AI Detection & Response (AIDR) is a new category of solutions for protecting AI execution environments, providing detection, investigation, and response to threats aimed at or originating from AI systems, regardless of where they operate: on endpoints, SaaS applications, or cloud environments.
AIDR forms a new security architecture for the era of AI agents—a unified platform focused on controlling and protecting AI agent actions in real-time.
The AIDR platform differs from related solution categories by three key principles:
- Protection during execution, not security posture assessment.
Security configuration management solutions assess risks before or after the execution of actions. Instead, AIDR works directly during execution, analyzing each request, tool call, and every AI agent action with millisecond precision, as modern autonomous attacks develop with such speed.
- A single platform instead of a set of separate tools
During the execution of a single task, an AI agent can simultaneously interact with endpoints, cloud infrastructure, and SaaS applications. Using separate specialized security tools for each level only creates fragmented security signals that do not provide a comprehensive understanding of the attack chain in real-time.
- Action-oriented control, not observation.
AIDR is not limited to threat detection. It ensures a full cycle of protection, allowing the blocking of dangerous actions, concealing confidential data, isolating compromised components, and revoking accesses directly during the execution of potentially dangerous operations.
Additionally, AIDR should ensure the protection of the entire seven-layer AI ecosystem, which includes data, models, prompts, AI agents, digital identities, infrastructure, and interactions.
Each of these layers forms its own attack surface and creates new challenges for cybersecurity.
Figure 2. The AI ecosystem consists of seven layers: data, models, prompts, AI agents, digital identities, infrastructure, and interactions.
The operational foundation of AIDR is the AI Control Plane—a unified AI security control plane that provides the execution of four key protection functions in real-time:
- control of digital identities through continuous verification and authorization;
- data protection by blocking dangerous operations, masking confidential information, and encryption;
- control of AI agent execution, allowing the stopping of threats directly during their implementation;
- incident response, including isolation, localization, and elimination of threats.
This control plane should encompass all seven levels of the AI ecosystem and provide unified protection across all environments where artificial intelligence operates: on endpoints, in SaaS applications, and cloud infrastructure.