Agent Security, Agentic Investigations, and integrated AI-driven data pipelines expand SentinelOne's strong portfolio of security solutions
SentinelOne (NYSE: S), a global leader in AI-powered cybersecurity, introduced a new range of AI-powered security solutions designed to give security managers a distinct competitive advantage. The new solutions, which span both AI security and the use of AI to automate security operations, build on SentinelOne's product portfolio. From protecting autonomous agents to conducting comprehensive agent investigations with a single click, offerings are being showcased at the RSAC 2026 conference (Booth N-5863).
As businesses adopt AI to accelerate innovation and increase productivity, AI itself has become the new attack surface and source of risk. Not surprisingly, Gartner has reported that AI cybersecurity – defined as both protection from AI and AI-enhanced security – is among the fastest growing markets for overall AI spending in the coming years. Gartner's January 2026 estimate predicted that spending on AI cybersecurity will grow at an annual rate (CAGR) of 73.9% through 2029, more than double the overall spending on AI.
New AI Agent Security Prompt security
Building on SentinelOne's end-to-end holistic approach to AI security (link al blog), Prompt AI Agent Security offers a new level of real-time control for the detection and governance of AI agents and their workflows. Leverage the same Autonomous Security Intelligence that powers SentinelOne across endpoint, cloud and identity, extending proprietary AI and automation to the agent level — monitoring, controlling and enforcing policies on agent interactions in real-time, at machine speed. The result is complete visibility, risk assessment and policy enforcement across every MCP server operating in the customer's environment. Additionally, in preview, customers can manage the security posture of each AI agent and agentic workflow and automatically correct agent behavior before unauthorized actions occur, such as an OpenClaw agent sending data to an external endpoint without the user's knowledge, or a Claude Cowork agent elevating privileges on systems through sequences of unauthorized actions.
New AI Red Teaming Prompt
Prompt AI Red Teaming provides security and product teams with unique capabilities to test and enhance internally developed and proprietary AI applications. As developers increasingly use agents to create new tools, applications and workflows in enterprise environments, traditional security testing is no longer sufficient to address the specific threats inherent to AI. With Prompt AI Red Teaming, organizations can maintain a competitive advantage in innovation without exposing business or customers to critical risk by simulating real AI attacks (prompt injection, jailbreak, privilege escalation, data poisoning, etc.), hardening AI apps before release, and continuously assessing risks (detecting pattern drift, emerging vulnerabilities, new attack vectors, etc.) as threats evolve.
Purple AI's new “Auto Investigation” feature is now available
At the RSAC 2026 conference, SentinelOne consolidates Purple AI's lead with the new “Auto Investigation” feature, accessible with just one click. Natively integrated into the Singularity™ platform, this new capability allows analysts to launch comprehensive, proactive investigations with a single click. Going beyond rigid playbooks, Purple AI autonomously collects cross-stack evidence, synthesizes threat data, and builds comprehensive attack histories in real-time. It provides clear, explainable verdicts that instantly trigger closed-loop correction via Singularity Hyperautomation, all while maintaining rigorous analyst governance.
Purple AI uses an agentic framework and human-level reasoning to give security teams speed, scale, and expertise to block sophisticated attacks. Furthermore, it provides intuitive automation with human intervention (human-in-the-loop) to free up human resources, allowing them to focus on the most strategic activities.
First introduced at RSAC 2023 and field-tested in thousands of real-world SOCs and customer environments, SentinelOne's Purple AI has become the industry's leading agentic AI-based security analytics offering. It has also become one of the most widespread. In SentinelOne's fourth-quarter fiscal 2026 financial results report, the company reported a record adoption rate for Purple AI, which was included in more than 50% of all licenses sold during the fourth quarter.
Auto Investigations Agentic integrates Purple AI reasoning into the most complex part of security operations, enabling in-depth, cross-source forensics at machine speed, without additional data routing or extended permissions. All of this is delivered within the constraints of the Singularity data platform and AI SIEM, both of which are fully regulated.
As a result, Purple AI's new “Auto Investigations” feature reduces security investigations that previously took hours or days to minutes or seconds, helping security teams level the playing field by matching the speed of AI-based attacks.
Purple AI Auto Investigations is available to all Purple AI Analyst customers, with no additional implementation or configuration required.
New AI-powered data pipelines in the Singularity AI SIEM
Following the acquisition of Observo AI, SentinelOne is integrating native AI data pipeline capabilities directly into the Singularity AI SIEM, to offer the only SIEM on the market that provides both pre-load analytics and flexible data collection in a single platform. Included as part of the Singularity AI SIEM, the integrated AI data pipeline includes intelligent filtering, enrichment, and normalization of unstructured data, all of which occur upstream before the data reaches the Singularity platform. This reduces data pollution by up to 80% before ingestion, reducing infrastructure costs while enabling AI detection and response on third-party data at scale.
“Since its founding, SentinelOne has focused on AI and automation to offer those who defend our world a decisive operational advantage,” said Tomer Weingarten, co-founder and CEO of SentinelOne. «Many of the largest and most important organizations rely on our portfolio of AI security solutions to protect the use of AI and enhance the work of expert analysts. With these new innovations, they can now capture and validate security data in real-time within the Singularity platform and have comprehensive, human-supervised investigations to accelerate security operations at machine speed, today. These new innovations build on our high-quality expertise to ensure that customers can confidently harness the full power of AI today, knowing that their businesses are secure, well-governed and resilient against future threats.”






