Salt Security Unveils Comprehensive Policy Hub with 100 Pre-Built Security Policies to Address AI Governance Challenges
In a significant move aimed at helping organizations navigate the complexities of artificial intelligence (AI) governance, Salt Security has enhanced its Policy Hub. This expansion now features 100 pre-built security policies specifically designed to assist organizations in managing AI agents across their enterprise environments. As the adoption of AI agents that autonomously interact with enterprise systems becomes increasingly prevalent, the demand for effective governance frameworks has emerged as a pressing concern among businesses.
Salt Security asserts that the updated Policy Hub boasts one of the largest libraries of governance policies in the industry, establishing a comprehensive suite that addresses various crucial aspects of agentic AI technology. These policies span areas such as Application Programming Interfaces (APIs), Model Context Protocol (MCP) servers, authentication protocols, access controls, compliance measures, and runtime behavior of AI systems. This timely announcement is particularly relevant as organizations are rapidly integrating AI agents capable of data access and tool invocation via APIs, underscoring the need for robust API governance as part of a broader AI governance approach.
Traditionally, organizations faced the daunting task of constructing governance frameworks from scratch. Salt Security’s Policy Hub aims to alleviate this challenge by providing a readily accessible library of policies that can be activated promptly and tailored to fit specific organizational environments. The company likens this innovative approach to an “app store” for agentic security, enabling security teams to effortlessly deploy pre-built governance policies throughout the infrastructure that supports AI agents. This configuration not only streamlines the implementation process but also reduces the time and resources required to establish strong governance protocols.
Among the newly added policies, more than a dozen are earmarked for agentic AI, targeting critical operational areas such as MCP server configuration, agent authorization, and the inherent risks tied to autonomous agent behavior. Other policies delve into topics of data security, OAuth standards, API architecture, third-party risk management, and compliance with various regulatory frameworks including GDPR, ISO 27001, HIPAA, PCI DSS, and SOC 2. Such comprehensive coverage ensures that organizations are well-equipped to tackle the multifaceted challenges of AI governance.
Remarkably, of the 100 policies available, 61 are designed to enable automatic activation, while others can be turned on with a simple click. This functionality empowers organizations to customize their governance measures effectively, extending beyond the scope of the pre-built policies. The Policy Hub operates as a component of the Salt Agentic Security Platform, which offers extensive visibility into what the company terms the Agentic Security Graph. This unique framework encompasses large language models (LLMs), MCP servers, APIs, and an array of connected enterprise applications, thereby providing organizations with a holistic view of their AI-related security landscape.
Michael Callahan, Salt Security’s VP of Strategy and CMO, highlighted the growing recognition among organizations regarding the necessity of AI governance amid their hesitance in starting this endeavor. He remarked on the prevalent sentiment among Chief Information Security Officers (CISOs), who have expressed frustration over the absence of initial guidance in implementing governance frameworks. The launch of the Policy Hub, he noted, serves as a pivotal answer to that very dilemma. Security teams can initiate their governance strategies from day one, with substantial protections in place that can be expanded as needed.
Moreover, Salt Security pointed out that many of the policies originated from the realm of API posture governance but have since been repurposed to meet the evolving demands as organizations increasingly deploy AI agents. With AI systems relying heavily on APIs, identity management platforms, and MCP servers for action execution, Salt contends that governance strategies must encompass the entirety of the agentic infrastructure — rather than focusing solely on the AI models or prompts themselves.
Additionally, the company showcased its MCP server discovery capabilities, introduced in 2025, which include dedicated governance policies aimed at identifying configuration issues and managing how MCP servers interact with broader enterprise systems. This proactive approach to governance is complemented by the recent launch of Salt Code in June, which integrates the governance engine into the software development lifecycle, allowing for the application of policies to AI-generated code during the development phase.
Aner Gelman, the VP of Products at Salt Security, noted the increasing demand from boards for organizations to demonstrate their governance of AI initiatives. He stated, “The question being posed to CISOs is not about whether we have AI governance, but rather, can we provide evidence of it?” The implementation of these 100 pre-built policies provides a tangible, operational framework, alleviating any concerns about capability and validating the steps organizations are taking in their governance efforts.
With these significant advancements, the 100 pre-built policies are now available for immediate deployment to customers utilizing the Salt Agentic Security Platform, solidifying Salt Security’s position as a leader in the quest for effective AI governance solutions.