Wallarm AI Control Platform
by Wallarm
Runtime discovery and inline policy enforcement for AI workloads on AWS
Wallarm AI Control Platform gives security and platform teams a runtime view of the AI agents, model-provider calls, MCP servers and AWS resources in their estate, and enforces policy inline at the connection level. Launched in June 2026, it extends Wallarm's API security business to AI workloads running on Amazon EKS.
Wallarm AI Control Platform is an AI governance and runtime security product from Wallarm, the Austin, Texas API-security vendor backed by Toba Capital and Y Combinator. It was made generally available in June 2026 in partnership with AWS and is sold through AWS Marketplace. It launched with two products. Infrastructure Discovery assumes a cross-account IAM role that needs no write permissions to map AWS accounts, regions, EC2, VPC, EKS, Lambda, API Gateway, IAM and Bedrock resources into a live relationship graph. It also syncs AWS Security Hub findings with plain-language enrichment, attributes resources to their CloudTrail creator and surfaces undeclared shadow AI services. AI Hypervisor deploys through Helm as a Kubernetes DaemonSet on Amazon EKS and uses eBPF at the kernel level to observe every outbound connection an AI workload makes. That covers calls to Bedrock, Anthropic, OpenAI, Azure OpenAI, Gemini, Mistral and other providers, plus S3, databases and internal APIs, for Python, Go, Node.js, Java, Ruby and generic containers, with no code changes, sidecars or restarts. It attributes sessions to users across service hops, detects card numbers, SSNs, passports, API keys and JWTs in transit, and can block calls at egress, rate-limit, or revoke a session by user or trace ID. Continuous evidence, including a coverage heatmap, AI-SBOM, session audit logs and sensitive-data flow records, is aimed at EU AI Act and SOC 2 obligations. Both products are AWS-only at launch, and AI Hypervisor has no self-service signup or free tier. Its pitch against AI-native security entrants is a single enforcement plane for both the AI workloads and the APIs underneath them.
Cloud security and platform engineering leads at AWS-centric enterprises running AI agents and LLM-calling services on Amazon EKS, especially existing Wallarm API-security customers.
A kernel-level record of every AI workload's model, data and API calls, with inline blocking and continuous EU AI Act and SOC 2 evidence, without changing application code.
At a Glance
- Category
- Governance & Security
- Pricing
- Freemium, Flat rate, Contact for pricing
- Target Market
- CISOs, CIOs, CTOs, Platform Engineers
- Deployment
- Cloud-only
- Headquarters
- Austin, USA
Key Features
- ✓Infrastructure Discovery
Maps AWS accounts, regions, compute, network, Lambda, API Gateway, IAM and Bedrock resources through a cross-account role without write permissions, surfacing shadow AI.
- ✓AI Hypervisor (eBPF)
Kernel-level instrumentation deployed as an EKS DaemonSet that sees every outbound AI workload connection with no code changes, sidecars or restarts.
- ✓Session attribution
Attributes AI calls to users and sessions across service hops without relying on trace headers, so incidents map to real identities.
- ✓Inline sensitive-data detection
Detects credit cards, SSNs, passport numbers, API keys, JWTs and dates of birth in transit before the data reaches a model provider.
- ✓Connection-level enforcement
Blocks calls at the egress boundary, rate-limits, or revokes sessions by user identity or trace ID without restarting pods.
- ✓Continuous compliance evidence
Produces a coverage heatmap, AI-SBOM, session audit logs and sensitive-data flow records aimed at EU AI Act and SOC 2 obligations.
- ✓Security Hub enrichment
Syncs AWS Security Hub findings with plain-language enrichment and CloudTrail creator attribution, plus custom detection rules written in Common Expression Language.
Use Cases
- •Shadow AI audit
A cloud security team connects its AWS accounts and sees undeclared Bedrock models and AI services across regions within minutes of connecting.
- •Data-leak prevention for agents
Platform teams stop agents on EKS from sending customer card numbers or API keys to external model providers by blocking at egress.
- •EU AI Act evidence
Compliance teams export continuous AI inventories, AI-SBOMs and session audit logs instead of assembling point-in-time evidence by hand.
- •Incident response
When an agent misbehaves, responders revoke the offending user session or trace ID immediately, without redeploying or restarting the workload.
- •Unified API and AI security
Existing Wallarm customers protect the APIs under their AI and the AI workloads calling them from a single enforcement plane.
Ideal For
Best For
- ✓Finding shadow AI services and Bedrock usage across many AWS accounts and regions
- ✓Runtime tracing of AI agents' model-provider, database and API calls on Amazon EKS
- ✓Stopping card numbers, SSNs and API keys from leaving AI workloads for external model providers
- ✓Producing continuous AI inventory and session audit evidence for EU AI Act and SOC 2
- ✓Existing Wallarm API security customers extending the same enforcement plane to AI
Not Ideal For
- ✗Multi-cloud or on-premises estates: both products are AWS-only at launch, and AI Hypervisor requires Amazon EKS.
- ✗AI that runs outside your Kubernetes clusters, such as Lambda functions or SaaS copilots: AI Hypervisor instruments pods on EKS only, although Infrastructure Discovery can still inventory AWS resources.
- ✗Teams that want to trial runtime enforcement self-serve: AI Hypervisor has no self-service signup, free tier or in-console activation.
Deployment
Market Analysis
Pros
- ✓No application code changes: label a deployment and eBPF instrumentation starts within about 60 seconds
- ✓Published flat-rate pricing and a genuinely free tier for infrastructure discovery
- ✓Combines AI and API security, closing blind spots in agent-to-API interactions
- ✓Continuous, audit-ready evidence aimed at the EU AI Act and SOC 2
Cons
- ✗AWS-only at launch, and AI Hypervisor requires Amazon EKS, so multi-cloud estates are not covered
- ✗Early product: capabilities beyond the two launch products were undisclosed, so buyers are partly betting on the roadmap (Efficiently Connected)
- ✗AI Hypervisor has no self-service signup, free tier or published price
- ✗Reviews of Wallarm's established WAF product (not this platform) cite inconsistent false-positive handling, documentation gaps and above-market pricing (PeerSpot, 5 reviews)
Pricing
Infrastructure Discovery Free
$0
- ✓1 AWS account, 1 region
- ✓Daily scanning, unlimited assets
- ✓Relationship graph, Security Hub sync, CloudTrail attribution
Infrastructure Discovery Starter
From $200/mo
- ✓3 AWS accounts, 1 region
- ✓Configurable scan frequency
- ✓$2,400/year via AWS Marketplace
Infrastructure Discovery Standard
From $500/mo
- ✓10 AWS accounts, 2 regions
- ✓Configurable scan frequency
- ✓Stackable up to 5 per organisation (50 accounts at $2,500/mo)
Growth, Enterprise, Enterprise+ and AI Hypervisor
Contact for pricing
- ✓Private offers via AWS Marketplace
- ✓AI Hypervisor requires separate sales-led onboarding
- ✓Scoped to EKS clusters, model providers and compliance targets
Infrastructure Discovery uses AWS Marketplace flat-rate pricing: free for one account and one region, $200/month for three accounts, and $500/month for ten accounts across two regions, stackable to 50 accounts; higher tiers are private offers. AI Hypervisor, the runtime enforcement product, has no published price, free tier or self-service signup and is scoped with sales by EKS clusters, model providers and compliance targets.
Security & Compliance
Sources
This page was written from 7 sources, 7 on domains other than wallarm.com.
- 1.lab.wallarm.com — introducing the wallarm ai control platform one closed loop
- 2.changelog.wallarm.com — introducing the wallarm ai control platform oFsqc
- 3.docs.wallarm.com — subscription plans
- 4.cybersecurity-insiders.com — wallarm launches ai control platform bringing runtime visibi
- 5.cybersecurity-insiders.com — wallarm infrastructure discovery now available on aws market
- 6.efficientlyconnected.com — wallarm ai governance platform enterprise
- 7.peerspot.com — wallarm reviews
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
WitnessAI
Network-layer AI security and governance for employee AI use, models, apps and agents
Ascerta
Enterprise AI management: measure the ROI, cost and adoption of every AI initiative, agent and coding tool
Reco
AI agent security and SaaS security platform that discovers, governs and secures every agent, app and identity
Arcjet
Runtime security for AI agents: observe, enforce and audit agent tool calls, with prompt-injection, PII and abuse controls in code