SecurityBrief Ireland - Technology news for CISOs & cybersecurity decision-makers
Ireland
Salt Security expands Policy Hub to 100 AI policies

Salt Security expands Policy Hub to 100 AI policies

Tue, 21st Jul 2026 (Today)
Mark Tarre
MARK TARRE News Chief

Salt Security has expanded its Policy Hub to 100 pre-built policies for API and AI agent governance, including more than a dozen designed specifically for agentic AI security.

The update focuses on governance rules for APIs, MCP servers, agent permissions, authentication, compliance and runtime behaviour. Of the 100 policies, 61 activate automatically. The rest can be enabled with a single click, and customers can also create their own policies without a stated limit.

The move reflects a broader shift in enterprise security as companies deploy AI agents that rely on APIs to fetch data, call tools and take actions across internal systems. Salt argues this makes the API layer a key control point for governing what AI agents can access and do.

Policy expansion

Salt described the 100-policy milestone as the first app-store-style library for agentic security governance. The policy set spans data security, access control, OAuth, API architecture, MCP configuration, third-party risk and agent-specific security issues.

Salt has also mapped the library to eight compliance frameworks: PCI DSS, FedRAMP, SOC 2, GDPR, HIPAA, ISO 27001, CMMC and HITECH. This gives customers a way to align policy checks with established regulatory and assurance schemes alongside operational controls for AI and API environments.

The Policy Hub sits within Salt's Agentic Security Platform, which manages visibility and governance across large language models, MCP servers, APIs and connected enterprise systems. Salt said the latest expansion extends that approach beyond runtime defence into posture management across the wider agentic stack.

Michael Callahan outlined how customer concerns shaped the rollout. "When we launched the Policy Hub in 2024, the most common thing we heard from CISOs was: we know we need posture governance, but we have no idea where to start. That question was killing governance programs before they launched. 100 policies means that question now has a concrete answer. Security teams can walk in on day one with meaningful protection already active, and extend it from there without limit," said Michael Callahan, Vice President of Strategy and Chief Marketing Officer, Salt Security.

Agent oversight

The new AI-focused rules cover areas including MCP server configuration, agent authorisation and the behaviour of autonomous software agents. Salt said it added controls for risks such as over-privileged agents, unauthorised actions and misconfigured MCP servers as enterprise use of these systems grows.

MCP, or Model Context Protocol, has become an area of interest for security teams because it gives AI systems a way to connect to tools and data sources. That means weak configuration or access controls at the MCP layer could give software agents a path into sensitive business systems.

Some policies in the hub were originally built for API posture governance before being adapted for broader agentic use cases. Salt argues that the controls needed for APIs now overlap with those required to govern AI agents because those agents operate through the same technical infrastructure.

Salt linked that development to its earlier work on MCP server discovery, introduced in 2025 to identify and classify MCP servers across enterprise estates. According to the company, governance policies for those servers were developed alongside the discovery tooling.

Wider platform

Salt has also extended its policy model into software development. Its Salt Code product applies the same posture governance engine to AI-generated code during development, giving customers a consistent set of rules across generated software, APIs, agents and runtime operations.

This suggests vendors in the sector are trying to bring together code security, API governance and AI oversight under a single framework rather than treat them as separate disciplines. For enterprise buyers, the appeal is likely to be a common policy structure that can be applied across several stages of the application lifecycle.

Aner Gelman framed the issue in terms of accountability to boards and senior management. "The board question CISOs are being asked right now is not whether we have AI governance. It is whether we can prove it. 100 policies in active deployment is a concrete, operational answer to that question. Not a roadmap. Not a strategy. An active governance layer running today," said Aner Gelman.

The full set of 100 pre-built policies is now available to customers using the Salt Agentic Security Platform.