Varonis is proud to be named Pace Setter in the Gartner® Emerging Market Quadrant for AI Application Security, recognized for our approach to securing AI applications across the entire development and deployment lifecycle.
We believe this recognition is especially meaningful for organizations that need AI security they can use now, not capabilities that are still on the roadmap. Pace Setters are vendors with strong existing capabilities across mandatory AI application security functions, including discovery and inventory, runtime defense, and AI security testing. This matters because enterprises moving quickly with AI need security controls that can deliver rapid time to value, provide immediate coverage for enterprise AI use, and support production environments with reliability and readiness.
As organizations push to rapidly adopt AI-powered applications, the attack surface is expanding faster than most security programs can keep up. Sensitive data now flows through training pipelines, system prompts, agent permissions, and the dozens of tools developers use to build and ship AI, often with little to no visibility or control. We believe this recognition reflects Varonis Atlas's ability to close that gap and validates the growing demand for security platforms that can discover, govern, and protect data across the full AI lifecycle.
Varonis Atlas is purpose-built to address this shift, bringing deep data visibility, automated remediation, and contextual intelligence to AI environments, from the first line of training code to production runtime.
The new AI attack surface: data, prompts, models, and agents
AI applications introduce risks that extend beyond infrastructure and identities and into data, prompts, models, and outputs. Hundreds of thousands of organizations are now building AI applications, and the pace of development is outrunning the pace of security.
Unlike traditional software, data isn't just an input for AI applications; it determines how those applications behave. That reshapes the attack surface. Credentials that authenticate AI services, the system prompts that define agent behavior, and the training data that shapes model output all flow through the development cycle and into production, often outside the reach of conventional AppSec tooling.
The security risks show up in a few consistent ways:
- Training data and retrieval sources pull from production, so a single leaked credential can expose everything an AI agent is trained on or can query, not just one database.
- System prompts and model configurations, stored in repos and wikis, describe internal policies and data schemas, effectively handing attackers a roadmap of what they can exploit.
- AI agents are overprivileged by design. The broad access scopes granted during development often persist unchanged into production, where they carry real consequences. This is already happening, with a recent example that involved an AI agent with excessive permissions and no runtime guardrails that deleted its own operator's inbox, despite explicit instructions to ask first.
Traditional security approaches lack visibility into how sensitive data is used by AI, cannot enforce policy across dynamic AI workflows, and were never designed to detect misuse or overexposure in AI-driven environments. Legacy AppSec tools are good at finding secrets in code and scanning for known vulnerabilities, but they have no visibility into system prompts pasted into Confluence, excessive permissions granted to agents, or proprietary configurations pasted into ChatGPT for debugging.
Securing AI development means protecting sensitive data and configurations everywhere developers actually work: repos, wikis, issue trackers, artifact registries, and AI assistants, not just source code.
Securing AI through data-first architecture with Varonis
Every one of those insights, from a leaked credential in a repo an overprivileged agent in production, feeds into the same data security posture management (DSPM) functions your team already relies on through Varonis DSP. AI risk doesn't sit in a separate silo; it shows up alongside the rest of your sensitive data risk, with the same automated remediation and reporting you get across the platform.
Varonis Atlas: built to disrupt AI security
Atlas represents Varonis' next evolution in data security, designed to address the complexity of AI-driven environments end to end. It provides:
- Unified visibility across AI data flows, from development through production.
- Context-aware risk detection that understands how sensitive data, credentials, and permissions move through AI systems.
- AI security testing, including AI pen testing that proactively stress-tests systems for vulnerabilities like prompt injection and jailbreaks.
- Real-time runtime guardrails through an AI Gateway that inspects prompts, responses, and agent actions before they reach the model.
- Automated enforcement and integration with the broader Varonis platform.
Across the board, Varonis gives security teams a single place to answer the questions that matter: What sensitive data sits in the repos where an AI system was built? What credentials are embedded in the images running AI agents? What data have developers shared with external AI assistants? Who can access the documentation describing an agent's permission scopes? If those questions can't be answered today, the underlying AI systems most likely carry baked-in vulnerabilities.
AI is transforming how organizations build and operate, and security has to evolve just as quickly. Varonis is committed to leading that shift with Atlas, and to continuing to innovate at the intersection of data, AI, and security.
Gartner, Emerging Market Quadrant for AI Application Security — Established Vendors, Meghan Hollis, Dionisio Zumerle, Dennis Xu, Marissa Schmidt, 14 September 2026.
Gartner and Magic Quadrant are trademarks of Gartner, Inc. and/or its affiliates.
Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.
Ready to secure everything you build and run with AI?
Below are three ways to continue your journey to reduce AI and data risk at your company:
See how Varonis secures AI environments: Schedule a demo of Varonis Atlas to understand what AI agents.