cybersecurity sdx crop hack
– Jenar/Getty Images

SentinelOne joined in the RSA cybersecurity release party with various innovations around AI agent security for both clouds environments and distributed infrastructure.

As revealed at this week's RSA 2026 event, the firm expanded autonomous AI security across its on-premises portfolio, offering data control for self-hosted and air-gapped environments. This includes protection for servers, private cloud, and data pipelines, as well as monitoring shadow AI within fully-disconnected environments via a firewall proxy.

The capabilities hinge on a "single, lightweight" agent, with organizations keeping full ownership of their data by streaming telemetry directly into their own systems for threat detection and investigations, eschewing external clouds.

The firm also promised real-time protection for private and sovereign cloud environments, securing servers, containers, and storage with autonomous, on-device detection. Integration is also included with local data storage systems from the likes of NetApp and Dell Technologies.

A new AI Data Pipeline tool was also said to optimize on-premises data flow through smart filtering, aiming to reduce alert fatigue with enriched telemetry and, again, without need for cloud processing.

“Empowering global organizations with the certainty that their data stays in their control is more urgent than ever given the need to adopt AI without compromising privacy," Ana Pinczuk, president of product and technology at SentinelOne, explained. "For too long, organizations in highly regulated sectors have faced a trade off between the speed of AI security and total data sovereignty, privacy, and control – especially for air-gapped networks. ... By delivering our most advanced autonomous engines and AI protections directly into the customer’s own hardware environment, we are giving them the freedom to innovate securely.”

Purple gain

SentinelOne also debuted new tools in its AI Security stack, including Prompt AI Agent Security, which is a shadow AI tool promising real-time governance of AI agents. Joining it is Prompt AI Red Teaming for testing AI applications, as well as general availability of Purple AI Auto Investigation, described as automating cross-stack investigations synthesizing threat data and building end-to-end attack timelines in real time.

Prompt AI Agent Security works across endpoint, cloud, and identity through the firm's Singularity Platform, covering visibility, risk assessment, and policy enforcement in each instance of a model context protocol (MCP) server.

The shift-left capabilities of Prompt AI Red Teaming simulate AI-driven prompt injections, jailbreaks, privilege escalation, and data poisoning while evaluating risks such as model drift, emerging vulnerabilities, and new attacks vectors that are inherent with the nascent nature of today's agents.

Purple AI Auto Investigation debuts under the firm's Purple AI add-on of generative AI tools, touting an agentic framework and what was described as "human-level reasoning" to prevent sophisticated attacks.

AI-native data pipelines have also been integrated into SentinelOne's security information and event management (SIEM) offering, courtesy of last fall's Observo AI acquisition. Bundled as part of Singularity AI SIEM, SentinelOne claimed to offer both pre-ingestion analytics and flexible data collection, including intelligent filtering, enrichment, and network data normalization, with a claim of reducing data noise by up to 80% prior to ingestion, and leveraging AI-detection and response across third-party data at enterprise scale.