Jul 29, 2026
Enterprise

Sweet Security Agentic AI Blocking targets rogue enterprise AI agents

Sweet Security launched Agentic AI Blocking to stop unauthorized AI agent actions in production before data or secrets leave enterprise systems.

Colin Brandt

By Colin Brandt · Enterprise Reporter

· 3 min read

Sweet Security Agentic AI Blocking targets rogue enterprise AI agents
Photo: SiliconANGLE

Sweet Security Agentic AI Blocking is the Israeli runtime security startup’s new control for stopping AI agents while they are acting inside production systems. The company said the feature extends its existing cloud workload enforcement to autonomous agents, a category where enterprises are giving software identities access to internal tools, data and workflows without a human approving each step.

Sweet did not disclose new pricing, revenue, valuation or headcount tied to the launch. The company has raised $120 million to date, including a $75 million Series B led by Evolution Equity Partners in November.

The feature is being released ahead of Black Hat USA 2026 in Las Vegas. Sweet said it will show the product at booth 5721 during the conference, which runs from Aug. 1 to Aug. 6.

What is Sweet Security Agentic AI Blocking?

Agentic AI Blocking is a runtime enforcement capability that Sweet says can terminate unauthorized agent sessions and tool calls as they happen. According to the company, it is designed to block attempts by agents to exfiltrate secrets or personally identifiable information and to stop prompt injection attacks before they change an agent’s intended behavior.

The pitch is aimed at a gap between monitoring and enforcement. Sweet argues that conventional detection can identify suspicious agent behavior only after an action has already been completed. Its claim is that security teams need a decision point during execution, especially when agents have their own identities and can touch sensitive enterprise systems.

Sweet Chief Executive and co-founder Dror Kashti said in the company’s announcement that AI has lowered the cost of attacks while placing autonomous software inside businesses. He said Sweet’s role is to decide in real time whether an agent should be allowed to carry out a given action and to give security teams a short explanation of what was found and what was blocked.

How Sweet says the blocking works

Sweet said its decisions rely on a runtime reasoning layer that evaluates more than one billion runtime events each day. The company says that analysis is used to define expected behavior for each application and agent, with actions outside that pattern treated as unauthorized.

The company also describes a process it calls a Learning Loop, built around attack, remediation and defense cycles. Sweet’s claim is that this lets customers enforce controls in live environments without disrupting normal workloads. That is the difficult part of the category: a runtime security product that blocks legitimate production activity can create its own outage risk.

Sweet said one early customer is Zoomd Technologies, an Israeli mobile advertising company. Zoomd Chief Technology Officer and co-founder Niv Sharoni said in Sweet’s announcement that the product gave the company more confidence to use AI across the business because problematic agent behavior could be stopped when it occurs rather than reviewed later in a report.

Why the launch fits Sweet’s broader platform

Sweet sells a runtime security platform for cloud workloads, identities and application programming interfaces. The company moved into AI security last year with tools for finding models and agents and observing what they connect to.

The founding team has Israeli military cyber and security backgrounds. Kashti is a retired brigadier general and former chief information security officer of the Israel Defense Forces. Co-founder Eyal Fisher previously led the cyber department at Unit 8200, and co-founder Orel Ben-Ishay ran the cybersecurity research and development center at Unit 81.

The launch puts Sweet into a fast-forming part of enterprise security: controls for nonhuman actors that can reason, call tools and move across systems. The company’s claims now depend on whether its runtime model can block genuinely risky agent behavior without breaking the production workflows those agents are being deployed to automate.

This story draws on original reporting from SiliconANGLE.

More from Enterprise

All Enterprise →