Sweet Security adds real-time blocking to AI agent enforcement

The $120m-backed runtime security firm now blocks rogue AI agent behaviour live, targeting a gap no existing cloud security tool covers.

Sweet Security adds real-time blocking to AI agent enforcement

Sweet Security, the Israeli-founded runtime enforcement company backed by $120m from Evolution Equity Partners, Munich Re Ventures, and Glilot Capital Partners, has launched Agentic AI Blocking: a capability that terminates unauthorised AI agent actions in real time rather than logging them for later review.

The announcement, made at Black Hat USA 2026 in Las Vegas, extends Sweet's existing cloud runtime platform into the rapidly expanding layer of autonomous AI agents now operating inside enterprise infrastructure. The company claims its system analyses over one billion runtime events daily to build a behavioural baseline for every application and agent, then enforces a single rule: do exactly what your creator intended and nothing more.

From detection to prevention

The dominant model in enterprise security has long been detect-and-alert. A tool flags anomalous behaviour; a human reviews the alert; a decision is made. That loop, adequate for slower-moving threats, is structurally mismatched with autonomous AI agents that can exfiltrate data, call external APIs, or escalate permissions in milliseconds. Sweet's pitch is that by the time an analyst reads the queue, the agent has already acted.

The new capabilities specifically address three risk vectors: unauthorised tool calls and sessions, outbound data flows carrying secrets or personally identifiable information, and prompt injection attacks, where a malicious instruction embedded in content steers an agent away from its intended task. Prompt injection is an emerging attack class that has no analogue in pre-AI cloud security, making it a useful bellwether for how far the threat surface has shifted.

Dror Kashti, CEO and co-founder, framed the problem in economic terms: "AI has collapsed the cost of attack, and it has put autonomous software inside the enterprise. Someone has to decide, in the moment, what an agent is allowed to do."

The convergence angle: cloud security meets the agentic layer

Sweet's expansion is a direct consequence of a structural shift in enterprise architecture. Agentic AI, where models are given tools, memory, and the authority to act on behalf of users or systems, is collapsing the boundary between application logic and security perimeter. The cloud security market, historically focused on infrastructure misconfigurations and network intrusion, now has to account for software that makes its own decisions about what data to access and what actions to take.

This creates a convergence challenge that reaches well beyond cybersecurity. For enterprises deploying AI agents across finance, healthcare, and logistics workflows, the risk is not just a data breach; it is an autonomous action taken in a live production environment before any human can intervene. The liability question alone, particularly under the EU AI Act's requirements for human oversight of high-risk AI systems, gives this product category regulatory urgency that pure cloud-security tooling does not carry.

The investor composition behind Sweet is itself a signal of convergence capital at work. Munich Re Ventures, the venture arm of one of the world's largest reinsurers, is backing an AI runtime security platform. Insurers pricing cyber risk are structurally motivated to fund tools that can produce auditable, real-time enforcement records, because those records are precisely what a claims investigation or a regulatory audit requires.

The broader agent-security market is still nascent. Established cloud security platforms from CrowdStrike, Wiz, and Orca Security have each added AI-workload monitoring features, but autonomous blocking rather than alerting remains an emerging capability. Sweet's claim to be enforcing across cloud and AI in a single platform positions it as a consolidation candidate if the major platforms move to acquire rather than build. The Black Hat showcase, a traditional hunting ground for enterprise security acquirers, is a deliberate stage for that audience.