- 100 pre-built policies now available in Salt Security's Policy Hub for AI governance.
- 61 policies activate automatically, providing instant protection.
- Policies mapped across 8 major compliance frameworks, including PCI DSS, FedRAMP, SOC 2, and GDPR.
Experts would likely conclude that Salt Security’s expanded Policy Hub offers a critical, operational solution for enterprises struggling to govern autonomous AI agents, bridging the gap between innovation and security.
Salt Security Answers the AI Governance Question with 100-Policy Hub
PALO ALTO, CA – July 20, 2026 – As enterprises deploy thousands of autonomous AI agents across their operations, a critical question echoes through boardrooms and security operations centers: How do we govern them? Salt Security, a company that built its name on securing the APIs that connect modern software, today announced a significant answer to that question, revealing its Policy Hub has reached 100 pre-built policies for agentic AI governance. The move effectively creates what the company calls the industry's first "app store" for securing the complex ecosystem that powers autonomous AI.
The announcement addresses a growing anxiety in the corporate world. AI agents, unlike static models, can reason, plan, and take autonomous action by leveraging an enterprise's existing infrastructure. They rely on Application Programming Interfaces (APIs) to access data and execute tasks, turning the very systems companies have spent years securing into a potential attack vector. This has blurred the lines between API security and AI governance, creating a dangerous blind spot for organizations racing to innovate.
A CISO's Playbook for the Agentic Era
For Chief Information Security Officers (CISOs), the rapid, often decentralized adoption of AI agents presents a daunting challenge. The pressure to enable business velocity is immense, but the security frameworks to manage the associated risks have lagged. "The board question CISOs are being asked right now is not whether we have AI governance. It is whether we can prove it," said Aner Gelman, VP of Products at Salt Security. Until now, proving it often meant embarking on a long, resource-intensive journey to build a governance program from scratch.
Salt Security aims to eliminate that barrier to entry. Its expanded Policy Hub provides a comprehensive library of policies that can be activated immediately. According to the company, 61 of the 100 policies activate automatically out-of-the-box, providing an instant layer of protection. More than a dozen are purpose-built for the unique threats posed by AI, covering Model Context Protocol (MCP) server configurations, agent authorization, and anomalous agent behavior.
"When we launched the Policy Hub in 2024, the most common thing we heard from CISOs was: we know we need posture governance, but we have no idea where to start," explained Michael Callahan, Salt Security's VP of Strategy and CMO. "That question was killing governance programs before they launched. 100 policies means that question now has a concrete answer."
This out-of-the-box approach is designed to give security teams a tangible playbook on day one. The policies are mapped across eight major compliance frameworks—including PCI DSS, FedRAMP, SOC 2, and GDPR—allowing organizations to not only secure their AI initiatives but also demonstrate adherence to regulatory mandates. For CISOs, this transforms the abstract challenge of AI governance into a concrete, operational program that is active from the moment of deployment.
Redefining Security: From APIs to the Agentic Graph
Salt Security's strategic evolution from a pure-play API security vendor to a broader agentic security leader highlights a fundamental shift in the cybersecurity landscape. While competitors like Akamai and Cequence Security have focused heavily on the API runtime protection market, Salt is making a concerted push to define and secure the entire agentic ecosystem. The company refers to this interconnected web of Large Language Models (LLMs), MCP servers, APIs, and enterprise systems as the "Agentic Security Graph."
Securing this graph requires more than just protecting individual APIs. It demands a holistic governance model that understands the context and behavior of autonomous agents. An over-privileged agent, an insecurely configured MCP server, or an API that unintentionally exposes sensitive data can become a critical vulnerability when leveraged by a powerful AI. Salt's platform is designed to provide full visibility and governance across this entire stack, moving from runtime threat detection to proactive posture management.
This strategy has been built methodically. The company's introduction of MCP server discovery in September 2025 was a key step, allowing organizations to identify and classify the crucial communication hubs that AI agents use. The development of corresponding governance policies followed naturally. More recently, the launch of Salt Code in June 2026 extended this governance model into the software development lifecycle itself, applying security policies to AI-generated code as it's being written. This "shift-left" approach aims to embed security into the DNA of AI applications, not just bolt it on at the end.
The 'App Store' Model for Enterprise Governance
The positioning of the Policy Hub as an "app store" is more than just marketing; it signals a new paradigm for deploying enterprise-grade security. Much like a consumer app store provides a trusted, curated, and easy-to-use source for software, Salt's model aims to democratize access to complex security governance. Instead of requiring deep specialization to write policies, security teams can browse a library of proven controls and activate them with a single click.
This approach stands in contrast to more traditional AI governance platforms from vendors like Credo AI or IBM, which often focus on policy management and regulatory documentation across the AI lifecycle. Salt's focus is on providing a pre-populated, operational set of technical controls specifically for the agentic stack. The platform also allows for the creation of unlimited custom policies, offering a crucial blend of standardization and flexibility that enterprises with unique risk profiles require.
By simplifying deployment, Salt is betting it can accelerate the secure adoption of autonomous AI. For many organizations, the complexity of governance has been a primary inhibitor. "A concrete, operational answer to that question" of provable governance, as Gelman puts it, could unlock significant innovation by giving businesses the confidence to move forward. This model of delivering ready-made, adaptable security could become a standard for how governance is managed in the fast-paced world of AI, where the threat landscape evolves daily and the time to build defenses from the ground up no longer exists.
As regulatory bodies from the EU to the U.S. government finalize frameworks like the EU AI Act and the NIST AI Risk Management Framework, the need for auditable, provable governance will only intensify. Solutions that provide a clear, operational path to compliance will not just be a competitive advantage, but a business necessity. With its expanded Policy Hub, Salt Security has laid down a significant marker, offering a tangible framework for enterprises to navigate the powerful but perilous agentic era.
Topics & Related
AI & Machine Learning
AI Governance
📝 This article is still being updated
Are you a relevant expert who could contribute your opinion or insights to this article? We'd love to hear from you. We will give you full credit for your contribution.
Contribute Your Expertise →