AI Defense Matrix: 194 Products Protect. Two Recover.
The AI Defense Matrix catalog maps 239 AI security products. Nineteen of the 48 cells sit empty or near-empty, every one in Govern, Respond, or Recover.
Open the AI Defense Matrix catalog and filter to Recover. You get two products out of 239. Filter to Protect and you get 194. Same catalog, same day, same 239 products. I pulled the raw data file yesterday and recounted every cell myself, because a gap that wide usually means somebody miscounted. Nobody miscounted.
What The AI Defense Matrix Measures
Lenny Zeltser and Sounile Yu built a grid with eight AI-specific asset classes down the side, the six NIST CSF 2.0 functions across the top, 48 cells where they meet. The AI Defense Matrix launched May 11, 2026 under CC BY-SA 4.0, as the security-for-AI companion to Yu’s Cyber Defense Matrix.
The rule they used to decide what gets a row is what makes the thing useful. A row exists only if defending that asset requires AI-specific considerations, processes, or tools. If a generic security approach handles the defense well, it belongs in the Cyber Defense Matrix instead. Raw GPUs and containers got cut for that exact reason, and the change log says so out loud, which is more than most frameworks bother to do.
That discipline is why counting the cells means anything. The companion catalog places 239 products across those 48 cells, sourced from public information, dated, open to community correction. It catalogs AI-specific security products. Your SOAR platform and your backup vendor aren’t in it, and they shouldn’t be. What it measures is whether the industry has built an AI-specific answer for each cell.
For most of the grid, it has. For one corner of it, nothing showed up at all.
Run The Count Yourself
Nineteen of the 48 cells hold zero products or exactly one. All 19 sit in Govern, Respond, or Recover.
Run it the other way and the picture gets starker. Every single cell in Identify, Protect, and Detect holds at least three products. The floor is three for Identify, seven for Protect, six for Detect. Not one thin cell anywhere in those three columns. Then you cross into Govern, and the floor drops to zero. Same for Respond. Same for Recover.
Before anyone writes to tell me thin rows explain thin cells, they don’t. Runtime AI Data is the fattest row on the grid, with 244 product placements across it, and it still shows blanks in Govern and Recover. AI Model carries 116 placements and covers all six functions. Row size doesn’t predict where the holes are. Column does.
One number needs a footnote so nobody catches me playing games with it. When I say 194 products do Protect, that’s how many products carry a Protect tag on at least one asset class. Those same products land in 312 asset-specific Protect cells, because a product covering three rows counts once in the first number and three times in the second. Both numbers are real. They answer different questions.
Now, I’d be remiss if I didn’t call out that my employer sits in this catalog with five cells: agent identity discovery, plus protection and detection on runtime AI data and orchestration tools. All five land in the middle three columns. I’m not going to pretend that’s a coincidence or a shortcoming particular to us. It’s what nearly every product in the AI security market looks like when you place it on this grid, including the ones you already bought, and it’s the shape of the problem rather than the shape of any one vendor’s roadmap.
Two Products Cover Recover
Here they are, by name. Hirundo does machine unlearning, stripping memorized data and jailbreak behavior out of a trained model without a full retrain, and the catalog places it in Recover for AI Model. Rubrik Agent Cloud rewinds destructive agent actions, and it holds Recover for AI Agent Identities and for AI-Generated Code.
That’s the column. Two products, three cells, and no cell in Recover holds more than one product.
Respond does better and still doesn’t do well. Nine products across five cells. Four of the nine hold their Respond coverage on the AI Agent Identities row, and all four are non-human identity platforms: Astrix, Clutch, Permiso, and Vorlon. Credential revocation and agent quarantine are the one response capability the market ships in any volume at all.
Read the actual cell text and the two columns split cleanly. Respond is written in containment verbs: credential revocation, agent quarantine, session termination, RAG source isolation, plugin disable, shadow AI takedown. Recover is written in undo verbs: model version restore, dataset restore from golden copies, vector DB restore, re-indexing, prompt rollback, agent identity re-provisioning.
Then there’s the detail I keep coming back to. Three cells on the entire grid are labeled generic by the authors themselves. Generic container IR. Generic platform restore. Generic network failover. All three sit in Respond and Recover. Nowhere else on 48 cells do Zeltser and Yu tell you the traditional answer will do. That admission is the most honest thing on the page, and it’s also a map of where the AI-specific work hasn’t happened yet.
Undo assumes a lot. An agent that ran for six hours holding delegated credentials across a dozen tools has sent emails, opened pull requests, written to a CRM, posted in channels, and fired webhooks that triggered things you don’t have visibility into. Restore the platform, and none of that comes back. Those effects live in separate systems with separate owners and no shared transaction boundary, which means there’s nothing to roll back to. I’ve written before about why least agency beats least privilege once agents can act, and this column is that argument showing up as somebody else’s control taxonomy.
Why The Market Sells The Middle
I had the wrong explanation for this at first. My first read was that the empty columns are the architectural ones, and the market only sells what bolts on. Identify killed that theory in about a minute. Discovering AI agents across an enterprise is an architecture problem too, and the market sells 146 products against it.
That’s the difference between watching a system and reaching into it.
Identify and Detect sell because a product can do the work from outside. Agentless posture management crawls your cloud and finds unregistered models, and you change nothing to let it. Protect sells at 194 for a reason that surprised me until I read the product descriptions: what the market calls Protect for AI is overwhelmingly inline filtering at a chokepoint. Gateways, proxies, browser extensions, guardrails on prompts and responses. That’s still exterior work. A filter inspects something crossing a boundary and decides yes or no.
Every containment verb in the Respond column carries a precondition somebody had to build. You terminate a session where sessions exist and can be terminated. You revoke a credential where it was scoped and revocable in the first place. You quarantine an agent where the agent runs somewhere quarantinable. A vendor can sell you the button. Nobody can sell you the wiring behind it.
One row breaks that pattern, and it’s the exception worth studying rather than the one that sinks the argument. AI Agent Identities carries 56 products under Protect, and the cell text reads agent OAuth, capability scoping, and short-lived credentials. That’s architecture sold as a product, which is the thing I said the market doesn’t do.
Look at what happened behind it. AI Agent Identities and AI Model are the only two rows on the whole grid with coverage in all six functions, Respond and Recover included. Every other row has at least one blank. Both of those rows got a market around the underlying primitive first, non-human identity tooling in one case and model registries and provenance in the other. Once the asset became addressable, once agents had scoped identities and models had versions and inventories, the containment columns filled in behind them. Four products doing agent quarantine exist because 56 products turned agents into principals you can scope.
That sequence is the roadmap, and it took me a while to see it. Response capability doesn’t show up because vendors decide to care about incidents. It shows up after somebody makes the asset addressable, and containment becomes something you can build on top of that. Runtime AI Data carries 244 placements and zero Recover coverage, because nobody has made a prompt, a RAG chunk, or an agent’s persistent memory into a thing with a version and an owner you can roll back to. Do that work and the column can fill. Skip it and vendor attention won’t rescue you.
Govern is the cleanest proof, and it settles a question I went back and forth on. Read all eight Govern cells and every one is a standard, a policy, or an evaluation decision. AI platform standards. AI application governance. AI coding standards and code-review policy. AI egress policy. Model selection and provider evaluation. Dataset provenance and licensing policy. Prompt and RAG policy. AI agent identity policy and authorization standards.
None of that is a product category. Zeltser and Yu tell you as much in their own instructions, where the gap analysis asks whether process, technology, or both cover each cell, and then tells you to start with Govern. Eleven products carry a Govern tag, and five of the eight rows have zero. Credo AI, OneTrust, Cranium, Holistic AI, and LatticeFlow are all in there and correctly tagged. They help you document and evidence a policy. Writing the policy stays yours.
The Prediction The AI Defense Matrix Sets Up
Here’s where I part company with the authors, and I want to be precise about it because they are probably right.
Their guidance to vendors says to treat thinly covered cells as opportunities for differentiation and new products that solve underserved needs. That’s a forecast because the thin columns fill because the market notices the gap and builds into it. My read is that Recover and most of Respond stay thin, because the missing capability isn’t a product somebody forgot to build. It’s a property of systems that were designed without it.
Put a number on it. I’d say 70% that the Recover column holds fewer than ten products in July 2028, and under 20% that it ever resembles what Protect looks like today. I’m at 70 rather than 90 because I’ve been wrong about market timing before. Nobody sold cloud posture management in 2016 either, and a July 2026 snapshot of a young category can look identical to a permanent boundary.
The falsifier is specific, so hold me to it. Watch Rubrik. If three more vendors ship agent-action reversal and it works without you rerouting your agents through their control plane first, I’m wrong and the market solved something I said it structurally couldn’t. If the only way it ever works is routing your agents through somebody’s plane, that’s the architectural decision doing the work, and the product is the part you bolt on afterward.
Meanwhile, NIST IR 8596, the Cyber AI Profile everyone’s waiting on, has been sitting as an initial preliminary draft since December 16, 2025, with the comment period closed since January 30, 2026. Seven months, no initial public draft. You need a working instrument now, and this grid is the best one anybody’s published.
Two products cover Recover for all of AI. One strips bad behavior out of model weights. The other rewinds agent actions it was routed through ahead of time. That’s the entire Recover column of the AI Defense Matrix, on a grid of 48 cells, in a market that has shipped 194 ways to protect you and almost nothing to put you back together.
What To Do Next
Download the matrix as a CSV, YAML, or Markdown and populate it for your own environment this week. Mark every cell covered, partial, or absent. Budget 90 minutes with whoever owns your agent platforms.
Then cover Identify, Protect, and Detect with your hand and look at what’s left. For each blank in Govern, Respond, or Recover, write down two things: the design decision that would have to change for that cell to fill, and the name of the person who can make that decision. Not the product that would fill it. The decision and the owner. That’s a build backlog and an ownership map, which is Create and Adapt work in the CARE model, and it’s a different conversation than a purchase order.
If you want the deeper argument on why authorization scope is a runtime decision rather than a connection-time checkbox, I wrote that up in the MCP authorization gap piece, and JadePuffer is what the Respond column being empty looks like when it happens to somebody. More at rockcybermusings.com, and the advisory work lives at rockcyber.com.
👉 For ongoing analysis of agentic AI governance frameworks, the conversation continues at RockCyber Musings.
👉 Visit RockCyber.com to learn more about how we can help with your traditional Cybersecurity and AI Security and Governance journey.
👉 Want to save a quick $100K? Check out our AI Governance Tools at AIGovernanceToolkit.com
👉 As a bonus, check out my latest appearance on the Down The Security Rabbit Hole podcast, where we discuss the current state of AI in the SOC for cybersecurity and specifically how it differentiates from the promise of SOAR.







