The finance team spins up an agent to reconcile vendor invoices against purchase orders. Someone grants it persistent access into the ERP and finance systems so it can pull the records it needs. Six months later, the access is still active, and the agent still runs on a schedule nobody remembers setting. The access tokens outlive the project they were issued for because nothing is watching the agent that holds them. No one knows who owns the agent and no one in security has reviewed its access or asked what it does with the data it consumes. Similar stories are playing out in customer service, engineering, HR, and marketing faster than security teams can track them.
AI Agent Visibility and Observability Platforms (AI-VOPs) are the category of security tooling built to close these gaps. A security team cannot enforce policy on an invisible agent, hold an owner accountable when none is registered, or judge the risk of unobserved behavior. AI-VOPs watch the agents themselves, regardless of what those agents are used for, who deployed them, or which system hosts them. To advance the conversation, KuppingerCole has formalized AI-VOP as its own market category and opened a Leadership Compass project to evaluate vendors and the market against a full set of requirements.
Why Agent Discovery Alone Isn't Enough
Agent discovery is only the starting point. In the blog You Cannot Secure the AI Agents You Don’t Know About, I made the straightforward case that organizations cannot secure or govern agents they cannot see. A follow-up post, AI Agent Observability: The Seven Controls Needed After Agent Discovery, went further. Knowing an agent exists tells a security team nothing about what it did, which credentials it used to do it, or whether the organization could reconstruct that activity in an audit. Three of the seven controls that post laid out were runtime telemetry and trace capture; interaction and delegation mapping; and behavioral analytics and policy violation monitoring. Each supplies something discovery cannot: agent behavior, chains of delegated authority, and the evidence a response team needs before it can act.
What AI-VOP Covers
The AI-VOP Market Definition lays out seven areas against which solutions will be evaluated:
- Agent discovery and visibility
- Agent inventory, ownership, and identity context
- Runtime telemetry and trace capture
- Interaction and delegation mapping
- Permission, credential, and tool access analysis
- Behavioral analytics and policy violation monitoring
- Explainability, audit, and governance reporting
Agent discovery and visibility means continuously discovering and tracking agents and agentic workflows across enterprise environments, including sanctioned and unsanctioned agents, shadow AI deployments, platform-native and developer-built agents, and agents embedded in SaaS, cloud, automation, and business applications. Agent inventory, ownership, and identity context adds the detail that makes a discovered agent governable: owner, creator, purpose, operating identity, delegated authority, and the users, service accounts, OAuth grants, API tokens, secrets, and connected resources underneath it.
Runtime telemetry and trace capture records prompts and responses, tool invocations, API calls, reasoning traces, Model Context Protocol (MCP) activity, code execution, data access events, errors, and cost and latency signals.
Interaction and delegation mapping traces the relationships and execution paths among agents, sub-agents, users, tools, APIs, and data sources, including the delegation chains that form when one agent acts under another's authority. Permission, credential, and tool access analysis flags access that is excessive, stale, over-privileged, transitive, or inconsistent with least privilege and separation of duties.
Behavioral analytics and policy violation monitoring evaluates agent activity against organizational policy and surfaces anomalies, suspicious tool use, and violations. Explainability, audit, and governance reporting explains how and why an agent reached a decision and produces tamper-resistant evidence for internal governance, EU AI Act, DORA, and NIST-CSF review.
Where the Category Boundary Sits
Vendors and other interested parties should weigh in on these seven areas. If you think the definition is missing a capability that belongs to the AI-VOP category or includes one that should carry less weight or sit outside of it, let us know. Where the boundary sits matters, because adjacent categories are already crowded. LLM and application observability tooling measures the quality of a model or an application; AI security posture management (AI-SPM) continuously assesses the configuration, exposure, and vulnerabilities of the AI estate itself (models, pipelines, datasets) and the infrastructure they run on. AI-VOP instead tracks the agent as an acting identity: what it reached, under whose credentials, and with what authorization.
We understand that most vendors will not offer pure AI-VOP solutions. Most will also span one or more of the other categories in KuppingerCole’s six-category agentic AI security framework as well as more traditional, non-AI security controls. This overlap is expected and normal in an early-stage market.
What Comes Next
KuppingerCole recently sent vendor invites for participation in the AI-VOP Leadership Compass. If you were missed, it is not too late to take part. The evaluation runs primarily using a technical questionnaire organized around the seven areas described above. If you think your solution should be included, reach out to KuppingerCole Analysts by mid-October 2026 and we will forward you the invite for your consideration.
An organization cannot govern, secure, or budget for what it cannot see. Agents that no one in security has reviewed often hold standing credentials, touch sensitive data, and act on someone’s behalf, whether or not that action was authorized. AI-VOP is the control layer that makes agents visible and keeps them monitored. Everything else in agent security and governance builds on top of this layer. If you are an enterprise security leader, start by asking how many agents are running in your environment and who owns them.