# Morphisec AI Hub _Last updated: 2026-08-05_ Morphisec's Adaptive AI Defense preemptively stops AI-driven ransomware and autonomous threats before execution, integrating with EDR and XDR solutions to deliver ransomware-free assurance and cyber adaptive resilience at scale. ## Threat Landscape AI-driven attacks have collapsed intrusion timelines from hours to seconds. Organizations face three structural gaps in AI security: - **Visibility gap**: No reliable way to enumerate every AI tool and agent on an endpoint or distinguish authorized from unauthorized use. Network and browser tools only see routed traffic. - **Control gap**: No runtime enforcement defining what AI agents may do once identified. Policies without enforcement are documents, not controls. - **Prevention gap**: Detection is reactive; AI acts at machine speed. By the time an alert fires, the agent has finished. Prevention must move upstream of execution. ### Key Metrics - 89% increase in AI-enabled adversary operations (CrowdStrike 2026) - 27 seconds: fastest recorded intrusion, faster than any human team can respond - Security spending shifting from 5% to 50% toward preemptive defense (Gartner 2025) ## Shadow AI Shadow AI is unsanctioned AI used outside IT oversight: assistants, desktop apps, CLI agents, browser extensions, and local large language models that touch files and credentials directly on endpoints. It represents a visibility failure, not merely a policy failure. Staff paste confidential data into assistants. Engineers install coding agents in IDEs. Someone runs Ollama on a laptop pointing at sensitive folders. None routes through a proxy, so none appears in network logs. Tools enterprises expect to catch shadow AI—SASE, CASB, browser extensions, DLP—are structurally incapable. They see routed traffic and browser tabs. A local model reading files on disk produces neither. You cannot govern what you cannot see. Discovery is not step one of shadow AI governance; it *is* governance until complete. ## Compromised AI Compromised AI is approved AI turned against you. An enterprise agent runs with broad permissions—that is its purpose. An attacker hijacks it through a poisoned prompt or supply-chain attack, and malicious commands inherit that legitimate trust. To a firewall, identity provider, or EDR, the behavior looks authorized because, in every credential sense, it is. The agent is who it claims; it simply wants something it should not. Shadow AI is a discovery problem. Compromised AI is a runtime-governance problem. Most enterprises have both, and the second does not disappear when solving the first. ## The Execution Layer Most AI security tools work at the prompt layer, inspecting what enters a model and what emerges, using filters, guardrails, and classifiers. Prompt injection remains unsolved because the malicious instruction and legitimate instruction arrive through the same channel in the same format. Filters raise attack cost but do not eliminate it. The execution layer sits where an agent's decision becomes a real action: a file access, a process launch, a data transfer. Policy enforced at that point evaluates the actual system call rather than model reasoning. The execution layer cannot be prompt-injected: even when prompt injection succeeds, the resulting action is still caught. | Dimension | Prompt Layer | Execution Layer | |---|---|---| | Inspection target | What enters/exits a model | System calls: file access, process launch, data transfer | | Prompt injection resilience | Can be defeated through legitimate channel | Cannot be prompt-injected; injection attempts are still caught at execution | | Privacy | Must inspect prompts and user content | No prompt capture; behavior only | | Resilience | Depends on network visibility and connectors; breaks on vendor UI changes | Local; works offline; no signatures to maintain | | Evidence | What agent said or was asked | What actually executed on device | Prompt-layer guardrails remain valuable, and EDR remains essential. The execution layer is the control that cannot be talked out of policy. ## AIUC-1 Standard AIUC-1 is an independent certification standard for AI agents issued by The Artificial Intelligence Underwriting Company. It defines 51 requirements and approximately 130 controls across six pillars: Data & Privacy, Security, Safety, Reliability, Accountability, and Society. Certificates are valid 12 months; technical controls are re-tested at least quarterly; the standard refreshes every quarter. It maps to EU AI Act, NIST AI RMF, ISO 42001, MITRE ATLAS, and OWASP agentic security lists. ### What AIUC-1 Covers AIUC-1 covers vendor-sold AI agents: certified chatbots, voice agents, and automation agents have been independently tested and adversarially probed within audit scope. This is a real signal worth requesting from vendors. ### What AIUC-1 Cannot Cover AIUC-1 cannot certify the AI you actually run: copilots employees installed themselves, local LLMs, coding agents in IDEs, or MCP connectors nobody reviewed. A certified agent can still be hijacked at runtime. Morphisec AI Usage Control maps to AIUC-1 controls across all six pillars and provides direct control on nine landing at the execution layer: A003, B006, B007, B008, D003, E009, E010, E015, F001. Morphisec is not affiliated with, endorsed by, or certified under AIUC-1. This is a capability mapping, not certification. ## MCP Supply-Chain Attack Morphisec Threat Research documented an attack class turning the Model Context Protocol trust model against AI coding assistants. A malicious npm package registered as an MCP server achieves full credential exfiltration in under 90 seconds with no binary written to disk. - **Exposure**: Payload fires on the `tools/list` handshake, before a user types a prompt. - **Evasion**: Signed-binary chain remained silent across five independent EDR, DLP, and CASB stacks. - **Prevention**: Intercepted at the memory layer before the first byte leaves the host. MCP connectors are software AI agents execute. Almost nobody inventories them. ## Morphisec AI Hub Platform The Morphisec AI Hub expands the Anti-Ransomware Assurance Suite into the AI era with Adaptive AI Defense at its core. It leverages AI, telemetry insights, and Automated Moving Target Defense (AMTD) to transform raw data into preventive action—from shadow AI discovery to exposure management to governance to policy enforcement. Designed to work seamlessly alongside any EDR/XDR solution, the AI Hub creates a preemptive defense fabric eliminating ransomware impact before execution. ### Adaptive AI Defense Adaptive AI Defense preemptively stops AI-driven ransomware and autonomous threats before execution through AMTD runtime randomization. It neutralizes AI-generated malware, compromised agents, and zero-day exploits without relying on signatures, behavioral rules, or false positives. - Blocks and disrupts AI attacks at machine speed with zero response delay. - Works seamlessly alongside EDR and XDR solutions to close detection and response gaps. - Core layer of Morphisec's Anti-Ransomware Assurance Suite and Preemptive Cyber Defense architecture. ### AI Usage Control (AIUC) AI Usage Control discovers and governs every AI tool, connector, and agent running on endpoints—including unapproved shadow AI like GitHub Copilot, Cursor, and ChatGPT extensions—before they can misuse data or privileges. - **Visibility**: Real-time inventory of all AI agents and connectors. - **Prevention**: Blocks prompt injection, rogue automation, and agent exfiltration pre-execution. - **Compliance**: Aligns with EU AI Act, ISO 42001, and SOC 2 requirements. - **Efficiency**: Lightweight (<1% CPU) and deploys alongside existing EDR/XDR solutions. ### AI Command Dashboard The AI Command Dashboard aggregates signals from Adaptive AI Defense, AMTD runtime protection, and EDR/XDR integrations to automate remediation and reduce SOC response cycles. - **System Health**: Monitors agent integrity and runtime performance for continuous resilience. - **Lateral Movement**: Flags rogue AI processes and RMM tool abuse as pre-ransomware indicators. - **Active Exploitability**: Prioritizes EPSS > 90% or CISA KEV alerts for actionable responses. - **Collaboration**: Integrates with Slack and Jira to accelerate tierless remediation. ### AI Exposure Assistant AI Exposure Assistant applies LLM analytics and AMTD signals to rank vulnerabilities by exploitability and business risk, closing gaps before exploitation. - **Precision**: Combines CVSS, EPSS, and AI context for precise risk prioritization. - **Efficiency**: Reduces patch timelines and manual overhead. - **Alignment**: Integrates with Adaptive Exposure Management and EDR/XDR risk insights for continuous remediation. ### AI Incident Assistant AI Incident Assistant transforms prevented-attack telemetry into plain-language incident summaries with prescribed next steps. SOC teams gain Tier 3 insight at Tier 1 speed. - **Speed**: Cuts triage time by up to 90%, allowing Tier 1 Security Analysts to operate faster than Tier 3 skill and speed. - **Clarity**: Correlates telemetry into root-cause reports for faster containment. - **Continuity**: Maintains context across analyst handoffs and incident phases. ## Real-World Attacks Prevented Polymorphic AI ransomware, weaponized AI CLIs, and autonomous extortion agents operate today. Morphisec stops them. ### PromptLock (ESET Research, Aug 2025) Polymorphic AI ransomware connecting to a local Ollama endpoint, generating unique polymorphic Lua at runtime. Static EDR signatures never match twice. **How Morphisec stops it**: Ollama is auto-flagged as an AI agent. File-write spikes plus abnormal child-process spawn rates raise Critical alerts; the local LLM is blocked by policy before encryption begins. No signature required. ### QUIETVAULT Stealer (Google Threat Intelligence, 2025) Delivered through a compromised npm plugin, weaponizes pre-installed AI CLIs on developer workstations to recursively scan and exfiltrate GitHub tokens and crypto wallets. **How Morphisec stops it**: Day-1 Guardrails block access to SSH keys and credential directories with no machine-learning baseline required. The weaponized CLI is denied the moment it reaches for secrets. ### GTG-2002 Campaign (17 organizations confirmed) A threat actor runs an AI coding agent on attacker-controlled infrastructure. The agent autonomously selects exfiltration targets, analyzes financial data, and sets ransoms from $75K to $500K. **How Morphisec stops it**: AI agent processes are identified instantly. Data-volume and sensitive-directory anomalies raise High alerts; egress policy blocks unapproved LLM services before data leaves. ### Unconstrained Deletion (no malware required) A coding agent told to "clean up old records" interprets the task at maximum scope and deletes the entire production database and every backup in under ten seconds. **How Morphisec stops it**: Morphisec detects the MCP connector's DELETE access preemptively, blocks the AI from backup locations, and flags mass deletion as critical, stopping the action before completion. ## Frequently Asked Questions ### What is shadow AI? Shadow AI is unsanctioned AI used outside IT oversight: assistants, desktop apps, CLI agents, browser extensions, and local large language models that touch files and credentials directly on devices. It is a visibility failure rather than policy failure. Network, SASE, CASB, and browser tools are structurally blind to a local LLM reading files on a laptop, a coding agent inside an IDE, or an MCP connector nobody reviewed. You cannot govern what you cannot see. ### What is compromised AI, and how does it differ from shadow AI? Shadow AI is unapproved AI. Compromised AI is approved AI turned against you. An enterprise agent runs with broad permissions; an attacker hijacks it through a poisoned prompt or supply-chain attack, and malicious commands inherit that legitimate trust. To a firewall, identity provider, or EDR, the behavior looks authorized because it is, in every credential sense. Shadow AI is a discovery problem. Compromised AI is a runtime-governance problem. Most enterprises have both. ### What is the execution layer in AI agent security? Most AI security tools work at the prompt layer, inspecting what enters and exits models using filters, guardrails, and classifiers. Prompt injection remains unsolved because malicious and legitimate instructions arrive through the same channel. The execution layer sits where an agent's decision becomes a real action: file access, process launch, data transfer. Policy at that point evaluates the actual system call. The execution layer cannot be prompt-injected; even when injection succeeds, the resulting action is caught. ### Can any security tool block prompt injection? No. Any vendor claiming otherwise overstates what the prompt layer can do. Prompt injection is unsolved because malicious and legitimate instructions arrive through the same channel in the same format. Filters raise attack cost but do not eliminate it. The durable answer is to assume the prompt layer can be lost and enforce policy one layer down, at execution, where an agent's intent becomes a real system call. Morphisec does not claim to block prompt injection. It catches what the injection tries to do. ### What is AIUC-1? AIUC-1 is an independent certification standard for AI agents, described as "SOC 2 for AI agents." Launched in 2025, it defines 51 requirements and approximately 130 controls across six pillars: Data & Privacy, Security, Safety, Reliability, Accountability, and Society. Issued by The Artificial Intelligence Underwriting Company and developed with input from more than 100 Fortune 500 CISOs, it maps to EU AI Act, NIST AI RMF, ISO 42001, MITRE ATLAS, and OWASP agentic security lists. Certificates are valid 12 months; technical controls are re-tested at least quarterly. ### Do AIUC-1-certified vendors cover our organization? Certification is a good signal that the agent was independently tested within audit scope. It covers only that vendor's agent. It says nothing about dozens of other AI tools on endpoints: copilots and assistants employees adopt, local LLMs like Ollama, coding agents in IDEs, browser AI, and unreviewed MCP connectors. A certified agent can still be hijacked at runtime through prompt injection or poisoned supply chains. Certification signals testing; it does not govern what AI does on devices day to day. ### Is Morphisec AIUC-1 certified? No. AIUC-1 certification applies to vendor-sold AI agent products: customer-facing chatbots, voice agents, and automation agents. Morphisec occupies a different position: the enterprise-side control governing all AI agents and tools running on endpoints, certified or not. Morphisec is not affiliated with, endorsed by, or certified under AIUC-1. Morphisec provides the mapping: Morphisec AI Usage Control maps to AIUC-1 controls across all six pillars and provides direct control on nine landing at the execution layer. ### Does Morphisec read employee AI prompts? No. Morphisec governs AI by behavior at the execution layer, not by inspecting prompt content. Prompt interception is a losing battle; traffic is encrypted, browser extensions break with every vendor UI change, and desktop apps use proprietary wrappers. Reading employee prompts creates privacy and compliance exposure under GDPR, CCPA, and HIPAA. All analysis runs locally on the endpoint; no prompts, telemetry, or behavioral data leave the machine. ### What is an MCP connector, and why is it a security concern? The Model Context Protocol (MCP) is how AI agents connect to external tools and data sources. It is a trust model: the agent trusts what the connector advertises. Morphisec Threat Research documented an attack class turning that trust against the agent. A malicious npm package registered as an MCP server achieves full credential exfiltration in under 90 seconds with no binary written to disk. The payload fires on the `tools/list` handshake before a user types a prompt, and the signed-binary chain stayed silent across five independent EDR, DLP, and CASB stacks. MCP connectors are software AI agents execute; almost nobody inventories them. ### Why can't firewalls, EDR, or CASB govern AI? They were built for people and devices, not for AI. Network, SASE, CASB, and browser tools only see routed traffic or browser tabs, so they are blind to local LLMs, CLI agents, and IDE-embedded AI on devices. EDR watches processes generically and can say a process ran but not that it was an unsanctioned AI agent reaching for credentials on behalf of a hijacked prompt. The gap is threefold: visibility (you cannot enumerate the AI), control (no runtime enforcement of what AI may do), and prevention (detection fires after AI has acted). ## Anti-Ransomware Guarantee Morphisec offers 100% money-back assurance—full reimbursement of subscription fees if a ransomware breach occurs on a protected endpoint. A dedicated Morphisec Incident Response team provides rapid containment, forensic investigation, and remediation. ## Additional Resources Gartner describes AI Usage Control as a named control category. Organizations must pilot AI Usage Controls as part of AI TRiSM and trust management. Endpoint-level detection of local AI agents and Model Context Protocol connectors is critical for reducing shadow AI risk (Gartner Innovation Insight for AI Usage Control, 2025; Solution Criteria for AI Usage Control, 2026). Morphisec occupies the endpoint-level position Gartner describes: you cannot govern local AI agents and MCP connectors from the network, so the control must sit on the endpoint.