SecurityBrief India - Technology news for CISOs & cybersecurity decision-makers
India
Menlo expands AI agent security for Copilot & Gemini

Menlo expands AI agent security for Copilot & Gemini

Thu, 6th Aug 2026 (Today)
Mark Tarre
MARK TARRE News Chief

Menlo Security has expanded Menlo Agent Runtime Security to cover AI assistants and coding agents, including Microsoft Copilot, Google Gemini in Chrome, and Claude Code. The move targets prompt injection and data exfiltration risks tied to the growing use of AI agents in business workflows.

The updated product sanitises the web pages and files agents read before they can act on the content. It applies to browser assistants, desktop assistants, coding agents, and autonomous agents that require web access.

The release reflects a broader shift in corporate security concerns as businesses move from testing large language models to connecting AI agents with email, files, websites, and internal tools. Menlo argues that the main risk now lies not only in the model itself, but also in the content and integrations around it.

According to Menlo, an AI agent can follow instructions hidden in content that a human user would not notice. Examples include white-on-white text, metadata inside files, and even a single human-invisible pixel.

Runtime focus

MARS runs web activity in the Menlo Cloud and cleans pages and files before an agent sees them. The process also covers uploads and downloads, with the aim of ensuring an agent acts only on sanitised content.

The product is designed to stop attacks before an agent carries them out, rather than detect the activity afterwards. Menlo describes this as a runtime control for agent behaviour rather than a model-level safeguard.

Menlo lists five main features in the updated release: removal of hidden instructions from web pages and files, sanitisation of documents from sources such as SharePoint and OneDrive, data protection controls for agents, token-based agent authentication, and activity logging with session recording.

Those controls are intended to extend the same policy framework used for human employees to AI agents. Security teams can apply granular policies to individual agents, including limits on which websites and applications each can access.

Market pressure

The launch comes as analysts and security researchers warn that prompt injection is becoming a central problem for enterprise AI deployments. Menlo cited Mandiant research that identified prompt injection as a leading threat to AI applications, while Gartner has projected rapid growth in task-specific AI agents across enterprise software.

That growth has left many organisations trying to balance adoption with governance. In customer discussions over recent months, Menlo said repeated concerns centred on assistants with broad access to email and files, low-code agents using employee credentials, coding agents exposing source code, and autonomous agents operating on the open web.

Bill Robbins, Chief Executive Officer at Menlo Security, said the product is intended to address those concerns at the point where agents interact with content and business systems.

"Every enterprise is racing to put AI agents to work, but agents operate at machine speed without human skepticism," Robbins said. "They live in the browser and the everyday tools our teams rely on, which is exactly where attackers are aiming. MARS provides the essential runtime guardrails so security teams can confidently say yes to agentic AI instead of standing in its way."

Broader platform

MARS was introduced earlier this year as a cloud-based browser security product for AI assistants, coding agents, and autonomous agents. The latest expansion broadens that remit to specific tools businesses are already adopting, including Microsoft Copilot, Gemini in Chrome, Claude Code, and Claude Cowork.

The system provides per-agent attribution for policy and visibility, alongside live browser session takeover for security teams and a tamper-proof record of the content an agent saw and acted on, Menlo said. The company added that the product's design aligns with emerging frameworks and guidelines covering AI risk and agentic systems.

Menlo has framed the release as an attempt to fill what it sees as a gap between blocking AI agents outright and relying on built-in safeguards from model and application providers. Its position is that enterprises need controls over what an agent reads and what data it can access or transmit once connected to real tools and information sources.

Menlo said more than 70 customer conversations informed its approach, with repeated concerns focused on assistants with broad access to business data, coding agents that could expose proprietary code, and autonomous agents operating with limited human oversight.