A new security startup is tackling one of the most urgent problems in enterprise AI: how to stop autonomous AI agents from causing real damage before it's too late.
Vorlon Inc. today launched Guardian, a real-time enforcement gateway that sits between AI agents and the enterprise systems they connect to, applying security policy before any transaction goes through. Unlike traditional security tools that flag incidents after the fact, Guardian blocks risky actions as they happen.
The product targets a fundamental gap in enterprise security. AI agents do not log in like human users — they authenticate with OAuth tokens and API keys, chain actions across multiple systems, and move sensitive data at machine speed with no human in the loop. As Vorlon puts it: with agents, the activity itself is the threat, not the access.
Guardian's policy engine can block actions that violate rules, mask sensitive data in transit before it reaches an unauthorized destination, and downgrade an agent's access to read-only where write access is not warranted. Policies can be set both at the agent platform level and at each connected system individually.
"Enterprises have spent years building security programs around the assumption of governing access equaling governing risk," said Amir Khayat, Vorlon's co-founder and CEO. "AI agents broke that assumption. They operate through legitimate access, at machine speed, across systems no single team fully owns."
The launch comes amid sharp unease among security leaders. Vorlon's 2026 Agentic Ecosystem Security Gap Report found that 75.4% of CISOs rate AI agents a critical or significant risk, 99% are worried about an AI or software supply chain breach this year, and fewer than 1% feel adequately protected.
Vorlon points to a concrete cautionary tale: in April 2026, an AI coding agent deleted the entire production database and all backups of a service called PocketOS in nine seconds — despite explicit rules against destructive operations. Guardian's read-only enforcement would have stopped the writes regardless of what the model decided.
Guardian covers any application or data store with an API or Model Context Protocol server, including homegrown apps, legacy systems, and tools built with AI coding assistants like Claude Code and Codex. It can be activated in minutes.
The company, founded in 2022 and backed by Accel, says Guardian is available now.
Sources
- siliconangle.comSiliconANGLE — Vorlon debuts Guardian to block risky AI agent actions before they complete
- cioinfluence.comCIO Influence — Vorlon Launches Guardian to Close the Enforcement Gap in Agentic AI Runtime Security
- securityboulevard.comSecurity Boulevard — Vorlon Adds Guardian Gateway to Secure Any AI Agent




