
Over the past several months, I've noticed a growing conversation around "AI Firewalls," "AI Gateways," and "AI Runtime Security." A recent analyst article argued that AI firewalls aren't really firewalls at all; they're fundamentally different technologies. I think that observation is directionally correct, but it also points to a much larger shift that our industry is only beginning to recognize.
We're asking the wrong question.
The real question isn't whether enterprises need an AI firewall. It's whether runtime is becoming the next security control plane. I believe the answer is yes.
Cybersecurity has always evolved alongside computing. As applications moved onto corporate networks, we built firewalls to protect them. As identity became the new perimeter, Zero Trust transformed authentication and authorization into the primary control plane. When infrastructure became software, we created cloud-native security, policy-as-code, and cloud governance to continuously validate how systems were configured and deployed.
Each technological shift demanded a new security architecture because each fundamentally changed what needed to be protected.
AI represents the next platform shift, but it changes something far more fundamental than infrastructure or identity. It changes the nature of software itself.
For decades, software has been largely deterministic. Given the same inputs, it executes the same instructions and produces predictable outcomes. AI agents are different. They interpret context, reason through problems, invoke tools, access sensitive data, generate code, interact with APIs, and increasingly collaborate with other AI agents to accomplish complex objectives. Rather than simply executing instructions, they make decisions.
That distinction has profound implications for security.
The defining security question is no longer, "Is this software secure?" Increasingly, the question becomes, "Should this action be allowed right now?"
That is not an application security problem. It is not purely an identity problem. Nor is it simply another evolution of cloud security. It is a runtime governance problem.
For the past decade, the security industry has embraced the philosophy of "shift left." We invested heavily in scanning source code, validating infrastructure-as-code, detecting vulnerabilities before deployment, and preventing misconfigurations from reaching production. Those investments remain critical, but they were designed for software whose behavior could largely be predicted before deployment.
AI agents don't fail because their code is inherently insecure. They fail because of the decisions they make after deployment.
A perfectly secure application can still expose confidential information to an unauthorized user, invoke the wrong tool, execute an infrastructure change outside established policy, or autonomously chain together actions that no human explicitly intended. None of these failures originate from vulnerable code. They originate from runtime behavior.
This is why I believe runtime governance, not simply runtime visibility, is the foundational security discipline governing enterprise AI.
Much of today's AI security conversation focuses on observability. Organizations want visibility into prompts, model interactions, tool usage, token consumption, and agent behavior. Observability is unquestionably valuable, but visibility alone does not create security. Watching an AI system make a poor decision is not the same as preventing it from making that decision.
The next generation of AI security platforms will evolve beyond monitoring. They will become policy enforcement points that continuously evaluate every AI interaction before it is executed.
Every request will become a policy decision.
Should this identity access this model?
Should this model retrieve this data?
Should this agent invoke this tool?
Should this action require human approval?
Should this workflow continue?
Those decisions cannot be made solely during development or deployment. They must be evaluated continuously as AI systems operate in production.
One reason the market feels fragmented today is that we're trying to describe this emerging architecture using yesterday's vocabulary. We hear terms like AI Firewall, Prompt Firewall, AI Gateway, Runtime Protection, Agent Security, and Guardrails. Each describes part of the problem, but none fully captures the architectural shift underway.
I suspect we're witnessing the emergence of a broader runtime security stack.
Just as CNAPP ultimately unified multiple cloud security disciplines under a common architecture, runtime governance will likely encompass several complementary layers. One layer will govern runtime behavior within cloud infrastructure and Kubernetes environments. Another will enforce policy around model interactions, prompts, identities, and token usage. Still another will govern autonomous agents themselves; determining what they are permitted to do, which tools they may invoke, how they collaborate with other agents, and when human oversight is required.
These are not competing categories. They are complementary enforcement layers within a common runtime control plane.
Every major security platform has historically answered a different question. Firewalls asked whether traffic should enter the network. Identity platforms asked who should have access. Cloud security asked whether infrastructure was configured correctly.
Runtime governance asks an entirely new question:
Should this autonomous system be allowed to perform this action, under these circumstances, at this moment?
That may become the defining security question of the AI era.
A few years from now, I suspect we will no longer speak about "AI security" as a separate discipline. Runtime governance will simply become part of enterprise architecture, just as identity, cloud security, and application security have before it. Every AI interaction will be evaluated against organizational policy. Every autonomous action will be continuously authorized. Every AI workflow will be governed in real time.
The companies that define this market won't simply provide better visibility into AI systems. They will become the operating system for trusted AI execution.
Because in the age of autonomous software, the greatest security risk isn't that an AI generates the wrong answer.
It's that it takes the wrong action.
And the only place to govern that action is at runtime.