Home
News
Tech Grid
Data & Analytics
Data Processing Data Management Analytics Data Infrastructure Data Integration & ETL Data Governance & Quality Business Intelligence DataOps Data Lakes & Warehouses Data Quality Data Engineering Big Data
Enterprise Tech
Digital Transformation Enterprise Solutions Collaboration & Communication Low-Code/No-Code Automation IT Compliance & Governance Innovation Enterprise AI Data Management HR
Cybersecurity
Risk & Compliance Data Security Identity & Access Management Application Security Threat Detection & Incident Response Threat Intelligence AI Cloud Security Network Security Endpoint Security Edge AI
AI
Ethical AI Agentic AI Enterprise AI AI Assistants Innovation Generative AI Computer Vision Deep Learning Machine Learning Robotics & Automation LLMs Document Intelligence Business Intelligence Low-Code/No-Code Edge AI Automation NLP AI Cloud
Cloud
Cloud AI Cloud Migration Cloud Security Cloud Native Hybrid & Multicloud Cloud Architecture Edge Computing
IT & Networking
IT Automation Network Monitoring & Management IT Support & Service Management IT Infrastructure & Ops IT Compliance & Governance Hardware & Devices Virtualization End-User Computing Storage & Backup
Human Resource Technology Agentic AI Robotics & Automation Innovation Enterprise AI AI Assistants Enterprise Solutions Generative AI Regulatory & Compliance Network Security Collaboration & Communication Business Intelligence Leadership Artificial Intelligence Cloud
Finance
Insurance Investment Banking Financial Services Security Payments & Wallets Decentralized Finance Blockchain Cryptocurrency
HR
Talent Acquisition Workforce Management AI HCM HR Cloud Learning & Development Payroll & Benefits HR Analytics HR Automation Employee Experience Employee Wellness Remote Work Cybersecurity
Marketing
AI Customer Engagement Advertising Email Marketing CRM Customer Experience Data Management Sales Content Management Marketing Automation Digital Marketing Supply Chain Management Communications Business Intelligence Digital Experience SEO/SEM Digital Transformation Marketing Cloud Content Marketing E-commerce
Consumer Tech
Smart Home Technology Home Appliances Consumer Health AI
Interviews
Anecdotes
Think Stack
Press Releases
Articles
  • AI

Wallarm Leads A2AS Standard for Agentic AI Security


Wallarm Leads A2AS Standard for Agentic AI Security
  • by: Source Logo
  • |
  • September 29, 2025

Wallarm has taken a leading role in publishing "A2AS: Agentic AI Runtime Security and Self-Defense," a pioneering research project spearheaded by Eugene Neelou from OWASP and Wallarm, in collaboration with experts from AWS, Bytedance, Cisco, Elastic, Google, JPMorganChase, Meta, and Salesforce. This framework establishes a dedicated security layer for AI agents, LLM-powered applications, and AI protocols, analogous to HTTPS for HTTP, to mitigate escalating risks in enterprise deployments.

Quick Intel

  • A2AS introduces runtime security for agentic AI, addressing prompt injection, tool misuse, and agent compromise through innovative capabilities.
  • Behavior Certificates enable declaration and enforcement of AI agent actions and permissions, securing interactions like HTTPS does for web traffic.
  • Model Self-Defense Reasoning embeds security awareness in the AI context window for real-time rejection of malicious instructions without external tools.
  • Prompt-Level Security Controls provide authenticated prompts, boundaries, and policy-as-code for verified, sandboxed interactions aligned with policies.
  • Framework counters enterprise risks in finance, healthcare, and infrastructure by offering lightweight, scalable protection without added latency.
  • Project invites researchers, engineers, and enterprises to collaborate via https://a2as.org for early adoption and standard development.

Establishing a New Security Paradigm for AI Agents

The A2AS framework emerges as enterprises integrate agentic AI into critical workflows, where vulnerabilities could lead to widespread compromise. Traditional approaches like guardrails and post-processing fall short in speed and cost-effectiveness, prompting the need for embedded runtime protections. By focusing on self-defense mechanisms, A2AS ensures AI systems operate securely from the outset, safeguarding against evolving threats in high-stakes sectors.

Core Capabilities: Behavior Certificates and Permissions

Behavior Certificates represent a foundational innovation, allowing AI agents to declare and enforce their actions and resource access explicitly. This mechanism mirrors HTTPS certificates by verifying and securing agent interactions with users, tools, and peers, preventing unauthorized behaviors and tool misuse. Integrated with enterprise identity controls, it supports attribution and access management, forming a robust barrier against compromise.

Embedding Self-Defense and Prompt Protections

Model Self-Defense Reasoning integrates security logic directly into the AI model's context, enabling instantaneous detection and deflection of untrusted inputs without relying on external components. Complementing this, Prompt-Level Security Controls—refined as Authenticated Prompts and Security Boundaries—verify prompt integrity, isolate untrusted data, and enforce code-driven policies. These features maintain context window separation, thwarting prompt injection through in-context defenses and runtime orchestration for defense-in-depth.

Collaborative Path to Industry Standardization

Led by Eugene Neelou, who coined MLSecOps and co-authored the OWASP Top 10 for LLM Security, the project draws on Ivan Novikov's API and AI security expertise from Wallarm. "AI agents are already in production, and they introduce a dangerous new attack surface," said Ivan Novikov. "With A2AS, we've shown that security can be embedded directly into the agent runtime, turning self-defense from a theory into a practical defense layer." "AI agents are rapidly infiltrating enterprise software, requiring privileged access and deep integration with company-wide tools," added Eugene Neelou. "Under pressure to adopt AI, enterprises are voluntarily incorporating vulnerable-by-design AI capabilities. Without deliberate security hardening, disaster is inevitable."

About Wallarm

Wallarm is the only unified platform for API and agentic AI security successfully deployed in enterprise production environments. With Wallarm, customers receive the fastest, easiest, and most effective way to stop API attacks. Organizations choose Wallarm to protect their APIs and AI agents because the platform delivers a complete inventory of APIs, real-time blocking, and patented AI/ML-based abuse detection. Wallarm is headquartered in San Francisco, California, and is backed by Toba Capital, Y Сombinator, Partech, and other investors.

  • WallarmA2ASAgentic AIAI SecurityLLM Security
News Disclaimer
  • Share