Latio Tech's 2026 AI Security Market Report set out to answer a question most security teams are still working through on their own. With dozens of vendors now claiming to secure AI, which capabilities actually matter, and who is actually building them well. The report maps the market across five categories, Endpoint Agent Specialists, Broader AI Security, Platform Providers, DLP and Insider Threat, and Developer Governance, and Lasso came out of it named a Leader.
‍
In the report, Lasso is named as one of the major Platform Leaders.
‍

‍
Where Lasso Shows Up in the Report
‍
Lasso is called out across nearly every major section of the report, including securing first-party agents, grouped with the vendors doing real application testing rather than posture checks alone, and again in the guide to securing third-party agents, grouped with the vendors that protect agents across SaaS, endpoints, and first-party systems at once instead of covering a single surface.
‍
‍

‍
Showing up in both guides reflects an architecture decision: covering first-party and third-party agents from one platform, rather than stitching together point tools for each.
‍
The report also places Lasso in its section on intent-based detection, one of the areas it flags as the most active site of innovation in the market right now. As the report describes it, agentic security is hard because agents are indeterminate: you want them to accomplish a goal, but only within defined boundaries, and intent-based detection is the mechanism most vendors are now building to enforce that. The report's guidance to readers here is direct: test a vendor's functionality yourself, because many runtime detection engines are not as powerful as advertised.
‍

‍
What the Report Says About Lasso Specifically
‍
The report gives Lasso a dedicated writeup, worth quoting directly because it gets at what our Intent Security Engine is built to do:
‍
"As organizations move more AI workloads into production, the market is demanding runtime protection that can understand not just what an application is doing, but its intentions. Lasso is a standout solution for demonstrating some of the deepest intent-based runtime protection, with flexibility in their runtime engine categories and thought put into prioritization and classifiers rather than a one-size-fits-all guardrail. This culminates in a fast, flexible, and effective detection engine that can scale across platforms."
‍
The report also describes how Lasso handles agent discovery across first and third-party applications, pairing AI red teaming with intent-based runtime protection, and calls out our visualizations of LangChain-style agentic workflows for giving teams an actual picture of what their homegrown agents are doing, rather than a list of API calls. It notes our expansion onto the endpoint, including the ability to red team local agents, which the report says few vendors currently offer.
‍
The report sums it up in one line: "Best for teams looking for discovery, runtime protection and red teaming that spans both first and third party agents."
‍
What the Report Covers Beyond Us
‍
The value of the report isn't only the vendor callouts. It's built as a practical guide, organized around the actual questions security teams are asking rather than a generic vendor list.
‍

‍
It includes two full decision trees, one for securing first-party agents and one for third-party agents, that route readers to the right category of vendor based on what they're actually trying to solve: application posture checking versus application testing, runtime guardrails for AI applications versus broader workload security, endpoint governance versus combined SaaS-and-endpoint coverage, with further breakdowns for endpoint DLP, insider threat, EDR, and OSS supply chain security.
‍
It also devotes a section to where the report's authors see the most meaningful innovation happening right now: employee-built applications and agent infrastructure, MCP and skills marketplaces, agent sandboxes, granular permissions, on-premise deployments, and intent-based detection. On employee-built agents specifically, the report notes that tools like Replit and Lovable have made it possible for a much broader set of employees to build and deploy their own agents, introducing security blind spots because that work now happens outside the established SDLC.
‍
Why This Matters
‍
None of this replaces testing tools yourselves, and the report says as much. But it's a rare artifact in AI security right now: a market map built from actual usage and testing rather than vendor claims, organized around the decisions security teams are actually trying to make. Being named a Leader in it, and being singled out specifically for how Lasso handles intent, discovery, and red teaming across both first and third-party agents, reflects the architecture decisions we've made from the start: a single platform built to cover agents wherever they actually run, first-party or third-party, SaaS or endpoint.
‍
.avif)

.png)

.png)