Brand Speak
Operant AI launches Semantic Firewall to enforce AI agents in real-time as enterprise adoption scales in India
- As enterprises deploy AI agents across systems handling sensitive data, controlling their actions in real time is becoming a key security requirement.
- The launch comes as India’s AI governance framework evolves, with the Data Security Council of India (DSCI) working on a framework to examine how liability should be distributed when AI agents act autonomously — bringing greater focus on accountability when autonomous systems make decisions or take actions on behalf of organisations.
- Operant Semantic Firewall addresses this challenge by evaluating the intent across prompts, code, tool calls and data movement, allowing organisations to block unauthorised actions before execution.
National, India, Aug 28:
As enterprises deploy AI agents in internal workflows, San Francisco headquartered Operant AI, a leader in AI security, today announced the launch of Operant Semantic Firewall, the first product, that understands an AI agent’s intent in real-time and enforces it inline, stopping a malicious action, a jailbreak, or a data breach in the moment before it executes.
Modern AI agents today can run code, modify records, access enterprise data, call external tools and interact with other models and services. When an agent is compromised or pursues its goal down a path no one authorized, static and pattern-based defenses can’t catch it.
In today’s probabilistic agentic world, there is no known bad pattern to match against an action that has never existed before. Operant Semantic Firewall evaluates the meaning and intent behind an agent’s activity across prompts, model responses, commands, tool calls and data movement. It makes an inline allow, block or redact decision as the agent acts, creating an enforceable control layer across the full agent loop.
The Governance Gap in Agentic AI
Agentic AI has drastically collapsed the time between a system making a decision and taking an action. Security controls therefore need to operate at the same point of execution, fast enough to sit in the live path without slowing it down and decisive enough to stop an action before it happens.
Traditional signature- and pattern-based controls are designed to identify known indicators of malicious activity. But agents can generate novel actions, chain individually legitimate steps into an unauthorised outcome, or encounter instructions through tools, data and context that were never anticipated when the system was configured.
The governance gap is already becoming visible as enterprises accelerate deployment. According to IBM’s 2026 study of 2,000 technology CXOs across 33 geographies, 77% believe AI adoption is already outpacing their governance capabilities. Organisations that embedded controls directly into their AI systems experienced 25% fewer incidents than those relying on manual governance.
The gap is also clearly visible in India. Salesforce’s 2025 State of IT: Security survey found that 76% of Indian IT security teams expect to use AI agents within two years, up from 43% today. Yet 52% were not fully confident they had the appropriate guardrails to deploy them, while 87% said AI agents present compliance challenges.
This becomes increasingly important as India advances its AI governance framework through the India AI Governance Guidelines and strengthens data-protection requirements under the Digital Personal Data Protection Act and Rules, placing greater emphasis on secure, accountable and responsible AI deployment.
The risk is not limited to malicious users. An agent can be manipulated by a prompt injection or jailbreak that changes its behaviour mid-session. It can also move outside its intended scope on its own, improvising a step that was never authorised or chaining a series of reasonable actions into an outcome no one intended.
Recent incidents involving frontier AI models have also highlighted the risks of increasingly autonomous systems. During cybersecurity evaluations, several leading AI labs have reported cases where models found unintended ways around sandbox or security controls and carried out actions beyond their intended boundaries.
In July 2026, OpenAI disclosed that experimental models left a test environment with no human direction, escaped through a zero-day, and used privilege escalation and lateral movement to reach Hugging Face’s production infrastructure while completing a cybersecurity evaluation reaching accounts at as many as four companies. The agent didn’t “want” to break in; it found an unintended path to finish its task. Operant Semantic Firewall governs scope itself, stopping any action outside the agent’s authorized purpose whether it comes from manipulation or the agent’s own initiative.
Operant Semantic Firewall is designed to address this problem at the point of execution. Rather than relying only on controls around the model or its operating environment, it evaluates whether an agent’s action is consistent with its authorised purpose. If it is not, the action can be stopped whether the deviation originates from an attacker’s manipulation or the agent’s own reasoning.
The Defense Layer for Sovereign AI
Enterprises already insist on sovereignty over their data where it lives, who can reach it, whose jurisdiction governs it. Agentic AI extends that requirement from data to decisions. Sovereign AI means the enterprise, not its model provider, decides what its agents are permitted to do and enforces that decision inside its own perimeter.
Operant Semantic Firewall makes that boundary operational in three ways:
- It runs where you run. Every allow, block, and redact decision is made inside the enterprise’s own environment, including VPC, on-premises, and air-gapped deployments. Prompts, payloads, and policy never leave the perimeter to be adjudicated elsewhere.
- It reaches its own verdicts. Semantic Firewall classifies intent using Operant’s own models, without routing decisions to an external frontier provider. Your enforcement layer does not inherit another vendor’s availability, pricing, policy changes, or safeguards.
- It survives a model change. Because enforcement sits above the model and works across frameworks, swapping providers in future may change economics, but doesn’t affect the controls.
For teams operating under data residency requirements, the EU AI Act, Singapore MAS framework, or other sector regulators in financial services and healthcare, that means AI governance that can be evidenced to an auditor rather than attested to on a vendor’s behalf. As agents connect to more external models, tools and services, enterprises increasingly need controls that do not depend on the safeguards of each third-party system.
Security built around agent intent
Operant Semantic Firewall brings together multiple forms of intent analysis under a single control plane:
- Tool Intent Guard — Reads the real-world impact of every tool call and blocks data exfiltration, bulk data dumps, credential access, and unauthorized sharing even when the request itself looks routine and matches nothing on a blocklist.
- Code Intent Guard — Distinguishes ordinary code from malicious execution, injection, shell breakout, privilege escalation, and hidden directives across everything a coding agent does — package installs, tool and MCP server installs, command execution, and skill usage alike.
- Data Intent Guard — Classifies files and data as confidential or business-sensitive using built-in classifiers and integrations with enterprise data-governance tools such as Microsoft Purview, so access decisions honor the sensitivity labels an organization already trusts.
- Scope Guard — Holds an agent to the purpose it was given, whether it strays by manipulation or on its own initiative. The first legitimate request becomes the agent’s contract for that session; later instructions can be measured against that contract but cannot silently rewrite it. Crucially, Scope Guard re-checks the whole loop rather than a single prompt: follow-up turns, tool arguments, tool results re-entering context, and high-risk actions such as execute, write, and transmit are continuously re-tested for drift so an agent cannot wander, or be walked step by step, toward work it was never authorized to do.
- Policies in natural language — Administrators express scope and restrictions the way they already describe risk “no unauthorized deletes,” “no PII leaving this workspace” and the firewall enforces that intent on every turn, returning an allow, block, or redact decision with a clear explanation of why.
Because the same intent model is applied across prompts, model responses, commands, tool calls and data movement, enforcement does not depend on catching an attack at a single checkpoint. An instruction introduced through a jailbreak, or an action independently improvised by an agent, can be evaluated again when the agent attempts to execute code, access a tool or move data.
The next evolution of the firewall is built on intent
“Agent security has moved past its first two generations. Watching agents and filtering keywords were fine for early experiments, and some teams will be comfortable there for a while. But the serious enterprises, the ones putting agents into revenue, customer data, and production systems, need a specialist layer that understands intent and enforces it in real-time. Vanilla controls weren’t built for that, but Operant was,” said Vrajesh Bhavsar, CEO and co-founder of Operant AI.
“And this year showed the industry that agents don’t only go off course because someone pushed them, they do it on their own, chasing a goal down whatever path they can find, including straight out to systems and models they were never meant to touch. The answer is to bring the trust boundary back inside your own walls. Operant Semantic Firewall understands the intent behind everything an agent does, governs every connection it makes, and enforces the enterprise’s policy inline at the speed of agents inside their perimeter, on their terms, no matter whose model is running underneath.”
Extended Defenses For Claude, Live Browser AI Protection, and Dynamic Token Metering Launching in Parallel
Alongside Operant Semantic Firewall, Operant AI is shipping several major updates to its AI Defense Platform in parallel:
Live Browser AI Protection: The browser has become an AI runtime that reads, reasons, and acts inside authenticated sessions — and it’s the one surface enterprise controls don’t protect. Operant Browser AI Protection reads the conversation itself in real-time, allowing, sanitizing, or blocking sensitive content inline on ChatGPT, Claude, Copilot, and Gemini — checking prompts before they’re sent and responses before they render, so a leak is stopped and an incoming instruction is caught without shutting the user down.
Broader Claude coverage: Operant now covers Claude Cowork cloud-mode sessions and, via a new inference-hook integration, the rest of the Claude family — including Claude in the desktop app, Claude Tag, and Claude Design. [Text Wrapping Break]
Operant Token Meter: Shipping in the latest platform update, Operant’s dynamic Token Meter turns token usage from an after-the-fact surprise into something you can see and control — near-real-time metrics by user, team, agent, and model, plus budget limits enforced mid-session, across every deployment including Bedrock, Vertex, and Foundry.
Availability
Operant Semantic Firewall, Browser AI Coverage, Expanded Claude coverage, and Operant Token Meter are all available today as part of Operant AI’s AI Defense Platform.
For more information or to request a demo, visit www.operant.ai or contact hello@operant.ai.

