What Wiz sees, and what it decides.
Wiz earned its place by seeing a whole cloud estate without installing anything and turning what it found into attack paths a team can act on. Its AI security applies that same method to models and agents. It is a strong answer to which AI exists and what it could reach. It is a different question from whether this agent may take this action, now, for that person.
How Wiz packages AI security
Wiz sells three products, Wiz Cloud, Wiz Code and Wiz Defend, and its AI coverage runs through all of them. Since the Google acquisition closed it operates as Wiz inside Google Cloud, under its own brand, and still covers AWS, Azure and Oracle Cloud alongside Google's.
- AI-SPMagentless discovery of AI services, models, agents and MCP connections, built-in rules for AI misconfigurations, exposed inference endpoints, and AI attack paths drawn on the Security Graph across identity, network, data and vulnerabilities.
- AI-BOMan inventory of the components inside AI systems: models, frameworks such as LangChain, SDKs, libraries and AI IDE extensions, with shadow AI flagged next to sanctioned tools.
- AI-APPthe umbrella for securing AI applications from code to runtime: agents found in managed services and agent studios, custom agents found through code and workload analysis, and the tools each agent can call classified by what they can do.
- Wiz Defend and the Wiz Sensordetection and response built from cloud logs, runtime signals and Security Graph context. An eBPF sensor, sold as an add-on, watches workloads and can block threats on them, and a sensor for developer workstations is in private preview.
Where Wiz is strongest
Four of the sixteen rows below go to Wiz and three are level. Each comes from the same vantage point: connected to the whole cloud through its APIs, looking at an agent before and around the moment it acts rather than from inside it.
- Posture before deploymentmisconfiguration rules for AI services, infrastructure-as-code scanning, and attack paths that join an agent's permissions to the data and exposure behind them. We judge the action rather than the configuration, which is what lets one policy reach an agent however it was configured.
- The AI bill of materialsmodels, frameworks, SDKs and IDE extensions inventoried across code and cloud. We discover the agents and MCP servers themselves, and govern what they do rather than cataloguing what they are built from.
- Prompt-injection detection and distributionprompt injection and rogue-agent behaviour detected with full cloud context, and more than 300 integrations with Google Cloud's channel behind them. Agen runs alongside that footprint rather than in place of it.
- Level on discovery and time to valueagentless discovery through cloud APIs, agents on any major cloud or agent studio, and an inventory within minutes of connecting. On those three, both columns carry the same score.
Detection is not a decision
Wiz's own description of its AI runtime layer is precise: Wiz Defend monitors AI behaviour out-of-band and detects prompt injection, rogue agents and anomalous data egress. Out-of-band means the agent's call has already gone through by the time the detection is raised. What follows is a good response, with an AI investigator triaging the alert, a ticket to the owner, and containment of the workload if it comes to that.
That is why the moment-of-action row scores a 2 rather than a 5. The sensor can block threats on a workload and kill a malicious process, and the table does not ignore it, but stopping a process is not the same as refusing one action while the agent carries on. An agent with a valid cloud role that reads the wrong table or sends the wrong message is doing something its permissions allow. Posture can tell you in advance that the role is too broad. Only a verdict at the moment of action can stop that one call.
A role in the log, not a person
Wiz maps each agent to the identities, workloads and data it touches, and that map is the core of its attack-path analysis. Detections read cloud logs and runtime events, so when an agent acts the record names the role or service account it used.
Owners exist in Wiz, but they exist to route work: which team gets the finding, who should merge the fix. An owner for remediation is not a named human answerable for each action an agent takes. When an autonomous agent acts on a cloud role at night, the record says which credential acted. Accountability needs the person behind the agent.
Three questions to ask of Wiz for AI security
Nobody disputes how much of a cloud Wiz can see. What separates the two products is what happens next, and each of the table's first three groups puts one question to it.
- Be at runtimeis there a decision before an agent's action lands? Wiz watches out-of-band and responds after a detection. The question is the action an agent takes with permissions it already holds.
- Know the identitycan the action be resolved to a named, accountable human? Wiz resolves it to a cloud identity and routes the finding to an owning team. The role stands where a person would.
- Cover everythingdoes it reach agents that do not live in a cloud account: on a laptop, in a browser, or bought as a SaaS product? Wiz covers the cloud and agent studios completely, workstations in preview, and documents no browser control.
Buying it is the fourth group. For a team already on Wiz, AI-SPM sits in the console they use every day, which is a real advantage. The unit is cloud workloads rather than agents, and runtime coverage adds the sensor and Wiz Defend on top of the base plan.