Salt Security Launches First AWS WAF Ruleset for AI Agent and API Protection
Event summary
- Salt Security launched Salt Managed Rules for AWS WAF, the first managed ruleset designed to protect both APIs and AI agents.
- The solution is available in AWS Marketplace and can be attached to existing web ACLs directly from the AWS console.
- Key features include advanced API threat detection, industry-first Model Context Protocol (MCP) awareness, context-aware rate limiting, and security signal enrichment.
- The announcement was made at Black Hat USA 2026.
The big picture
Salt Security's new managed ruleset addresses a critical gap in traditional WAF solutions, which were not designed to handle the behavioral nuances of APIs or the dynamic nature of AI-powered agents. This launch comes at a time when APIs are powering nearly every digital experience and AI agents are becoming a significant source of API traffic. The recent Hugging Face incident highlights the growing need for specialized security measures in this evolving landscape.
What we're watching
- Adoption Pace
- How quickly enterprises will integrate Salt's managed ruleset into their existing AWS WAF deployments.
- Competitive Response
- Whether competitors will introduce similar AI agent and API protection solutions for AWS WAF.
- Threat Landscape
- The pace at which new attack vectors targeting APIs and AI agents emerge, necessitating further updates to security rulesets.
Related topics
