decide, in the moment, what an agent is allowed to do," stated Dror Kashti, CEO and co-founder of Sweet Security. "When an agent reaches for data it shouldn’t touch, Sweet stops the action red-handed and provides the team one line: here is what we found, and here is how we stopped it. Nothing bad happened, and nothing is waiting in a queue. That is what lets an enterprise adopt AI with confidence."
Agentic AI Blocking introduces several key features designed to prevent malicious or unintended actions by AI agents. These include the termination of unauthorized tool calls and sessions at runtime, the prevention of sensitive data, personally identifiable information (PII), and secrets from being exfiltrated by an agent, and the live blocking of prompt injections that could steer an agent off course.
The effectiveness of Sweet Security's solution is powered by its "Sweet Learning Loop," which continuously attacks, fixes, and defends. This process leverages a runtime reasoning layer that analyzes over a billion runtime events daily to establish a baseline of intended behavior for each application and agent. By holding agents to the standard of "do exactly what your creator intended and nothing more," Sweet Security can enforce security policies decisively without disrupting live production environments.
Industry analysts increasingly recognize runtime inspection and enforcement as essential for securing AI agents, predicting that successful products will focus on automatically preventing risky behavior rather than generating more alerts. Sweet Security's platform uniquely enforces protection across both cloud and AI workloads within a single, unified system. The company highlights its deployment at Zoomd, where the platform protects tens of thousands of cloud applications, demonstrating its ability to operate at scale in environments where disruptions have significant market impact.
Niv Sharoni, CTO at Zoomd, commented on the impact of Sweet Security's solution: "Sweet gave us the confidence to adopt AI across the business. With most tools, you find out about bad behavior in a report after the damage is done. With Sweet, it's blocked in runtime, the moment it happens. That's the difference between monitoring risk and actually removing it."
Sweet Security plans to demonstrate its autonomous protection capabilities live at Black Hat USA 2026, in Booth 5721. The company, founded in 2023 by veterans of elite IDF cyber units, has secured $120 million in funding and aims to provide proactive runtime enforcement for the growing AI enterprise landscape.