Salt Security Launches First AWS WAF Ruleset for AI Agent and API Protection

  • Salt Security launched Salt Managed Rules for AWS WAF, the first managed ruleset designed to protect both APIs and AI agents.
  • The solution is available in AWS Marketplace and can be attached to existing web ACLs directly from the AWS console.
  • Key features include advanced API threat detection, industry-first Model Context Protocol (MCP) awareness, context-aware rate limiting, and security signal enrichment.
  • The announcement was made at Black Hat USA 2026.

Salt Security's new managed ruleset addresses a critical gap in traditional WAF solutions, which were not designed to handle the behavioral nuances of APIs or the dynamic nature of AI-powered agents. This launch comes at a time when APIs are powering nearly every digital experience and AI agents are becoming a significant source of API traffic. The recent Hugging Face incident highlights the growing need for specialized security measures in this evolving landscape.

Adoption Pace
How quickly enterprises will integrate Salt's managed ruleset into their existing AWS WAF deployments.
Competitive Response
Whether competitors will introduce similar AI agent and API protection solutions for AWS WAF.
Threat Landscape
The pace at which new attack vectors targeting APIs and AI agents emerge, necessitating further updates to security rulesets.