Acalvio Technologies has unveiled Deception Guardrails, an advanced defensive mechanism aimed at enhancing the security of AI agents through innovative cyber deception.
Designed to fill a significant void in AI security, Deception Guardrails go beyond traditional mechanisms, which often concentrate on monitoring input and output, to equip enterprises with proactive detection and prevention tools. These tools, known as tripwires, work to identify, deceive, and thwart malicious activities of AI agents before any damage is done to enterprise systems.
Addressing new AI security challenges
The swift adoption of agentic AI systems, which leverage autonomous reasoning and task execution via various tools and APIs, has notably expanded the potential attack surface. Recent security breaches involving AI agents have demonstrated how they can swiftly exploit access credentials and manipulate systems, bypassing conventional security guardrails. The reliance on traditional AI guardrails—primarily focused on managing agent inputs and outputs—leaves organisations vulnerable once these are circumvented.
Ram Varadarajan, CEO of Acalvio, explains the shift in strategy, "Reactive guardrails are designed to keep well-behaved AI systems on the road, but they do nothing to stop a hijacked agent driven by a malicious actor. With our patent-pending Deception Guardrails, we are moving the industry from reactive filtering to preemptive defence. If an AI agent goes rogue or its infrastructure is manipulated, our deceptive assets rapidly detect the misalignment, feed the attacker fabricated data, and alert the SOC before real enterprise assets are compromised."
Enhancing deception strategies
The recent incident at Hugging Face highlighted the critical need for enhanced AI security measures
The recent incident at Hugging Face highlighted the critical need for enhanced AI security measures. Experts from the Cloud Security Alliance and other cybersecurity organisations advocate for deception technologies, recommending the deployment of fake identities, credentials, and other decoys to mislead and slow down attackers.
According to Lawrence Pingree, Head of Research at Software Analyst Cyber Research, "Acalvio has spent years perfecting deception technologies to detect sophisticated attackers inside enterprise environments. Extending those same principles to AI agents is a natural and compelling evolution."
Comprehensive detection and prevention
Acalvio's Deception Guardrails integrate seamlessly with the company's ShadowPlex platform, offering a robust blend of deception methods for both AI-specific and traditional enterprise settings. Deception Guardrails deliver high-confidence early alerts, allowing security teams to mitigate risks promptly and before critical systems are jeopardised. Key aspects include comprehensive enterprise coverage with honeytokens and decoys, agentic deception with highly credible honey skills, and decoy AI infrastructure to present a false reality for attackers.
With organisations increasingly moving towards large-scale AI deployments, the ability to manage agentic risks without hindering innovation becomes paramount. Deception Guardrails ensure that enterprises maintain the necessary visibility and defensive posture to secure their AI initiatives effectively. Interested parties can learn more about these advancements at Black Hat USA, where Acalvio will present live demonstrations at Booth #8606, AI Zone.
Acalvio Technologies, the pioneer in autonomous cyber deception technology, announces the launch of Deception Guardrails, a groundbreaking preemptive defence capability designed specifically to secure AI agents.
The new capability addresses a critical gap in agentic AI security: traditional guardrails primarily focus on inputs and outputs and provide limited visibility into agent behaviour after compromise. Deception Guardrails introduce proactive tripwires that detect, deceive, disrupt, and deny malicious agent activity before enterprise systems are impacted.
Adopting agentic AI systems
As enterprises rapidly adopt agentic AI systems capable of autonomous reasoning and task execution via tools and APIs, the attack surface has fundamentally shifted. Recent incidents involving AI agents have highlighted how quickly compromised agents can exploit credentials, tools, and external systems in ways that evade traditional guardrails. Most AI guardrails primarily focus on controlling and filtering agent inputs and outputs, leaving security teams blind once an attacker bypasses them.
"Reactive guardrails are designed to keep well-behaved AI systems on the road, but they do nothing to stop a hijacked agent driven by a malicious actor," said Ram Varadarajan, CEO at Acalvio. "With our patent-pending Deception Guardrails, we are moving the industry from reactive filtering to preemptive defence. If an AI agent goes rogue or its infrastructure is manipulated, our deceptive assets rapidly detect the misalignment, feed the attacker fabricated data, and alert the SOC before real enterprise assets are compromised."
Perfecting deception technologies
The urgency of addressing agentic AI threats was underscored by the recent Hugging Face incident. A briefing, authored by top cyber authorities from the Cloud Security Alliance, SANS, and RSAC, issued a clear recommendation for deception, "Because agents cannot easily tell valid credentials or systems from honeypots, deploy fake identities, credentials, package registries, datasets, honey APIs, and honey clusters to slow attackers and generate high-confidence indicators."
"Acalvio has spent years perfecting deception technologies to detect sophisticated attackers inside enterprise environments. Extending those same principles to AI agents is a natural and compelling evolution. By embedding deceptive assets directly into agent workflows and surrounding AI infrastructure with decoys, organisations gain a powerful new layer of detection that complements existing AI safety and governance controls," said Lawrence Pingree, Head of Research at Software Analyst Cyber Research.
Detecting compromised agents
Beyond detecting compromised agents, Deception Guardrails provide high-confidence early warnings that help security teams reduce AI risk and respond before business-critical systems are affected. Acalvio’s Deception Guardrails natively extend the company's award-winning ShadowPlex platform, combining agentic deception and AI-infrastructure honeytokens and decoys, with comprehensive enterprise deception across on-premises and cloud environments.
Key features of Deception Guardrails include:
- Full-Spectrum Enterprise Coverage: An extensive set of honeytokens and decoys deployed across on-premises and cloud environments. This comprehensive enterprise deception ensures that any misalignment or unauthorised lateral movement by internal AI agents against enterprise infrastructure is rapidly detected.
- Agentic Deception: Deploys highly credible honeytokens and honey skills in the files and configuration surfaces that AI agents read as operational context. If a compromised agent attempts to access or utilise these tools, high-fidelity alerts are triggered.
- Decoy AI Infrastructure: Surrounds the AI ecosystem with a deceptive reality, including decoy MCP (Model Context Protocol) servers, decoy RAG (Retrieval-Augmented Generation) systems, and decoy AI agents.
- Real-time Misalignment Detection: Identifies malicious manipulation, jailbreak behavior, and prompt injections in real-time by monitoring interactions with deceptive guardrails, neutralising threats before they can pivot to production environments.
Enterprise-scale deployment
As organisations move from AI experimentation to enterprise-scale deployment, Deception Guardrails provide the visibility and pre-emptive defence required to manage agentic risk without slowing innovation.
To learn more about cyber deception, visit the Acalvio team at Black Hat USA, at Booth #8606, AI Zone. Attendees are encouraged to visit the booth for a live demonstration of Deception Guardrails against agentic attacks.