Acalvio Technologies Launches Deception Guardrails to Secure Autonomous AI Agents

Cyber deception technology provider Acalvio Technologies launched Deception Guardrails, a preemptive defense capability designed specifically to secure AI agents. The platform deploys credible honeytokens and honey skills in the files and configuration surfaces that AI agents read as operational context. If an agent is compromised or goes rogue, the system detects the unauthorized lateral movement, feeds fabricated data to the attacker, and alerts the security operations center.

Acalvio Technologies Launches Deception Guardrails to Secure Autonomous AI Agents
Acalvio Technologies Launches Deception Guardrails to Secure Autonomous AI Agents

Acalvio Technologies, a cyber deception provider based in Santa Clara, California, has launched Deception Guardrails, a preemptive security capability designed to defend autonomous AI agents. The new capability embeds high-fidelity decoys and fabricated configurations into the files and data systems that AI systems read as context. If an agent is hijacked or experiences alignment failure, the software identifies unauthorized actions, feeds false data to the attacker, and alerts the security operations center.

Why Input-Output Filters Fall Short in Protecting Autonomous AI Agents

Many current security systems for large language models act as filters on incoming prompts or outgoing responses. These filters prevent the model from generating toxic text, leaking proprietary code, or executing basic prompt injection attacks. However, when companies deploy fully autonomous agents, these systems go beyond simple text processing to execute complex tasks using external APIs and databases.

If an attacker compromises the underlying host or bypasses the initial input-output filters, the agent behaves as a privileged insider. The attacker can then use the agent’s trusted access to move laterally through the enterprise network, utilizing connected tools and credentials. In cybersecurity, lateral movement refers to the process where an intruder compromises one entry point and systematically explores the network to access deeper, higher-value targets.

In an AI context, this occurs when an agent uses its pre-configured API keys or database access to query systems it has no legitimate reason to touch. This makes standard boundary filters and external guardrails ineffective once a compromise has occurred, as the malicious actions look identical to normal, automated workflows.

How Honeytokens and Honey Skills Intercept Rogue Agent Activity

To counter this vulnerability, the platform deploys highly credible “honeytokens” and “honey skills” directly into the operational contexts that agents scan. Honeytokens are fake credentials, inactive database connections, simulated package registries, or artificial datasets. Honey skills are fabricated functions or tools listed in the configuration files that describe what tasks the agent is capable of performing.

AI agents routinely parse these configuration files to determine what resources they have at their disposal. When a compromised or misaligned agent attempts to execute a honey skill or access a honeytoken, the system immediately recognizes the abnormal action. This interaction creates a high-fidelity alert, indicating malicious behavior without relying on slow log analysis.

Expanding Defense to Decoy RAG Databases and MCP Servers

The platform also deploys simulated environments around the core AI infrastructure to trap and analyze attackers. This includes decoy Retrieval-Augmented Generation (RAG) systems and decoy Model Context Protocol (MCP) servers. Both technologies represent common data access pathways for enterprise AI architectures.

RAG systems allow AI models to query external company documents dynamically to find answers to specific user questions. A decoy RAG mimics these private file repositories but contains entirely fabricated data, which is fed to attackers when they attempt to query the system. This interaction immediately exposes the attacker’s search queries and intent without exposing any genuine corporate intellectual property.

MCP is an open standard that dictates how AI models retrieve data and call functions from external applications. By surrounding the ecosystem with simulated MCP servers, the system forces attackers to reveal their methods before they can touch active, production databases. This creates a deceptive runtime environment that changes what the agent sees and trusts.

Integrating Agent Defense Into the Broader ShadowPlex Ecosystem

The new capability operates as a native extension of the company’s core platform, ShadowPlex. This allows security teams to manage AI agent security alongside pre-existing cloud and on-premises deception infrastructure. This integration provides early warning signals that help security teams respond before business-critical systems are affected.

Ram Varadarajan, CEO at Acalvio, stated that current protective measures focus too heavily on keeping benign systems aligned. “Reactive guardrails are designed to keep well-behaved AI systems on the road, but they do nothing to stop a hijacked agent driven by a malicious actor,” Varadarajan said. “With our patent-pending Deception Guardrails, we are moving the industry from reactive filtering to preemptive defense”.

The need for active deception in AI environments was recently highlighted in a security briefing issued by authorities from the Cloud Security Alliance, SANS, and RSAC. The briefing noted that “because agents cannot easily tell valid credentials or systems from honeypots, deploy fake identities, credentials, package registries, datasets, honey APIs, and honey clusters to slow attackers and generate high-confidence indicators”.

Lawrence Pingree, Head of Research at Software Analyst Cyber Research, added that the approach integrates with existing defense pipelines. “By embedding deceptive assets directly into agent workflows and surrounding AI infrastructure with decoys, organizations gain a powerful new layer of detection that complements existing AI safety and governance controls,” Pingree said.

Topics
  • #Products
Raj M

Author

Raj M

Contributor

AI Systems Architect is a seasoned technology leader with over 15 years of experience in the IT industry working with Fortune 500 companies. With a solid foundation in multi-agent systems, open-source LLM infrastructure, and enterprise deployment, he excels at building scalable production-grade AI platforms.