[Glossary]

AIDR (AI Detection and Response)

AIDR (AI Detection and Response) is the practice of detecting, investigating, and responding to threats targeting and originating from AI systems at runtime, while models and agents are actively working, rather than before or after.

The category is the AI-era counterpart to endpoint detection and response (EDR). Where EDR monitors processes on a machine, AIDR monitors the prompts, responses, and tool calls flowing between users, agents, models, and MCP servers. Threats run in both directions: attacks that target AI systems, such as prompt injection, jailbreaks, and poisoned tool descriptions, and threats that originate from them, such as an agent leaking secrets in a prompt or executing a manipulated tool call against internal systems.

AIDR emerged because agentic AI acts at machine speed. Posture and governance tools work before the action, setting policy and assessing risk. Logs and forensics work after it. Neither can intervene in the seconds during which an agent reads data, calls a tool, or sends content to an external model, so a distinct runtime discipline formed to fill the gap.

In practice, an AIDR capability combines three elements: runtime inspection of AI traffic, visibility across every surface where AI runs (browser, desktop apps, coding agents, CLIs, MCP servers), and the ability to respond at the point of execution by blocking, redacting, or quarantining. For the full picture of the category, what it requires, and how it compares to adjacent tools, read What is AIDR? AI Detection and Response.

[Related]

Go deeper

[Get started]

See AIDR in action.

Cerbera detects and responds to AI threats at runtime, across browser, desktop, coding agents, CLIs, and MCP, from one transparent proxy deployed through your MDM.

Book a demo