Express Computer
Home  »  News  »  Operant AI launches Semantic Firewall to secure AI agents

Operant AI launches Semantic Firewall to secure AI agents

0 0

San Francisco-headquartered Operant AI has announced the launch of Operant Semantic Firewall, an AI security layer designed to understand an AI agent’s intent in real time and enforce enterprise policies inline. The solution can stop malicious actions, jailbreaks and potential data breaches before they are executed.

As enterprises increasingly deploy AI agents across workflows handling sensitive data, agents are gaining the ability to run code, modify records, access enterprise data, call external tools and interact with other models and services. This increased autonomy is creating a need for security controls that can assess not only what an agent is doing but also whether its actions remain within the purpose and permissions assigned to it.

Operant Semantic Firewall evaluates the meaning and intent behind an agent’s activity across prompts, model responses, commands, tool calls and data movement. It can then make an inline allow, block or redact decision as the agent operates, creating an enforceable control layer across the agent loop.

Addressing the governance gap in agentic AI

Unlike traditional signature- and pattern-based security controls, which are designed to identify known indicators of malicious activity, agentic systems can generate novel actions, chain individually legitimate steps into an unauthorised outcome, or encounter instructions through tools and data that were not anticipated when the system was configured.

The need for such controls is becoming more pressing as enterprise AI adoption accelerates. According to IBM’s 2026 study of 2,000 technology CXOs across 33 geographies, 77% believe AI adoption is already outpacing their governance capabilities, while organisations that embedded controls directly into their AI systems experienced 25% fewer incidents than those relying on manual governance.

The challenge is particularly relevant in India. Salesforce’s 2025 State of IT: Security survey found that 76% of Indian IT security teams expect to use AI agents within two years, compared with 43% today. However, 52% were not fully confident that they had the appropriate guardrails to deploy them, while 87% said AI agents present compliance challenges.

As India advances its AI governance framework and strengthens data-protection requirements under the Digital Personal Data Protection Act and Rules, organisations are facing greater expectations around secure, accountable and responsible AI deployment.

The risk is not limited to malicious users. An agent can be manipulated through prompt injection or a jailbreak, but it can also move beyond its intended scope independently, improvising a step that was never authorised or chaining together legitimate actions into an unintended outcome.

A security layer for sovereign AI

Operant positions Semantic Firewall as a defence layer for sovereign AI, extending the concept of sovereignty beyond data residency and access to the decisions and actions taken by AI agents.

The platform is designed to keep enforcement within the enterprise environment. Every allow, block and redact decision can be made inside the organisation’s own VPC, on-premises or air-gapped environment, with prompts, payloads and policies remaining within the enterprise perimeter.

Semantic Firewall uses Operant’s own models to classify intent rather than routing enforcement decisions to an external frontier model provider. Its enforcement layer also operates independently of the underlying AI model, allowing enterprises to change model providers without changing their security controls.

This approach is intended to help organisations operating under data residency requirements and sector-specific regulatory frameworks demonstrate AI governance and enforcement to auditors, rather than relying solely on assurances from third-party AI providers.

Security built around agent intent

Operant Semantic Firewall brings together multiple intent-analysis capabilities under a single control plane:

-Tool Intent Guard: Evaluates the real-world impact of tool calls and can block data exfiltration, bulk data transfers, credential access and unauthorised sharing, even where an activity does not match an existing blocklist.

-Code Intent Guard: Analyses coding-agent activity, including package and MCP server installations, command execution and skill usage, to identify malicious execution, injection, shell breakout, privilege escalation and hidden directives.

-Data Intent Guard: Classifies files and data as confidential or business-sensitive, including through integrations with enterprise data-governance platforms such as Microsoft Purview.

-Scope Guard: Keeps an agent aligned with its authorised purpose by continuously testing follow-up instructions, tool arguments, tool results and high-risk actions for scope drift.

-Natural-language policies: Allows administrators to define restrictions in straightforward terms, such as “no unauthorised deletes” or “no PII leaving this workspace”, with the firewall enforcing those policies on every turn and explaining each allow, block or redact decision.

Because the same intent model is applied across prompts, model responses, commands, tool calls and data movement, enforcement can take place at multiple points in an agent workflow rather than relying on a single security checkpoint.

Vrajesh Bhavsar, CEO and co-founder, Operant AI, said, “Agent security has moved past its first two generations. Watching agents and filtering keywords were fine for early experiments, and some teams will be comfortable there for a while. But the serious enterprises, the ones putting agents into revenue, customer data, and production systems, need a specialist layer that understands intent and enforces it in real time. Vanilla controls weren’t built for that, but Operant was.”

He added, “This year showed the industry that agents don’t only go off course because someone pushed them; they do it on their own, chasing a goal down whatever path they can find, including straight out to systems and models they were never meant to touch. The answer is to bring the trust boundary back inside your own walls. Operant Semantic Firewall understands the intent behind everything an agent does, governs every connection it makes, and enforces the enterprise’s policy inline at the speed of agents inside their perimeter, on their terms, no matter whose model is running underneath.”

Expanded AI security capabilities

Alongside Semantic Firewall, Operant AI is introducing several updates to its AI defence platform.

Live Browser AI Protection is designed to secure AI activity taking place within authenticated browser sessions. It can analyse conversations in real time across ChatGPT, Claude, Copilot and Gemini, allowing, sanitising or blocking sensitive content before prompts are sent and responses are rendered.

The company has also expanded its Claude coverage to include Claude Cowork cloud-mode sessions and, through a new inference-hook integration, Claude across its desktop app, Claude Tag and Claude Design.

Meanwhile, Operant Token Meter provides near-real-time visibility into token usage by user, team, agent and model, with budget limits that can be enforced during a session across deployments, including Bedrock, Vertex and Foundry.

Operant Semantic Firewall, Browser AI Coverage, expanded Claude coverage and Operant Token Meter are all available as part of Operant AI’s AI defence platform.

Leave A Reply

Your email address will not be published.