[Buyer's guide]

AI security categories, compared

AI-SPM, AI firewalls, AI DLP, AI governance, AIDR: five categories, a lot of overlapping marketing. Here is what each one actually does, what it cannot do, and the questions that cut through a vendor pitch.

·Security, CISOs, IT leaders·10 min·All levels

[Key takeaways]

  • AI security tools split into two halves: those that describe and direct (posture, governance) and those that observe and act at runtime (firewalls, DLP, AIDR).
  • AI-SPM finds and assesses AI assets before they run; it cannot stop a prompt or a tool call in flight.
  • AI firewalls and AI DLP are runtime controls, and their value depends entirely on which surfaces they can actually see.
  • AIDR is the umbrella discipline: detect, investigate, and respond to AI threats at the moment of execution.
  • Evaluate vendors on where inspection runs, which surfaces it covers, and what infrastructure they require you to adopt first.

Why the category names are confusing

AI security is a young market, and young markets name themselves badly. Analysts, incumbents, and startups have each coined categories that overlap, and most products span more than one. The result is that two vendors using the same acronym can sell very different things, and two vendors using different acronyms can sell nearly the same thing.

The clarifying move is to sort every tool by when it acts. Posture and governance tools act around AI usage: before it, to inventory and set policy, and after it, to report and prove compliance. Runtime tools act during AI usage: they sit in the traffic path and inspect or block individual prompts and tool calls as they happen. No amount of posture makes up for a missing runtime control, and no runtime control replaces the policy and evidence work. Most organizations need both halves; the buying question is how many products, agents, and consoles that should take.

The five categories

AI-SPM (AI security posture management) extends the posture-management idea from cloud (CSPM) to AI. It discovers AI assets, models, training data, pipelines, and agents, then flags risky configurations, excessive permissions, and exposed data paths. It answers "what AI do we have and how risky is it?" It does not sit in the traffic path, so it cannot intervene while any of that AI is running.

AI firewalls are runtime controls. They inspect prompts, responses, and tool calls inline and block what breaks policy: prompt injection, jailbreaks, unapproved models, unsafe output. The word covers a wide range of architectures, from an API gateway in front of one sanctioned model to an endpoint proxy in front of everything, and the architecture determines what the firewall can actually see.

AI DLP applies data loss prevention at the prompt layer: detecting secrets, source code, and regulated data in AI-bound content and redacting or blocking it before it reaches a model. It is the control that stops the pasted customer database. It concerns data leaving; it says nothing about what an agent is being manipulated into doing.

AI governance platforms manage the paperwork of responsible AI: use-case approvals, risk registers, model documentation, and evidence for frameworks like ISO 42001 and the EU AI Act. They are systems of record, not systems of enforcement. A governance platform with no runtime control attached is a policy binder describing behavior it cannot verify.

AIDR (AI detection and response) is the newest label and the broadest of the runtime categories: detecting, investigating, and responding to threats targeting and originating from AI systems at runtime. Where a firewall names a control and DLP names a data outcome, AIDR names the discipline, the AI counterpart to EDR. In practice, inline inspection (firewall) and content redaction (DLP) are the mechanisms an AIDR product uses to detect and respond. The full argument for the category is in What is AIDR?

Side by side

The table below compares the five categories on what they do, where each one stops, and where Cerbera sits in each. Cerbera is not an AI-SPM or a governance platform; it spans the firewall, DLP, discovery, and runtime-enforcement columns from a single endpoint proxy, and feeds the posture and governance tools you already use.

CategoryWhat it doesWhat it cannot doWhere Cerbera fits
AI-SPMInventories AI assets (models, datasets, pipelines, agents) and assesses their configuration and risk posture before anything runs.Act while AI is running. A posture finding cannot stop a prompt, a tool call, or a leak in progress.Cerbera's discovery inventories every AI tool, agent, and MCP server actually in use on endpoints, then adds the runtime layer posture tools stop at.
AI firewallInspects prompts, responses, and tool calls inline and blocks what breaks policy: injections, unapproved models, unsafe output.See surfaces it does not sit in front of. A gateway that only covers sanctioned API routes misses the browser, desktop apps, and CLIs.Cerbera is an AI firewall at its core: one transparent proxy on the endpoint inspecting every surface, browser to CLI to MCP, on the same path.
AI DLPDetects secrets, source code, PII, and regulated data in AI-bound content, then redacts or blocks it before it reaches a model.Govern what agents do. Data leaving is one risk; a manipulated tool call acting on your systems is another, and DLP does not see it.Cerbera does prompt-level DLP with detection running locally on the device, across every surface, so raw prompts are not shipped to a cloud to be scanned.
AI governanceManages AI policy, risk registers, approvals, and compliance evidence for frameworks like ISO 42001 and the EU AI Act.Enforce anything by itself. A policy document does not stop a prompt; it needs a runtime control to make it real.Cerbera's managed policy engine turns runtime events into audit-ready evidence, complementing governance platforms rather than replacing them.
AIDRDetects, investigates, and responds to threats targeting and originating from AI systems at runtime: the detection-and-response discipline applied to AI.Replace posture reviews or governance paperwork entirely. It acts during execution; you still decide policy before and report after.Cerbera is endpoint-first AIDR: see every AI in use, detect threats in every prompt and tool call, respond by blocking, redacting, or quarantining inline.

Two honest caveats when reading any table like this one. First, category boundaries are blurrier in real products than in analyst diagrams; judge the product against your requirements, not its label. Second, overlap is not redundancy: a firewall that cannot see the terminal and an AIDR product that can are different purchases wearing similar names.

How to evaluate vendors

Whatever a product calls itself, five questions expose what it will actually do for you. Put them in your RFP and insist on demonstrations, not roadmap answers.

1. Does it act at runtime? Ask the vendor to show a secret being redacted or a tool call being blocked live, in the moment it happens. Dashboards that report yesterday's incidents are posture tools, whatever the label says. With agents acting at machine speed, after the fact is too late by definition.

2. Does it see the terminal and the CLI, not just the browser? The highest-volume AI data flows on a developer machine come from coding agents and CLIs reading repositories and environment files. A browser extension cannot see any of it. Ask for the full list of covered surfaces: browser, desktop apps, IDE agents, terminal CLIs, and MCP connections, and how each one is covered.

3. Does inspection happen on-device or in a vendor cloud? If every prompt is shipped to the vendor's cloud to be scanned, your most sensitive content now has a second home, and the DLP tool has become its own exfiltration path. On-device inspection means raw prompts never leave the endpoint by default. Ask where detection executes and what leaves the machine.

4. Does it require a platform migration? Some runtime AI controls only ship as modules of an endpoint platform or a network security stack, so the real price includes an EDR replacement or a SASE rollout. Ask what has to change in your environment: which agents are installed or replaced, how traffic is rerouted, and how long deployment took at a comparable customer. An afternoon through your existing MDM and a quarter of re-architecture are different projects.

5. Who maintains the rules? AI threats move monthly: new models, new clients, new MCP servers, new injection techniques. If your team writes and updates every detection, the product's real cost is a standing engineering commitment. Ask whether policies are authored and kept current by the vendor, how often detections update, and what happens when a new AI tool appears in your fleet unannounced.

Score candidates against these five before comparing prices. A tool that fails question one is not a runtime control at all, and a tool that fails question four costs whatever the migration costs, not whatever the invoice says.

[Related]

Keep reading

[Get started]

Four categories, one proxy

Cerbera combines AI firewall, prompt-level DLP, shadow AI discovery, and runtime enforcement in a single transparent proxy, deployed through your existing MDM in an afternoon.

Book a demo