Comparison · agent governance · Gray Swan

Gray Swan, measured.

Gray Swan red-teams AI systems before they ship and filters their model traffic once they run. This page scores that architecture across 16 capabilities against the same capabilities in Agen.co — with the sources, the scoring ladder, and the three rows Gray Swan wins all on the page.

The short answer

  • Gray Swan's runtime product, Cygnal, is a proxy in front of the model. Change the base URL and every request and response, tool calls included, is classified inline; a violation cuts the response and returns a refusal.
  • The verdict is about the conversation. It answers whether the input is a jailbreak or an injection, and whether the output breaks a policy. It does not answer whose action this is: requests carry an organisation API key, not a user.
  • They win three rows of sixteen. Adversarial testing before an agent ships is the clearest — Shade runs attack campaigns in your deployment context, fed by a network of more than fifteen thousand red teamers. They also take prompt-injection detection and ecosystem reach.
  • Four rows are level: agents built on any model provider, customer-facing traffic, time to first coverage, and a deployment model that runs as SaaS, on-premises or in your VPC.
  • Coverage starts when a team routes an application through Cygnal. No discovery, no device or browser control point and no named owner per agent are documented. Agen discovers agents agentlessly and attributes every action to the human accountable for it.
  • Agen governs the action an agent takes against your systems, in under 30ms, wherever it runs. The two sit at different points and can run side by side.
The long read

What Gray Swan's verdict knows.

Two products can both stop something inline and still be answering different questions. Gray Swan asks whether what the model is being told, or is about to say, is an attack or a policy breach. That is a hard question and they answer it with frontier-lab rigour. It is not the same question as whether this agent may take this action on behalf of that person.


Three products, one research lineage

Gray Swan came out of a decade of adversarial-AI research, and the product is organised around the attacks that research produces.

  • Cygnalruntime protection delivered as a drop-in proxy. An application points its model client at Cygnal instead of the provider, and inputs and outputs are classified against your policy before they pass. Policies are categories of natural-language rules, each set to block or to observe, with thresholds for violations and jailbreaks.
  • Shadeautomated red teaming. An adversarial agent runs adaptive attack campaigns against your model, your guardrails and your deployment context, and returns findings with reproductions and severity ratings that can become Cygnal detection rules.
  • Arenaa public red-teaming network of more than fifteen thousand researchers breaking frontier models in competitions. It is the threat intelligence that keeps Shade's attacks and Cygnal's classifiers current.

It works with any OpenAI-compatible provider, needs no SDK change, and deploys as SaaS, on-premises or inside your VPC.

Where Gray Swan is strongest

Three of the sixteen rows below go to Gray Swan and four are level. They follow from where each product puts its decision: Gray Swan inside the conversation with the model, Agen at the action the agent takes.

  • Adversarial testing before productionShade and the Arena together are a red-teaming capability few vendors can match. We govern agents once they act, which is what lets one policy reach every agent regardless of how it was tested.
  • Prompt-injection and jailbreak detectionclassifiers trained on the attacks that work against current frontier models, including indirect injection through tool results. We judge the action rather than the prompt, and run alongside whatever inspects the prompt.
  • Ecosystem reacha native Snowflake integration, a global systems-integrator partnership and cloud and reseller programmes give them a wider distribution footprint than ours today.
  • Level on deployment and time to valuea base-URL swap, any model provider, SaaS or self-hosted, and inline on customer-facing traffic. These rows are level, and they are printed that way.

Where the model path ends

An agent does two kinds of things. It talks to a model, and it acts on a system — updates a record, sends a message, moves money, calls an internal API. Cygnal sees the first directly, and the second where it passes through the model as a tool call. Gray Swan documents it monitoring every prompt, response and tool call, sitting between an agent and the tools it calls, and catching unauthorised tool use; tool results coming back are checked for indirect injection, and the monitor API classifies whatever conversation an application sends it. In each case the verdict is on traffic a team has chosen to route, so an action the agent takes through credentials it already holds, on a path nobody pointed at Cygnal, is judged only if that call was sent for a verdict.

That is where the architecture draws its line, and it is why runtime enforcement scores a 3 rather than a 5: real inline blocking, tool calls included, on the traffic that crosses the proxy. Coverage follows the same rule. An agent is governed once a team routes it there, so an agent nobody routed — on a laptop, in a browser, or bought rather than built — is outside it.

A policy is not an owner

A Cygnal request authenticates with an organisation API key and names a policy, or an agent ID that loads one. Policies apply across the organisation. Every classification is logged and explainable, and the record says which rule fired and why.

What the record does not carry is a person. No user field is documented on the request and no owner is recorded against an agent, so when an action needs answering for, the log says what was blocked but not who it belonged to. A verdict tells you the conversation was safe. Accountability needs the human behind the agent.

Three questions to ask of a Cygnal verdict

Cygnal's classifier quality is not in question, so the useful way to read it against Agen is to ask what each verdict it returns can be used for. The table is organised around the same three questions.

  • Be at runtimeis there a decision at the moment the agent acts on a system? For traffic routed through the Cygnal proxy, tool calls included, there is. The question is the action on a path nobody pointed at it.
  • Know the identitycan the verdict be resolved to a named, accountable human? A Cygnal verdict names a policy and, where the header is set, an agent ID. The organisation API key stands where a person would.
  • Cover everythingdoes it reach the agents nobody changed a base URL for: the ones on a laptop, the ones in a browser, and the ones bought as a product rather than built on a model client?

Running it is the fourth group, and the one where Gray Swan scores best: a base-URL swap with no SDK change, any OpenAI-compatible provider, SaaS or self-hosted, and a native Snowflake integration. Gray Swan publishes no pricing, so cost is left off the table rather than guessed.

The scored comparison

Sixteen capabilities, scored side by side.

Runtime enforcement, identity and accountability, coverage, and what it costs to operate — each scored 0–5 on capability depth against vendor documentation, including the three rows Gray Swan wins.

Capability depthNoneCompleteGray SwanAgen.co
01 · Runtime enforcement
Verdict rendered at the moment of actionGray SwanTool calls inline, on routed trafficCapable3/5Agen.coPer-action verdicts, <30msComplete5/5
Decision latency, published and measuredGray SwanMilliseconds claimed, no figurePartial2/5Agen.co<30ms, published, no samplingComplete5/5
Adversarial testing of an agent before productionGray SwanShade, plus Arena's 15,000 red teamersComplete5/5Agen.coNot offeredBasic1/5
Prompt-injection and content-threat detectionGray SwanJailbreak and injection classifiersComplete5/5Agen.coAction-level, not prompt inspectionPartial2/5
02 · Identity & accountability
Agent has a first-class identity objectGray SwanAgent ID selects a policyPartial2/5Agen.coFirst-class agent identityComplete5/5
Each individual action attributed to that humanGray SwanOrg API key, no user fieldBasic1/5Agen.coAttributed per actionComplete5/5
Access evaluated at action time, not only at grant timeGray SwanContent judged, not accessPartial2/5Agen.coJudged in context, per actionComplete5/5
Audit record per actionGray SwanLogged per request, no user fieldStrong4/5Agen.coA record per actionComplete5/5
03 · Coverage
Endpoint enforcementGray SwanAPI proxy, no device presenceBasic1/5Agen.coAgenShield on the deviceComplete5/5
Browser enforcementGray SwanNo browser control documentedBasic1/5Agen.coBrowserShield, early accessCapable3/5
Agentless discovery — no SDK, no self-registrationGray SwanNo discovery; routed by base URLBasic1/5Agen.coAgentless, 5 surfaces, no SDKComplete5/5
Agents built outside the vendor's own stackGray SwanAny model provider, any SDKComplete5/5Agen.coAny agent, any stackComplete5/5
External customer-facing agentsGray SwanInline on user-facing trafficComplete5/5Agen.coCustomer-facing agents, same planeComplete5/5
04 · Operate & buy
Time to first governed agentGray SwanBase-URL swap, no SDK changesComplete5/5Agen.coDays to a first governed agentComplete5/5
Deployment model and data residencyGray SwanSaaS, on-prem, or VPCComplete5/5Agen.coSaaS, hybrid, or on-premComplete5/5
Ecosystem and marketplace breadthGray SwanSnowflake native, Deloitte, cloud partnersCapable3/5Agen.coFocused platform, not a marketplacePartial2/5
9 rows Agen.co leads4 tied3 rows Gray Swan leads
Levels reflect capability depth and supporting evidence. Capability descriptions based on vendor public documentation.
Get the walkthrough

Get the scored comparison walkthrough.

Thirty minutes, row by row, including the ones we lose to Gray Swan. You leave with the same table, scored for your environment. Tell us anything we should know in the comments.

length30 minutes
formatrow by row
commitmentnone
What the table shows

Cygnal's verdict stops at the policy and the proxy.

The scores give Cygnal its due: a 3 on runtime enforcement with tool calls inside it, three rows won outright on red teaming, injection detection and ecosystem reach, and four level on model providers, customer-facing traffic, setup time and deployment.

Two lines in its architecture account for the rest. A Cygnal verdict is attached to a policy and an organisation key, not to the human the action belongs to; and it exists only for traffic a team has pointed at the proxy or the monitor API. The cards below follow those two lines through each group of the table.

Reading the table

What Cygnal's scores mean in production.

One card per table group, read for two agents: one routed through Cygnal's proxy, and one that never was.

01

The verdict lands on the conversation

Jailbreaks, injections, policy-breaking outputs and the tool calls that cross the proxy are stopped inline, and the red teaming behind them is genuinely strong. But the verdict is made on traffic a team has routed to it, not at the system the action lands on, and no latency figure is published beyond “milliseconds”.

published latencynone
02

An API key is not an accountable human

Requests carry an organisation key and a policy or agent ID. Every classification is logged and explainable, which scores a 4 and earns it. But no user field is documented on the request and no owner is recorded against an agent, so the log cannot say whose action it was.

owner per agentnone
03

Covered once routed, invisible until then

Any model provider and any customer-facing app can be put behind the proxy in a base-URL change — a real advantage, scored level. But no discovery is documented for the agents nobody routed, and there is no control point on the device or in the browser.

agent discoverynone
04

Fast to switch on, wherever you run

No SDK change, SaaS, on-premises or VPC, and a native Snowflake integration with systems-integrator and cloud partners behind it. This is the group Gray Swan scores best in. Pricing is not published, so cost is not scored here.

published pricingnone
Watch it happen

Every action resolved to the human who answers for it.

Not an API key and not a policy — a named accountable owner carried on every agent, and every individual action attributed back to them, including the agents nobody routed anywhere.

agent ownership · live product scene
What closes the gap

Keep the red team. Govern the action.

Keep testing your models and filtering their traffic. Agen governs the layer above: every agent discovered without being routed anywhere first, every action judged against your policy at the moment it happens, every verdict resolved to the human behind the agent.

Select a capability

Continuous discovery across your IdP, gateway, devices, cloud, and registries. Nothing has to self-register: agents are found, risk-scored, and resolved to a named human before they act.

  • Agentless and API-based across five surfaces
  • First-party, custom, and third-party agents alike
  • Every agent mapped to an owner, approver, and escalation
Agen Discover AI agent discovery flow: any identity provider, productivity suites and assistants, cloud, gateway, endpoints, and MCP server registries all feed one agent registry where every AI agent is inventoried, risk-scored on arrival, given a named human owner, and shadow AI is surfaced.
Discovery pulls from five surfaces into a single agent registry — no SDK self-registration required.
ClosesWhich agents are running that nobody registered?
no SDK required5 surfacesowner-mapped
Discover in depth →

Methodology

How these scores were reached.

Twenty-nine capabilities were scored against the ladder in our internal rubric; sixteen are published here. Fifteen more were dropped and are not published on any page — some because the only finding was an absence in public documentation, which is weaker evidence than a documented limit; some, including pricing, because the vendor publishes nothing to score; and some because the two products are built so differently that the row would not have been a fair like-for-like. Each score reflects capability depth in the vendor's best available configuration.

Sources12 primary
Evidence ledger
  1. Gray Swan — platform overviewTier ACygnal for runtime enforcement, Shade for adversarial assessment and Arena as the red-teaming network; tool integration for AI connected to databases, APIs and files. No browser or device product is described.
  2. Gray Swan — CygnalTier AMonitors every prompt, response and tool call at runtime; sits inline between users and the model, between the agent and its tools, and between retrieval and content; catches unauthorised tool use and scope violations; block, flag and rewrite actions; classification in milliseconds, fast enough for user-facing traffic; SaaS, on-premises and VPC deployment; every classification logged, explainable and reviewable.
  3. Gray Swan — ShadeTier AAutonomous adversarial campaigns against models, agents and guardrails in their deployment context; findings with reproductions and severity ratings that become Cygnal detection rules.
  4. Gray Swan Docs — Cygnal completionsTier AProxy integration by changing the model client's base URL; a policy-id header, or an agent-id header that loads that agent's policy, is required; a violation cuts the response and returns a refusal with finish_reason set to violation; reasoning modes trade latency for depth.
  5. Gray Swan Docs — monitoringTier AThe monitor endpoint returns a violation probability, the rules violated with descriptions, and mutation and indirect-prompt-injection flags; tool-role messages are assessed for indirect injection.
  6. Gray Swan Docs — policiesTier APolicies are categories of natural-language rules with per-rule block or observe modes and violation and jailbreak thresholds, managed at the organisation level by admins.
  7. Gray Swan Docs — API referenceTier AEndpoints cover Cygnal monitoring and proxied completions, policy management and versioning, and activity export. No user, owner, identity or discovery resource is documented.
  8. Gray Swan — govern agent behaviorTier ABehavioural policies enforced on agent tool calls, response generation, data access and multi-step workflows, defined by role, context or workflow.
  9. Gray Swan — prevent AI data breachesTier AEvery prompt, response and tool interaction validated against custom policy in real time; exfiltration through inputs, outputs, memory and tool calls blocked.
  10. Gray Swan — partnersTier APartner programmes for global systems integrators, technology and cloud platforms, resellers and MSSPs, and research; named partners include Deloitte, Snowflake, OpenHands, AWS and Google Cloud.
  11. Gray Swan Docs — features overviewTier AWorks with OpenAI, Anthropic, Google Gemini and any OpenAI-compatible provider; change only the base URL with no SDK changes; jailbreak detection and prompt-injection prevention; continuous automated stress-testing through Shade.
  12. Gray Swan — Series A announcementTier AArena counts more than 15,000 researchers and security professionals; Shade automates red teaming; runtime protection integrates natively with Snowflake's AI ecosystem.

Vendor capabilities change. If a row is out of date or wrong, tell us and we will re-score it — corrections are published with the date they were made.

FAQ

Questions, answered.

What is Gray Swan?
Gray Swan AI is an AI security company spun out of Carnegie Mellon adversarial-AI research. It sells three things: Cygnal, a runtime proxy that classifies and blocks adversarial inputs and policy-violating outputs; Shade, an automated red-teaming agent that attacks your models, agents and guardrails in their deployment context; and Arena, a public red-teaming network of more than fifteen thousand researchers whose findings feed both.
Does Gray Swan block AI agent actions at runtime?
Yes, within a defined scope. Cygnal sits inline as a proxy in front of the model: an application changes its base URL, and each request and response is classified against your policy before it passes. A violation cuts the response and returns a refusal. Gray Swan documents Cygnal monitoring tool calls as well as prompts and responses, and tool-result content is checked for indirect prompt injection. The verdict is made on traffic an application routes to Cygnal, through the proxy or its monitor API, so an action an agent takes against a system is judged only where a team has wired in that check. The verdict records the policy applied, not a user.
How does Gray Swan identify the human behind an agent?
At the level of the organisation and the agent rather than the person. A Cygnal request authenticates with an organisation API key and either names a policy or carries an agent-id header that loads the policy configured for that agent, and policies are managed across the organisation. The documented request has no user field and an agent carries no owner, so a verdict records which policy and which agent, not which human. Agen maps every agent to a named accountable owner and attributes each individual action back to that person, autonomous runs included.
Can Agen.co run alongside Gray Swan?
Yes. Red teaming and prompt-level classification are where Gray Swan is strongest, and they sit at a different point from Agen. Gray Swan protects the conversation with the model; Agen governs the action the agent takes, in under 30ms, and resolves it to a named human. Nothing in your existing model path has to change.
Where does Gray Swan score better than Agen.co?
Three rows of sixteen outright, and four more are level. Adversarial testing before production, through Shade and the Arena. Prompt-injection and jailbreak detection. Ecosystem reach, through a native Snowflake integration and systems-integrator and cloud partners. Level with us on agents built on any model provider, on customer-facing traffic, on time to first coverage, and on deployment model.
How is Gray Swan priced?
Gray Swan does not publish pricing, so this comparison does not score it. Agen is priced per governed agent with no prerequisite tier.
Does this cover agents that are not routed through a proxy?
With Cygnal, an agent is covered once a team points its model client at the proxy. Agen discovers agents agentlessly across five surfaces — identity provider, gateway, devices, cloud and registries — so an agent does not have to be routed anywhere, enrolled, or carry an SDK to be found, owner-mapped and governed. Internal and customer-facing agents run on the same policy plane across endpoint, browser, gateway and cloud.
How current is this comparison?
Every Gray Swan score comes from Gray Swan's own product pages and API documentation, and the page is re-scored against them on a fixed internal cadence. Each published row cites at least one of the twelve primary sources listed above, so any row can be checked against the Cygnal, Shade and Arena material directly.

Bring your own comparison.

Send us the rows you would score differently. We will show you the evidence behind ours, and where we are wrong we will change the page.