Radware announced the launch of its Agentic AI Protection Solution, extending the Radware Platform into the rapidly growing AI security market.
As organizations increasingly deploy autonomous AI agents to boost productivity and automate decision-making, Radware delivers a purpose-built defense against the unique and emerging risks of the agentic AI era.
In January, Gartner Research forecasted worldwide AI spending will reach $2.5 trillion in 2026, including $51.3 billion dedicated to AI security solutions.
Comprehensive Protection for the Agent Economy
Most AI security approaches rely on static, software-based guardrails designed for governance, not for securing autonomous, tool-using AI agents at runtime. As agentic AI systems scale, these guardrails fail to keep pace. Radware’s Agentic AI Protection goes beyond guardrails, using external, algorithmic behavioral analysis to identify malicious intent and misuse in real time, providing protection aligned with the scale and complexity of agentic AI.
Radware’s new solution is designed to address a broad spectrum of agent-specific security risks, including direct and indirect prompt injection attacks, tool abuse, human–agent trust exploitation, and unauthorized data access. The solution is built on four strategic pillars:
Discovery and Visibility: Real-time identification of all AI agents—both homegrown and SaaS-based—and the tools and systems they access.
Intent-Based Security: Advanced runtime behavioral algorithms that detect and mitigate malicious or abnormal intent within agent interactions, including multi-step and cross-agent behaviors.
Deep Integration: Seamless protection for custom-built agents as well as leading third-party agent platforms and services, including homegrown agents, Microsoft 365 Copilot, Microsoft 365 Copilot Studio, AWS Bedrock and more.
Continuous AI Security Posture Management: A dynamic Risk Graph Map that continuously scores an organization’s agentic AI security posture, highlighting multi-agent risk paths and potential data exposure in real time.
Aligning with Industry Standards
Radware Agentic AI Protection is designed to align with the OWASP Top 10 for Agentic AI and leverages the AI Vulnerability Scoring System (AIVSS) to assess and prioritize core security risks. By introducing a dedicated security layer for autonomous workflows, Radware assists enterprises to safely adopt AI agents while maintaining control over sensitive data and critical systems.
The Growing Danger: “ZombieAgent” and the Blind Spot of Autonomy
The launch follows Radware’s recent discovery of ZombieAgent, a critical zero-click indirect prompt injection (IPI) vulnerability affecting agentic AI environments. Unlike traditional cyberattacks, ZombieAgent enables attackers to implant malicious, persistent instructions directly into an AI agent’s long-term memory or working context—without any user interaction.
These “zombie” instructions can silently trigger ongoing data exfiltration, including emails and corporate files, directly from cloud-based systems, while bypassing traditional security controls such as firewalls and endpoint detection solutions.
Agentic AI Protection Solution is part of Radware’s broader agentic AI protection solution for enterprises. It follows the recent launch of LLM Firewall, designed to help address the growing security concerns around integrated LLM modules in applications and to protect the LLM prompt and response against attacks and abuse.
Roy Zisapel, president and CEO of Radware
Our customers understand the dual nature of AI — they want the business benefits while recognizing the growing threat landscape. With decades of experience applying advanced algorithms to solve complex application security challenges, Radware is uniquely positioned to bring innovative AI security solutions to market.
Constance Stack, chief growth officer, Radware
Enterprises rely on these agents to make decisions and access sensitive systems, but they lack visibility into how agents interpret untrusted content. Radware Agentic AI Protection was born to close this dangerous blind spot