
SANTA CLARA, Calif., Septempber 22, 2026 – Recently, global business and technology insights company Gartner® released its “Emerging Market Quadrant for AI Application Security — Established Vendors” report. NSFOCUS, recognized for its capabilities in the field of AI application security, was selected into the “Specialists” quadrant.
In its report “Forecasting the $16.4 Billion Opportunity in Securing AI”, Gartner® pointed out that the AI security market is accelerating, with the market size expected to reach $4.783 billion by 2027, representing a YoY growth of 68.7%. For NSFOCUS, being selected alongside other leading international security vendors showcases its technical strength and practical achievements in AI application security.
Understanding the EMQ: Grasping New Changes in the AI Application Security Market
The Gartner® Emerging Market Quadrant (EMQ) visually represents the development status and vendor capabilities of emerging markets. In our opinion, compared to the Magic Quadrant, which focuses on relatively mature markets, the EMQ places greater emphasis on rapidly changing markets. Consequently, this EMQ serves as a valuable reference for enterprises choosing security capabilities and partners during market transition periods.
According to the report: “Gartner defines the AI application security market as technologies that protect enterprise-developed AI applications and agents by combining security testing, exposure management, and runtime defense to detect, alert on, or block threats. Delivered via SaaS or on-premises technologies, these tools enable cybersecurity and risk teams to manage posture, conduct adversarial testing, and enforce real-time protection of AI applications.” The report highlights four mandatory functional requirements: AI application discovery and inventory, Automated AI security testing, AI runtime defense, and Coverage for cloud provider AI services. NSFOCUS has built its product layout and practical implementations around these core capabilities, laying the foundation for this inclusion.
Innovation and Execution Capabilities Still Require Synergistic Breakthroughs
The report reveals that the Pioneers quadrant currently features no established vendors. We believe this reflects a current challenge in the market: established vendors need to further enhance their disruptive innovation capabilities, while startup vendors need to build out their scalable execution capabilities. The gap between innovation and execution capabilities will also drive acquisitions, product restructuring, and shifts in the market landscape over the next 12 to 24 months. In response to this window of opportunity, NSFOCUS will leverage its mature customer base and delivery network to continuously invest in cutting-edge technological innovation, promoting mutual enhancement between technical breakthroughs and large-scale implementation.
New Challenges in AI Application Security Revealed by Real-World Attacks
Gartner® analyzed real-world threats facing AI applications in the report. To us, one notable attack chain is: Agent Indirect Prompt Injection → MCP Tool Abuse → Code Execution. Combined with vulnerabilities and attack cases disclosed by institutions like Wiz Research and CSA Labs, these risks can be understood more intuitively:
- CVE-2025-49596 (CVSS 9.4): A remote code execution vulnerability exists in Anthropic’s official MCP Inspector, allowing attackers to execute code and access the full file system without authorization.
- CVE-2025-54135 (CVSS 8.6): Attackers embed malicious prompts into Slack workspace messages, which are passed through an approved Slack MCP Server. This induces the rewriting of the ~/.cursor/mcp.json configuration file, prompting Cursor to automatically execute the attacker’s code.
- Miasma Worm Campaign: Attackers planted malicious MCP configuration files across 73 GitHub repositories, including Microsoft Azure’s azure/durabletask repository. When developers open them, it triggers a credential-stealing payload.
The unique aspect of such risks is that malicious content might pass conventional security checks like SAST, SCA, SBOM, and antivirus software, yet still be read and executed as valid instructions by AI agents.
These cases demonstrate that attackers may not need to breach traditional security controls; they simply need the agent to read and execute malicious content to advance the attack chain. Therefore, defense strategies must go beyond content security checks to further verify instruction sources, enforce least privilege, and check whether behaviors align with user intent. This explains why the report lists runtime defense as a mandatory capability and considers “Least Privilege and Intent Drift Detection” as cutting-edge trends. Intent Drift Detection focuses on whether an agent, after multi-step autonomous actions, is still progressing toward the user’s original goal.
Advancing AI Security Capability Building Through Products and Practice
Gartner® analyzed vendors in the “Specialists” quadrant in its report: “Typical vendors in this quadrant are enhancing AI security levels by combining network-grade visibility with controls targeted at AI application interactions… Most vendors’ solutions focus on behavioral analysis and insider risk intelligence, using endpoint telemetry data to distinguish human operations from AI-driven operations.” Areas requiring further enhancement include agent security and unified security posture management. Centering around these directions, NSFOCUS “NSFAIS” product series continues to refine its security assessment, operational defense, and monitoring/response capabilities. AI Agent Detection and Response (AI-DR), released in September 2026, coordinates with AI Guardrails (AI-GR) and AI Unified Threat Management (AI-UTM) to integrate asset discovery, identity recognition, permission management, and behavioral constraints throughout the entire agent operation process. This helps enterprises clarify access permissions, control action boundaries, and reduce security risks stemming from unauthorized operations and behavioral drift.

Regarding standard setting, NSFOCUS led the drafting of the national standard “Cybersecurity Technology—Large Model Security Gateway Products Security Guideline”, driving the standardization of AI security product capabilities and ecosystem construction.
In terms of industry practice, in the first half of 2026, the NSFAIS solution achieved benchmark deployments across industries such as government, telecommunications, finance, and energy. It also passed the government LLM application security test conducted by the China Industrial Control Systems Cyber Emergency Response Team, becoming one of the first three vendors to pass.
A Phased Roadmap for Enterprise AI Application Security Construction
Based on the mandatory features and cutting-edge trends highlighted in the report, and combined with NSFOCUS’s practical experience, we have outlined an AI application security roadmap with four stages for CISOs and security teams. The following timeline serves as a suggested implementation cadence, which enterprises can adjust based on their own foundation and risk priorities.
- Phase 1: Establish Visibility (1–3 Months)
- Goal: Identify all AI applications and agents present within the enterprise.
- Core Deliverables: Build an inventory of AI applications and agent assets (including Shadow AI), tag ownership and criticality, and compile an inventory of MCP Servers and Skills.
- Phase 2: Establish Testing Capabilities (3–6 Months)
- Goal: Identify weak links and exploitable risks in AI applications.
- Core Deliverables: Establish automated adversarial testing baselines, output test reports on indirect prompt injection and multi-turn attacks, scan model repositories, and define remediation priorities.
- Phase 3: Establish Runtime Controls (6–9 Months)
- Goal: Promptly detect and block threats during the operation of AI applications.
- Core Deliverables: Deploy runtime guardrail policies, integrate anomaly detection with the Security Operations Center (SOC), perform traffic inspection on MCP/A2A protocols, and enforce least privilege policies and intent drift monitoring.
- Phase 4: Establish Continuous Governance Loop (9–18 Months)
- Goal: Continuously discover, handle, and mitigate risks.
- Core Deliverables: Automatically fine-tune runtime policies based on test results, establish a unified execution layer for agent runtime authorization, and create an integrated security posture view.
NSFAIS Product Synergy: Connecting Endpoint, Gateway, and Guardrails; Bridging Assessment and Protection
AI security risks span multiple levels—data, models, applications, and agents—running through the entire lifecycle of AI system development, deployment, and operation. This requires coordinating security capabilities across all levels to carry out collaborative defense and continuous governance.
The NSFOCUS NSFAIS series builds a product system covering risk assessment, operational protection, and security governance through the synergy of AI-Scan, AI-DR, AI-UTM, AI Guardrails (AI-GR), and AI Red Teaming.
- AI-Scan: Focuses on systematic assessments of large model security and compliance.
- AI-DR: Centers around agents to perform asset discovery, identity recognition, permission management, and behavioral governance.
- AI Security Gateway: Provides unified model access, identity authentication and access authorization, token management, model routing, and interaction auditing to ensure secure and controllable model access and calls.
- AI Guardrails: Provides deep content security detection.
- AI Red Teaming: Identifies pre-launch attack surfaces through adversarial testing to verify risk exploitability.
The synergy and linkage among these products and services connect risk assessment with operational protection, helping enterprises translate assessment results into concrete policy configurations and protective measures.
Continuously Deepening Technological Innovation and Industry Practice
Continuously advancing technical innovation and translating innovative results into deployable, deliverable security capabilities will be key for vendors to enhance their market competitiveness.
To us, inclusion in the Gartner® Emerging Market Quadrant highlights NSFOCUS’s technological accumulation and practical achievements in AI application security. As the only Chinese vendor selected in this report, NSFOCUS will continue to increase R&D investment, enhance AI security risk monitoring and agent security capabilities, strengthen product synergy, and deepen industry practice. With products and services tailored to business needs, NSFOCUS aims to provide continuous security assurance for enterprise AI application adoption.
References
[1] Gartner, Emerging Market Quadrant for AI Application Security — Established Vendors, 14 September 2026
[2] Gartner, Forecasting the $16.4 Billion Opportunity in Securing AI, 30 July 2026
Disclaimer
Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.
GARTNER and MAGIC QUADRANT are trademarks of Gartner, Inc. and its affiliates.