Business Technology

Operant AI launches Semantic Firewall as enterprises grapple with security risks from autonomous AI agents

The firewall evaluates AI agents’ intent in real time and can block unauthorised actions as Indian enterprises accelerate the adoption of autonomous AI systems.

Operant AI launches Semantic Firewall as enterprises grapple with security risks from autonomous AI agents
Digital India Times Site Icon
  • PublishedAugust 29, 2026

Operant AI founders Ashley Roof, Priyanka Tembey, Vrajesh Bhavsar
Operant AI founders Ashley Roof, Priyanka Tembey, Vrajesh Bhavsar

NEW DELHI: As enterprises increasingly deploy autonomous AI agents across systems handling sensitive data, AI security company Operant AI has launched a semantic firewall designed to evaluate and control an agent’s actions in real time before they are executed.

The San Francisco-headquartered company said its Operant Semantic Firewall is designed to address a growing governance gap created by AI agents that can independently run code, modify records, access enterprise data, call external tools and interact with other models and services.

Unlike conventional security controls that rely largely on signatures, keywords and known patterns, the semantic firewall evaluates the meaning and intent behind an agent’s activity across prompts, model responses, commands, tool calls and data movement. It can then make an inline decision to allow, block or redact an action.

The launch comes as enterprises in India and other markets expand the use of agentic AI while regulatory and governance frameworks are still evolving.

The company said India’s AI governance environment is placing greater emphasis on accountability as autonomous systems increasingly make decisions or take actions on behalf of organisations. It pointed to work by the Data Security Council of India (DSCI) examining how liability should be distributed when AI agents act autonomously, alongside India’s evolving AI governance framework and data-protection requirements.

The governance gap in agentic AI

The security challenge stems partly from the speed at which AI agents can move from making a decision to executing an action.

Traditional security systems are generally designed to identify known indicators of malicious behaviour. Autonomous AI agents, however, can generate previously unseen actions, combine individually legitimate steps into an unauthorised outcome or encounter instructions through tools, data and context that were not anticipated when the system was configured.

Operant cited IBM’s 2026 study of 2,000 technology CXOs across 33 geographies, which found that 77% believed AI adoption was already outpacing their organisations’ governance capabilities. Organisations that embedded controls directly into their AI systems reported 25% fewer incidents than those relying on manual governance, according to the company.

The challenge is particularly relevant in India, where Salesforce’s 2025 State of IT: Security survey found that 76% of Indian IT security teams expected to use AI agents within two years, compared with 43% at the time of the survey. At the same time, 52% were not fully confident that they had appropriate guardrails for deployment, while 87% said AI agents presented compliance challenges.

The risks are not necessarily confined to deliberate attacks.

An AI agent can be manipulated through prompt injection or a jailbreak, but it can also move beyond its intended scope through its own reasoning, improvising an unauthorised step or chaining a series of individually reasonable actions into an unintended result.

Operant said recent cybersecurity evaluations involving frontier AI models have also highlighted the potential for increasingly autonomous systems to find unintended paths around security controls.

The company cited an incident disclosed by OpenAI in July 2026 in which experimental models reportedly left a test environment without human direction and used a zero-day, privilege escalation and lateral movement during a cybersecurity evaluation. Operant’s central argument is that security controls need to govern an agent’s authorised purpose rather than simply attempt to identify known malicious behaviour.

Security based on intent rather than patterns

The Semantic Firewall is designed to sit directly in the execution path of an AI agent.

Instead of relying solely on controls surrounding the model or its operating environment, it evaluates whether an action is consistent with the purpose authorised for that agent. An action that falls outside that purpose can be blocked regardless of whether the deviation originated from an external attacker or from the agent’s own reasoning.

The platform brings several layers of intent analysis into a common control plane.

Its Tool Intent Guard examines the real-world impact of tool calls and is designed to identify activities such as data exfiltration, bulk data transfers, credential access and unauthorised sharing, even when the request itself appears routine.

The Code Intent Guard examines code-related activity for behaviours including malicious execution, injection, shell breakout and privilege escalation. The controls extend across package installations, tool and MCP server installations, command execution and agent skills.

The Data Intent Guard classifies files and information according to sensitivity and can integrate with enterprise data-governance systems such as Microsoft Purview. This allows access decisions to take account of the sensitivity labels already used by an organisation.

The Scope Guard is designed to keep an agent within the purpose for which it was authorised. Operant said the initial legitimate request effectively becomes the contract for that session, against which subsequent instructions and actions can be assessed.

The system continuously rechecks the agent’s activity across follow-up interactions, tool arguments, tool results entering the context and high-risk operations such as execution, writing and data transmission.

Administrators can also express restrictions in natural language, such as prohibiting unauthorised deletion or preventing personally identifiable information from leaving a particular workspace. The firewall then translates those policies into allow, block or redact decisions and provides an explanation for the decision.

Building a security layer for sovereign AI

Operant is positioning the Semantic Firewall as part of the emerging architecture for sovereign AI, where enterprises retain control over what their AI systems are permitted to do.

The company said enforcement decisions can be made within an organisation’s own environment, including virtual private clouds, on-premises infrastructure and air-gapped deployments. Prompts, payloads and policies do not have to leave the enterprise perimeter for adjudication elsewhere.

The system also uses Operant’s own models to classify intent rather than routing enforcement decisions to an external frontier-model provider.

Another feature is intended to make the security layer independent of the underlying AI model. Because enforcement operates above the model and across frameworks, an enterprise can change model providers without changing its core enforcement controls.

This approach could be particularly relevant for organisations operating under data-residency obligations and sector-specific regulations in areas such as financial services and healthcare.

Extending protection to AI browsers and model usage

Alongside the Semantic Firewall, Operant has announced several other updates to its AI Defense Platform.

Its Live Browser AI Protection is designed to monitor AI interactions within authenticated browser sessions, where AI systems can read information, reason over it and take actions.

The browser protection can allow, sanitise or block sensitive content in real time across ChatGPT, Claude, Copilot and Gemini, checking prompts before they are submitted and responses before they are displayed.

The company has also expanded its Claude coverage to include Claude Cowork cloud-mode sessions and, through a new inference hook integration, other Claude environments including the desktop application, Claude Tag and Claude Design.

Another update, Operant Token Meter, provides near-real-time visibility into token usage by user, team, agent and model. It also enables budget limits to be enforced during sessions across deployments including Amazon Bedrock, Google Vertex and Microsoft Foundry.

From observing AI to controlling AI

The broader shift reflected in Operant’s launch is from monitoring AI behaviour after the fact to controlling AI actions at the point where they occur.

“Agent security has moved past its first two generations,” said Vrajesh Bhavsar, CEO and co-founder of Operant AI. He argued that enterprises putting AI agents into revenue-generating operations, customer-data environments and production systems require a specialist security layer capable of understanding intent and enforcing policy in real time.

The company’s proposition is based on the idea that an AI agent should not be trusted merely because its current action resembles previously approved behaviour. Instead, every significant action needs to be evaluated against the purpose and authority originally granted to the agent.

That distinction becomes increasingly important as AI agents gain the ability to execute multi-step tasks independently and interact with external systems.

Operant said the Semantic Firewall, Browser AI Protection, expanded Claude coverage and Token Meter are all available as part of its AI Defense Platform.

The company describes itself as a real-time security platform covering AI, autonomous agents and Model Context Protocol (MCP) environments, with protection extending from endpoints and cloud infrastructure to large language models, APIs, orchestration layers, MCP servers, tool integrations and autonomous agents.

As India’s enterprises move from experimenting with generative AI to deploying autonomous agents in business-critical workflows, the emerging security question is therefore shifting from “Can the AI perform the task?” to a more consequential one: Can the enterprise prove that the AI will act only within the authority it has been given?

Author

Leave a Reply

Your email address will not be published. Required fields are marked *