Acalvio Technologies has introduced Deception Guardrails, a new preemptive defense mechanism tailored to enhance the security of AI agents.
This innovation fills a critical gap in securing AI systems, which often face limited oversight once compromised. Traditional security measures primarily focus on monitoring inputs and outputs, whereas Deception Guardrails incorporate proactive tripwires to detect and disrupt malicious activities before they impact enterprise systems.
Adopting Agentic AI Systems
Enterprises are increasingly adopting agentic AI systems that utilize tools and APIs for autonomous decision-making, significantly altering the security landscape. Recent breaches involving AI agents have demonstrated how attackers can circumvent traditional defenses, exploiting credentials and tools in unexpected ways. Current guardrails tend to only manage inputs and outputs, leaving security personnel unable to detect compromised agents effectively.
CEO Ram Varadarajan highlighted the shift from reactive to preemptive approaches with their new technology. According to Varadarajan, "Reactive guardrails are designed to keep well-behaved AI systems on the road, but they do nothing to stop a hijacked agent driven by a malicious actor. With our patent-pending Deception Guardrails, we are moving the industry from reactive filtering to preemptive defense." This system aims to quickly identify rogue AI behavior and feed attackers false data, thereby preventing real assets from being compromised.
Perfecting Deception Technologies
The need for enhanced AI security was emphasized by a recent incident involving Hugging Face
The need for enhanced AI security was emphasized by a recent incident involving Hugging Face, where cyber experts recommended using deception tactics to impede attackers.
Deploying deceptive elements like fake identities and honey clusters can mislead attackers and generate actionable alarms. Lawrence Pingree, Head of Research at Software Analyst Cyber Research, stated that extending deception technologies to AI is a logical progression, offering a new detection layer that complements current AI security measures.
Detecting Compromised Agents
Beyond detecting compromised agents, Deception Guardrails provide early warnings, allowing security teams to address potential threats before they escalate. The addition of Deception Guardrails extends Acalvio’s ShadowPlex platform with comprehensive enterprise deception, including both on-premises and cloud environments. Key features include:
- Full-Spectrum Enterprise Coverage: Deploys honeytokens and decoys across various environments, detecting unauthorized AI movements quickly.
- Agentic Deception: Introduces honeytokens in AI operational context, raising alerts when a compromised agent attempts access.
- Decoy AI Infrastructure: Includes decoy systems and agents to create a misleading ecosystem, thwarting malicious attempts.
- Real-time Misalignment Detection: Monitors interactions to neutralize threats in real-time, addressing manipulations and jailbreaks effectively.
Enterprise-Scale Deployment
As organizations transition from AI trials to full-scale implementation, Deception Guardrails ensure they can manage associated risks without hindering innovation. Interested parties can learn more about these advancements by visiting the Acalvio booth at Black Hat USA, at Booth #8606, AI Zone, where live demonstrations will showcase the system's effectiveness against AI threats.
Acalvio Technologies, the pioneer in autonomous cyber deception technology, announces the launch of Deception Guardrails, a groundbreaking preemptive defense capability designed specifically to secure AI agents.
The new capability addresses a critical gap in agentic AI security: traditional guardrails primarily focus on inputs and outputs and provide limited visibility into agent behavior after compromise. Deception Guardrails introduce proactive tripwires that detect, deceive, disrupt, and deny malicious agent activity before enterprise systems are impacted.
Adopting agentic AI systems
As enterprises rapidly adopt agentic AI systems capable of autonomous reasoning and task execution via tools and APIs, the attack surface has fundamentally shifted. Recent incidents involving AI agents have highlighted how quickly compromised agents can exploit credentials, tools, and external systems in ways that evade traditional guardrails. Most AI guardrails primarily focus on controlling and filtering agent inputs and outputs, leaving security teams blind once an attacker bypasses them.
"Reactive guardrails are designed to keep well-behaved AI systems on the road, but they do nothing to stop a hijacked agent driven by a malicious actor," said Ram Varadarajan, CEO at Acalvio. "With our patent-pending Deception Guardrails, we are moving the industry from reactive filtering to preemptive defense. If an AI agent goes rogue or its infrastructure is manipulated, our deceptive assets rapidly detect the misalignment, feed the attacker fabricated data, and alert the SOC before real enterprise assets are compromised."
Perfecting deception technologies
The urgency of addressing agentic AI threats was underscored by the recent Hugging Face incident. A briefing, authored by top cyber authorities from the Cloud Security Alliance, SANS, and RSAC, issued a clear recommendation for deception, "Because agents cannot easily tell valid credentials or systems from honeypots, deploy fake identities, credentials, package registries, datasets, honey APIs, and honey clusters to slow attackers and generate high-confidence indicators."
"Acalvio has spent years perfecting deception technologies to detect sophisticated attackers inside enterprise environments. Extending those same principles to AI agents is a natural and compelling evolution. By embedding deceptive assets directly into agent workflows and surrounding AI infrastructure with decoys, organizations gain a powerful new layer of detection that complements existing AI safety and governance controls," said Lawrence Pingree, Head of Research at Software Analyst Cyber Research.
Detecting compromised agents
Beyond detecting compromised agents, Deception Guardrails provide high-confidence early warnings that help security teams reduce AI risk and respond before business-critical systems are affected. Acalvio’s Deception Guardrails natively extend the company's award-winning ShadowPlex platform, combining agentic deception and AI-infrastructure honeytokens and decoys, with comprehensive enterprise deception across on-premises and cloud environments.
Key features of Deception Guardrails include:
- Full-Spectrum Enterprise Coverage: An extensive set of honeytokens and decoys deployed across on-premises and cloud environments. This comprehensive enterprise deception ensures that any misalignment or unauthorized lateral movement by internal AI agents against enterprise infrastructure is rapidly detected.
- Agentic Deception: Deploys highly credible honeytokens and honey skills in the files and configuration surfaces that AI agents read as operational context. If a compromised agent attempts to access or utilize these tools, high-fidelity alerts are triggered.
- Decoy AI Infrastructure: Surrounds the AI ecosystem with a deceptive reality, including decoy MCP (Model Context Protocol) servers, decoy RAG (Retrieval-Augmented Generation) systems, and decoy AI agents.
- Real-time Misalignment Detection: Identifies malicious manipulation, jailbreak behavior, and prompt injections in real-time by monitoring interactions with deceptive guardrails, neutralising threats before they can pivot to production environments.
Enterprise-scale deployment
As organizations move from AI experimentation to enterprise-scale deployment, Deception Guardrails provide the visibility and pre-emptive defense required to manage agentic risk without slowing innovation.
To learn more about cyber deception, visit the Acalvio team at Black Hat USA, at Booth #8606, AI Zone. Attendees are encouraged to visit the booth for a live demonstration of Deception Guardrails against agentic attacks.