Aug 7, 2026
Enterprise

Menlo Security expands MARS for AI agent security

Menlo Security has expanded MARS to govern agent web activity, but independent evidence of its effectiveness was not disclosed.

Dominic Okoye

By Dominic Okoye · Staff Writer

· 3 min read

Menlo Security expands MARS for AI agent security
Photo: SiliconANGLE

Menlo Security MARS AI agent security now covers AI assistants, coding agents and autonomous agents, the company said Aug. 5. The expansion places a browser-security control layer between agents and the pages or files they consume, targeting prompt injection and data leakage as enterprises give software agents access to work systems and data.

Menlo did not disclose pricing, availability details, customer deployments or independent testing results for the expanded product. The company said MARS was introduced earlier in 2026 and runs on its existing cloud-based Browser Security Platform.

The named targets include Microsoft Copilot, Gemini in Chrome, Claude Code and Claude Cowork, as well as autonomous agents that need web access. Menlo says agents send web and file activity through MARS, which runs that activity in the Menlo Cloud before content reaches the agent.

How does Menlo Security MARS protect AI agents?

The product is designed to screen the material an agent reads and constrain what the agent can access or send elsewhere. This addresses indirect prompt injection, where malicious instructions are embedded in content that an agent treats as data, including white-on-white web text, file metadata or other content a human may not notice.

Menlo says MARS provides five groups of controls:

  • removal of hidden instructions and other suspect content from web pages;
  • sanitization of files, including downloads and uploads, before an agent consumes them;
  • per-agent access policies and data-loss-prevention controls that can mask sensitive information;
  • token-based authentication and attribution for agents initiating browser sessions; and
  • activity logs, session recordings and a capability for security teams to take over a live agent session.

Menlo also says the system can give agents controlled access to data held behind web interfaces that lack adequate APIs. That proposition puts MARS beyond a narrowly defined prompt-filtering tool: it would act as both a security checkpoint and a browser-mediated access route for agent workflows. Those capability and outcome claims come from Menlo; the available materials do not include an independent evaluation or comparative test.

For security teams, the practical question is whether agent-specific controls can be added to the broader enterprise security program without creating a separate set of permissions and audit trails. Menlo says it applies the same underlying policy framework to human employees and agents, while offering controls tied to each agent.

Ramin Farassat, Menlo's chief product officer, told SiliconANGLE that agents can be manipulated into actions they were not intended to take and may expose data they can access. He also cautioned that no prompt-injection technology will be “100% safe and complete” against every threat. That is a material constraint on the category's claims: content filtering, access policy and auditability can reduce exposure, but do not establish that an agent workflow is immune to manipulation.

Security Boulevard reported that the rate of production AI-agent deployment remains unclear and that adoption may be advancing faster than security teams can secure it. Menlo's release is an attempt to make browser activity the enforcement point as companies connect agents to files, SaaS applications and web-based workflows.

This story draws on original reporting from SiliconANGLE.

More from Enterprise

All Enterprise →