An acronym is a ticker symbol. Before you take the position, read the prospectus.
Why the Acronym Soup Matters Now
The AI-security vendor landscape has minted more category names in eighteen months than endpoint security produced in a decade: AIDR, AI-SPM, AITDR, AI gateways, LLM firewalls, guardian agents. On a recent call, one vendor rep was candid about where his own category label came from: “a marketing term we pretty much made up.” That’s not a scandal — it’s how young markets work. But it means the acronym on the datasheet tells you nothing about where the product sits in your stack or what it can actually stop.
The stakes of getting the sorting wrong are no longer theoretical. Budgets are forming, and the line item will be defended in front of a CFO who wants to know what was bought.
| Signal | Number | Source |
|---|---|---|
| Enterprises with AI agents already active on endpoints | 88% | Ospiri research |
| Vendors in Gartner’s “risk and security specialist” guardian-agent category alone | 29+ | Gartner |
| Projected share of agentic AI spend allocated to guardian agents by 2028 | 5–7%, up from under 1% today | Gartner |
| Window before agent governance becomes a standard procurement line | 12–18 months | Ospiri research |
When a category has 29+ vendors and no settled definition, the operational decision is harder than the budget decision. The acronyms won’t sort them for you. Architecture will.
What the Labels Actually Claim
Strip the branding and every vendor in the soup occupies one of a small number of structural positions. The label is packaging; the position is the product.
| Label | What it inspects | Where it sits | Observe or enforce |
|---|---|---|---|
| AI-SPM (posture management) | Cloud workloads, SaaS configs, model inventories | Cloud APIs and logs | Observe — posture and inventory |
| AIDR (detection & response) | AI usage signals, anomalous model traffic | Network edge, SaaS logs, sometimes endpoint telemetry | Mostly observe; response is often a ticket |
| AITDR (threat detection & response) | Attacks on models — prompt injection, jailbreaks, poisoning | Application layer, in front of the model | Detect; block at the prompt layer |
| AI gateway / LLM proxy | Prompts and completions in transit | Forward proxy or SDK | Enforce — but only on traffic routed through it |
| Agent firewall | Process, file, and network actions of agents | OS kernel on the endpoint | Enforce in-line, below the application layer |
Notice what the table sorts on: not the acronym, but the underlying. A posture tool prices configuration risk. A gateway prices routed-traffic risk. An agent firewall prices action risk — what software does on the machine after the prompt resolves. These are different books, and no single position hedges all three.
The Seven Questions That Cut Through
Run every shortlisted vendor through the same seven questions, in the same order, and record verbatim answers. The framework does the sorting the acronyms can’t.
- Do you observe, or do you enforce? The single sharpest question in the category. Most guardian-agent tools today support passive monitoring; in-line enforcement remains rare. A dashboard that reports an incident thirty seconds after the file left the estate is a record of what you failed to stop.
- Where in the stack do you sit? Browser extension, forward proxy, SaaS API, cloud log ingestion, or endpoint kernel. This determines what the product can ever see — a proxy will never see a local MCP server over stdio; a cloud posture tool will never see a laptop filesystem.
- What counts as “an agent” in your model? Some vendors mean chatbot sessions. Some mean SaaS copilots. Very few mean the standalone binaries — Cursor, Claude Desktop, Goose, Cline — that hold real permissions on real endpoints. If their definition excludes your riskiest surface, so does their coverage.
- What is the policy granularity? Org-wide toggle, per-user rule, or per-process, per-file, per-scope policy? “Block AI” is not a policy; it’s a memo. Ask them to author a policy live on the call: this process may read this directory but not that one.
- What are your top customers’ top pain points? A vendor fluent in their customers’ actual incidents will answer instantly and specifically. A vendor selling a repositioned product will answer with the analyst narrative.
- Which platforms get real depth? Everyone claims cross-platform. Ask what’s shipped for Windows kernel versus macOS versus Linux, and what “supported” means on each — enforcement, or telemetry.
- What can’t you do? The gaps a vendor can enumerate are the gaps they’ve measured. “We have no blind spots” is the least credible sentence in the category. Then ask for the live demo of enforcement — “the agentic piece can’t be demoed today” is an answer, and it’s the answer.
Scoring the Answers
Verbatim answers are the raw data; the decision needs a number. Score each vendor on four factors, 1–5 each:
Vendor Fit Score = (Enforcement Depth × Surface Coverage) + (Evidence Quality × Definitional Honesty)
| Factor | What it measures | 5 looks like | 1 looks like |
|---|---|---|---|
| Enforcement Depth | Can it intervene mid-action? | In-line kernel block or sandbox, demoed live | Alert-only dashboard |
| Surface Coverage | Which agent classes it governs | Standalone binaries, embedded copilots, and MCP servers | Browser chat sessions only |
| Evidence Quality | Audit-grade artifacts | Process, file, label, action, verdict — exportable to your SIEM | Screenshots of a dashboard |
| Definitional Honesty | Questions 3 and 7 | Precise agent definition, enumerated blind spots | “Everything, everywhere, 100%” |
The multiplication is deliberate: enforcement without coverage is a control on the wrong surface, and evidence without honesty is marketing with timestamps. A vendor scoring high on one leg and near-zero on its pair rounds to near-zero — the same way a hedge that only covers one leg of a position isn’t a hedge.
What CISOs Should Do This Quarter
| Step | Action | Output | Effort |
|---|---|---|---|
| 1 | Inventory the shortlist and map each vendor to a structural position, ignoring the acronym on the datasheet | One-page category map | Half a day |
| 2 | Run the seven questions on identical terms across every vendor; require a live enforcement demo | Verbatim answer sheet per vendor | One call each |
| 3 | Score the answers with the fit formula; flag any vendor that refuses the live demo | Ranked scorecard | Two hours |
| 4 | Match the top scorer against your riskiest surface — for most estates, the ungoverned agents already on endpoints | PoC scope with exit criteria | One planning session |
The Bottom Line
The acronyms are packaging; the only durable way to sort AI-security vendors is by where they sit in the stack and whether they can enforce, not just observe. A market with 29+ vendors and a made-up-by-marketing category name rewards buyers who run their own framework instead of adopting the vendor’s. The seven questions cost you one call per vendor and will save you a procurement cycle spent discovering that “response” meant a ticket. And the honest vendors — the ones who can name their gaps and demo enforcement live — will welcome the exercise, because it’s the shortest path past the noise. That’s the governance posture the budget line was supposed to buy in the first place.
If your team is sizing this for the next budget cycle, request a working session. We will walk through your environment, run the seven-question scorecard against your current shortlist, and scope a deployment. 90 minutes.