
Operant AI has launched a new security product designed to stop potentially malicious actions by AI agents before they are executed, as companies increasingly deploy agents capable of running code, accessing databases and interacting with enterprise systems.
San Francisco-based Operant AI announced on August 27, 2026, that its Operant Semantic Firewall can evaluate an AI agent’s intended action and decide whether to allow, block or redact it in real time. The company says the system is intended to enforce security policies based on the meaning and expected effect of an agent’s activity rather than relying only on conventional network and application controls.
The launch comes amid recent reports of security incidents involving AI agents and AI-powered coding tools. Reuters reported on August 26 that OpenAI had investigated an incident involving hundreds of AI agents that accessed connected systems, while a separate Reuters report published on August 27 said Russian-speaking cybercriminals had used Cursor AI coding agents during attacks against seven companies.
Operant says the Semantic Firewall is built around four controls called Intent Guards. The Tool Intent Guard examines agent tool calls and is designed to identify activity such as data exfiltration, bulk extraction, credential access, unauthorized sharing and suspicious use of tools, MCPs, plugins and sub-agents.
The Code Intent Guard is focused on coding agents and generated commands. According to Operant, it evaluates generated code, shell commands, scripts, package installations, MCP server installations, skills and command execution for activity including command injection, shell breakout, privilege escalation, malicious execution and hidden instructions.
The Data Intent Guard focuses on information being accessed or transferred. Operant says it can use built-in data classification as well as existing enterprise governance systems, including Microsoft Purview. The company says the system can redact sensitive information rather than necessarily stopping an entire workflow when only part of an operation violates policy.
The fourth control, Scope Guard, is designed to track an agent’s original objective throughout a session and assess whether later actions remain within that scope. Operant describes two scenarios it is designed to address: an attacker changing an agent’s behavior through techniques such as prompt injection, malicious documents or hidden instructions, and an agent independently taking actions beyond what its operator originally intended.
Operant says administrators can express restrictions in natural-language policies. Examples published by the company include rules such as “no unauthorized deletes” and “no PII leaving this workspace.” The firewall evaluates activity against those policies and returns an allow, block or redact decision with an explanation.
The company says the Semantic Firewall operates as an inline enforcement layer across the agent loop. Operant says deployments can run inside a customer’s virtual private cloud, on-premises infrastructure or air-gapped environment. It also says prompts, payloads and policy decisions do not have to leave the organization’s perimeter for adjudication.
Operant says its approach is intended to keep enforcement within the customer’s environment and uses models developed by the company for intent classification rather than relying on an external frontier-model provider to make each security decision.
The product is positioned as part of a broader Operant AI security platform rather than as a standalone launch. The company’s existing portfolio includes Semantic Firewall, Agent Protector, Endpoint Protector, MCP Gateway and AI Gatekeeper, alongside protections for APIs and cloud environments.
Operant’s MCP Gateway provides controls for MCP servers, clients, tools and connections, while Agent Protector is focused on runtime monitoring and blocking for agent workloads. The company also launched Endpoint Protector in 2026 to monitor AI tools and agents running on employee endpoints, including coding agents and MCP clients.
The Semantic Firewall is described as supporting environments including Claude Code, LangChain and Cursor MCP. Operant’s wider platform also includes browser-based AI protection. In its August 27 announcement, the company said that feature can inspect conversations in real time across ChatGPT, Claude, Copilot and Gemini and can allow, sanitize or block content before prompts are sent or responses are rendered.
Operant also announced expanded Claude coverage for Claude Cowork cloud sessions and said an inference-hook integration extends protection to other Claude surfaces, including the desktop application, Claude Tag and Claude Design.
A separate product announced alongside the firewall, called Token Meter, is designed to provide near-real-time usage information by user, team, agent and model, with runtime budget controls. Operant says it supports deployments including Amazon Bedrock, Google Vertex and Microsoft Foundry.
Operant was founded by Vrajesh Bhavsar, Priyanka Tembey and Ashley Roof. The company’s background includes security and infrastructure work associated with Apple, Arm and VMware. Bhavsar previously worked on Dynamic Tracing, Data Protection and Secure Enclave at Apple and later built an ML and AI business unit at Arm. Tembey previously worked on VMware’s hybrid-cloud technology, while Roof previously held sales and marketing roles at Google.
The company raised $10 million in Series A funding in September 2024, a round led by SineWave Ventures and Felicis. Operant said the financing brought its total funding to $13.5 million at the time. Alumni Ventures, Massive, Calm Ventures and Gaingels also participated.
Operant is also listed on the AWS Marketplace. AWS’s listing for the company’s AI Gatekeeper describes runtime protection for LLMs, agents, Kubernetes, APIs and MCP. The listing states that the product can provide inline protection and automatic redaction without making external calls for those defenses.
The AWS Marketplace listing shows contract-based pricing for AI Gatekeeper, including a listed one-month option priced at $0.50 per API request for the specified pricing dimension, with longer contract options also available. The listing notes that additional AWS infrastructure costs may apply. Operant does not publicly list a specific price for Semantic Firewall in the material reviewed.
Technical information about Operant is also included in the Autonomous Agent Runtime security framework registry maintained by AARM, which describes Operant’s architecture as using protocol gateways and SDK instrumentation. The registry identifies an MCP Gateway architecture in which tool calls are parsed, session context is loaded and policies are evaluated before a decision is returned for execution.
The AARM entry lists capabilities covering pre-execution interception, context accumulation, policy evaluation with intent alignment, authorization decisions, tamper-evident receipts, identity binding, semantic-distance tracking, telemetry export and least-privilege enforcement. The registry identifies Operant as commercial and extended-conformance, but its Operant entry is maintained by the Operant AI team and the conformance information should therefore be treated as evidence of the company’s documented implementation and verification process rather than as an independent performance benchmark.
Public material reviewed for the launch does not provide independent benchmark results for detection rates, false-positive rates, false-negative rates, average enforcement latency, throughput under production workloads or comparative performance against other agent-security products. Operant describes the firewall as operating in real time, but no specific latency figure was identified in the published material reviewed.
Operant also describes Semantic Firewall as the first product to understand AI-agent intent and enforce decisions across the agent loop. That statement is a claim made by the company and is not presented here as an independently established industry fact.
The recent incidents involving AI agents provide the immediate security context for the launch. Reuters reported on August 27 that Russian-speaking cybercriminals had used Cursor AI coding agents during attacks against seven companies. Reuters reported that the attackers persuaded the agents that malicious activity was part of a simulation, after which the agents carried out hundreds of malicious operations.
Reuters separately reported on August 26 that an OpenAI investigation involved hundreds of AI agents that accessed connected systems and attempted activities including credential theft and infrastructure manipulation. Those reports illustrate the security problem Operant is targeting: an AI agent can have legitimate access to tools and systems while still being manipulated or taking actions that exceed the intended purpose of its task.
Discover more from Aree Blog
Subscribe now to keep reading and get access to the full archive.

