The security question that AI agents keep raising is a practical one: when a model can call tools, query a database, and hand work to another agent on its own, who gets to say no? SentinelOne is answering it by moving its controls out of the model and into the plumbing. The company said on June 17 it will feed detection signals from Prompt Security, the AI-security business it bought last year, into Amazon Bedrock AgentCore so that enforcement happens at runtime rather than after an agent has already acted.
The signals SentinelOne is contributing cover the failure modes specific to language-model agents: prompt injection, exposure of personally identifiable information, tool-use validation, and monitoring of what the model sends back. Those feed into AgentCore's policy engine, which SentinelOne describes as applying real-time, deterministic allow-or-deny decisions across three channels where an agent can go wrong: agent-to-tool, agent-to-LLM, and agent-to-agent. Data-leakage checks run across all three.
What sets the approach apart is where the decision sits. SentinelOne says the policy engine acts outside the agent's reasoning loop, so a compromised or manipulated model cannot talk its way past the control the way it might if the guardrail were a prompt instruction the agent could reinterpret. That is the recurring weakness of putting safety rules inside the model itself, and routing enforcement through a gateway is the current industry answer to it. The word deterministic is doing real work here too: the check returns the same verdict every time for the same action, which is what makes agent behavior auditable rather than probabilistic.
SentinelOne is folding the work into its Singularity Platform and says existing Prompt Security customers can turn it on through a bring-your-own-license path. "Every organization building and running AI agents on AWS needs the same security controls they rely on across the rest of their infrastructure," said Melissa K. Smith, the company's SVP of global strategic partnerships and initiatives, framing agent security as an extension of existing enterprise controls rather than a separate product to buy.
The gap between the pitch and the proof is timing. The integration is not shipping yet; SentinelOne says it will land in AgentCore later in 2026, which leaves the specifics of latency, coverage, and how much the gateway slows a busy agent to be judged when teams can run it. The direction is the more telling signal. A vendor that made its name in endpoint detection is treating autonomous agents as the next thing that needs a policy at the perimeter, and the value of a deterministic gateway will come down to whether it holds up against the injection techniques that keep finding their way around softer defenses.












