Find the AI tools and agents your people use, keep customer and company data out of the wrong ones, and protect the AI apps you build. Delivered with Sophos AI Defense and TrendAI Vision One AI Security. Sophos Silver Partner. Sophos and TrendAI quoted in CAD and USD. Offices in Markham, Ontario and Dallas, Texas. Recent research on how AI is creating new ways to lose data. Each figure links to its source. TrendAI's global AI study of 3,700 decision makers found 67% felt pressured to approve AI despite security concerns, and only 38% have comprehensive AI policies. Source Each row shows what can go wrong, which standard or rule covers it, and the products that close the gap. Orange links are Sophos and other products; blue links are TrendAI. Staff paste customer records, code and contracts into AI tools your business has no agreement with. One in five organizations reported a breach due to shadow AI, and organizations with high levels of shadow AI saw breach costs $670K higher on average. Source Standards that apply Agents connect to email, files and business systems and act on their own, with whatever access they were given. 82% of organizations have unknown AI agents in their IT infrastructure. Source Standards that apply What fixes it Hidden instructions in an email, web page or file trick your AI into leaking data or taking an action. 32% of cybersecurity leaders said their organization faced prompt-based attacks on its AI applications. Source Standards that apply Chatbots and AI features can leak their instructions, trust bad output or run up costs if they are not tested and guarded. 13% of organizations reported breaches of AI models or apps; 97% of those lacked AI access controls. Source Standards that apply AI servers and MCP tool connectors left open on the internet give attackers a direct way in. TrendAI found 1,467 exposed MCP servers, nearly triple the 492 it found in July 2025. Source Standards that apply What fixes it A cloned voice or video of an executive, or a flawless phishing email, gets money moved or a password handed over. 62% of cybersecurity leaders said their organization faced a deepfake attack. Source Standards that apply What fixes it Most organizations need the first job now. If you build chatbots, AI features or agents, you need the second as well. For every organization whose people use AI tools. Sophos AI Defense works in four steps. Source Sees AI use in three places, through Sophos Workspace Protection, Sophos Endpoint, Sophos Firewall and Sophos MDR. Source Prefer TrendAI? TrendAI ZTSA AI Service Access inspects traffic to GenAI services and stops sensitive data going out. Source For organizations that build AI apps, chatbots or agents. TrendAI covers development, deployment and runtime. Source AI Scanner and AI Guard run as a TrendAI-hosted service or self-hosted in your own environment. Source An add-on for the Sophos detection and response products, not a separate product to deploy. TrendAI Vision One modules for AI, each linked to the product in our store. Quoted in CAD or USD. The umbrella module that protects both how your people use AI and the AI you build, across models, data and users, including shadow AI discovery and runtime protection against prompt injection and data exfiltration. Source AI Scanner tests your AI apps for weaknesses before launch; AI Guard filters prompts and responses once they are live. Hosted by TrendAI. Source The same AI Scanner and AI Guard, self-hosted in your own environment. Source Sits between your people or apps and GenAI services, inspects that traffic, applies policy and stops sensitive data going out. TrendAI now calls it AI Secure Access. Source Secure web access and AI service access in one subscription. Source Finds security problems in code and containers, including the code behind your AI apps. Source No single law covers AI security in Canada or the US yet, so most organizations work to these frameworks. Start with the OWASP list: it names the ten ways AI apps most often go wrong. Crafted input changes what the model does. The model reveals private or confidential data. Risky third-party models, data or plug-ins. Tampered training or fine-tuning data. Other systems trust the model's output without checking it. The AI has more access or freedom to act than it needs. Hidden instructions, and any secrets in them, get exposed. Flaws in the search data store behind retrieval (RAG). Confident but false output that people rely on. Runaway use that drives up cost or knocks the service over. Matters to Canadian and US firms that sell AI systems or their output into the EU. EU timeline Status as of October 3, 2026. Check the linked source before relying on a date. This is general information, not legal advice. Each industry page ties its top risks to the rules that apply. Five of them include an AI risk row. Four steps we take with customers. The first one usually changes the conversation, because most organizations find more AI in use than they expected. Turn on discovery with Sophos AI Defense to list the AI tools and agents in use, or see which AI services people reach with TrendAI ZTSA AI Service Access. Decide which AI tools are approved and what data may go into them. The NIST AI RMF Govern function and ISO/IEC 42001 give the structure. Block unapproved tools, keep sensitive data out of AI prompts and uploads, and guard the AI apps you build. Send AI activity into detection and response, so Sophos MDR or your team can act on it like any other alert. AI Defense is cybersecurity for AI. It finds the AI tools and agents people in your organization use, keeps sensitive data out of tools you have not approved, blocks attacks such as prompt injection, and protects the AI applications you build. Nuformat delivers it with Sophos AI Defense and TrendAI Vision One AI Security. Sophos AI Defense works in four steps. It discovers AI tools, agents and activity, including shadow AI. It assesses risk in context, weighing identity, permissions, location, data access and behavior. It enforces guardrails, including controls on prompts and agent behavior. It feeds AI activity into detection and response. It sees AI use in the browser, on the endpoint and on the network. Sophos opened early access in August 2026 for accounts on Sophos Fusion and scheduled general availability for October 2026. It is an add-on for Sophos EDR, XDR and MDR customers who have been upgraded to Sophos Fusion, the evolution of Sophos Central, and Sophos says those upgrades begin in October 2026 for partners and MSPs. Nuformat confirms the status for your account when it quotes. No. Sophos says AI Defense needs no new deployment. It builds on Sophos Workspace Protection, Sophos Endpoint, Sophos Firewall and Sophos MDR, so it works through the Sophos products you already run. Sophos AI Defense focuses on how your people and agents use AI: finding it, scoring the risk and enforcing policy through Sophos products you already have. TrendAI covers that too with ZTSA AI Service Access, and adds tools for the AI you build: AI Scanner tests AI apps for weaknesses such as prompt injection before launch, AI Guard filters prompts and responses in real time, and AI Security Posture Management watches your AI infrastructure. Prompt injection is when someone hides instructions in the text an AI reads, such as an email, a web page or a document, so the AI ignores its own rules and leaks data or takes an action. It is the first item, LLM01, on the OWASP Top 10 for LLM Applications 2025. Shadow AI is AI use your organization has not approved or cannot see, such as staff using personal AI accounts for work. IBM's 2025 Cost of a Data Breach Report found one in five organizations reported a breach due to shadow AI. Neither country has a broad federal AI security law. Canada's proposed Artificial Intelligence and Data Act died in January 2025, leaving a 2023 voluntary code. In the US, NYDFS has issued AI cybersecurity guidance for the firms it regulates, and Colorado's SB 26-189 takes effect January 1, 2027. Most organizations use the NIST AI Risk Management Framework, ISO/IEC 42001 and the OWASP Top 10 as their yardsticks, and the EU AI Act applies if you sell into Europe.AI Defense: cybersecurity for the AI your business already uses.
AI risk in numbers
Six AI risks, the standard behind each, and what fixes it
1Shadow AI and data leaking into AI tools
2AI agents nobody approved
3Prompt injection
4Weak spots in the AI apps you build
5Exposed AI servers and tool connections
6AI used against you: deepfakes and AI-written phishing
Two jobs: use AI safely, and build AI safely
Use AI safely
Build AI safely
Sophos AI Defense: what you need
Item Details Base product Sophos EDR, Sophos XDR or Sophos MDR. Source Platform Your account upgraded to Sophos Fusion, which Sophos describes as the evolution of Sophos Central. Sophos says upgrades begin in October 2026 for partners and MSPs. Source Partner note Deployment No new deployment: it uses the Sophos agents and products you already run. Source Availability Early access opened in August 2026 for accounts on Sophos Fusion; general availability scheduled for October 2026. Source Licensing Licensed as an add-on. Sophos does not publish list prices, so Nuformat quotes it against your seat count and base product. TrendAI AI security, in the store
TrendAI Vision One AI Security
AI Application Security for SaaS
AI Application Security, private cloud and on-premises
ZTSA AI Service Access
ZTSA Internet and AI Service Access
TrendAI Code Security
The standards and laws for AI security, in plain English
OWASP Top 10 for LLM Applications 2025 Source
Prompt injection
Sensitive information disclosure
Supply chain
Data and model poisoning
Improper output handling
Excessive agency
System prompt leakage
Vector and embedding weaknesses
Misinformation
Unbounded consumption
EU AI Act dates, after the 2026 Digital Omnibus Source
Where Standard or rule What it asks, in plain English Status Everywhere OWASP Top 10 for LLM Applications 2025 The ten most important security risks for apps built on large language models, used as a test and design checklist. Source Published 2025 Everywhere OWASP Top 10 for Agentic Applications 2026 The top risks and mitigations for AI agents that plan and act on their own, built with input from over 100 security researchers and practitioners. Source Published December 2025 United States, used worldwide NIST AI Risk Management Framework 1.0 and the Generative AI Profile (NIST AI 600-1) Four functions for managing AI risk: Govern, Map, Measure and Manage. The profile applies them to generative AI. Source Voluntary International ISO/IEC 42001:2023 A certifiable management system for AI: set up, run, maintain and keep improving how the organization governs its AI. Source Voluntary, certifiable International MITRE ATLAS A knowledge base of real-world attack tactics and techniques against AI systems, modeled on MITRE ATT&CK. Source Reference European Union EU AI Act, as amended by the Digital Omnibus (Regulation (EU) 2026/1744) Bans some AI uses, sets rules for general-purpose AI, and adds duties for high-risk systems. Applies to Canadian and US firms that sell AI or its output into the EU. Source Prohibitions from Feb 2, 2025; general-purpose AI from Aug 2, 2025; high-risk systems moved to Dec 2, 2027 and Aug 2, 2028 Canada No federal AI law yet; Voluntary Code of Conduct on advanced generative AI The proposed Artificial Intelligence and Data Act (Bill C-27) died when Parliament was prorogued in January 2025. The 2023 voluntary code asks firms to test systems and secure them against attacks. Source Voluntary Canada, Ontario Enhancing Digital Security and Trust Act (Bill 194) Gives Ontario the power to regulate how designated public sector organizations use AI, alongside its new cyber rules for hospitals, school boards, colleges and universities. Source Cyber rules in force July 1, 2026 United States, New York NYDFS industry letter on AI cybersecurity risks No new requirements, but tells regulated firms to cover AI in risk assessments, use MFA that resists deepfakes, train staff, monitor AI use and limit the data AI can reach. Source Guidance, October 2024 United States, Colorado SB 26-189 (replaces the 2024 Colorado AI Act) A narrower law on automated decision-making technology. Source Takes effect Jan 1, 2027 United States, lawyers ABA Formal Opinion 512 Lawyers using generative AI keep their duties of competence, confidentiality, client communication and reasonable fees. Source Ethics opinion, July 2024 AI risk in your industry
Where to start
Find the AI already in use
Write the rules
Enforce them
Watch and respond
Frequently asked questions
What is AI Defense?
What does Sophos AI Defense do?
Is Sophos AI Defense available now?
Do I need to install new software for Sophos AI Defense?
What is the difference between Sophos AI Defense and TrendAI AI security?
What is prompt injection?
What is shadow AI?
Which AI rules apply in Canada and the United States?
AI Defense · Canada and USA
In plain terms: AI brings two new problems. Your data can leak into AI tools nobody approved, and the AI apps and agents you run can be tricked into doing harm. AI Defense covers both, mostly through security products you may already own.
82%
of organizations have unknown AI agents running in their IT infrastructure
13%
reported breaches of AI models or apps, and 97% of those lacked AI access controls
OWASP LLM02 Sensitive information disclosureNIST AI RMF GovernISO/IEC 42001
OWASP LLM06 Excessive agencyOWASP Top 10 for Agentic ApplicationsNIST AI RMF Map
OWASP LLM01 Prompt injectionMITRE ATLAS
OWASP LLM05 Improper output handlingOWASP LLM07 System prompt leakageOWASP LLM10 Unbounded consumptionNIST AI 600-1
OWASP LLM03 Supply chainNIST AI RMF Manage
NYDFS AI guidance (2024)NIST AI RMF Manage
Not sure how much AI your people already use?Ask for an AI use review. A Nuformat specialist recommends the AI Defense setup for what you run today, at no charge.
DiscoverReveals AI tools, agents and activity across users and devices, including shadow AI and agents nobody approved.
AssessScores risk in context, weighing identity, permissions, location, data access and behavior together.
EnforceApplies guardrails, including controls on prompts and agent behavior, without blocking the work people need to do.
RespondFeeds AI activity into detection and response as a security signal, for your team or Sophos MDR.
BrowserEndpointNetwork
See your AI estateAI Security Posture Management watches your AI infrastructure to cut data exposure and overall AI infrastructure risk.
Test before launchAI Scanner simulates real-world attacks to find weaknesses such as data leakage and prompt injection.
Guard in productionAI Guard filters prompts and responses in real time to block malicious prompts and sensitive data leaks.
Govern agentsTrendAI's Agentic Governance Gateway, announced in March 2026, adds visibility and policy over what autonomous agents do. Ask us about availability.
TrendAI
TrendAI
TrendAI
TrendAI
TrendAI
TrendAI
LLM01
LLM02
LLM03
LLM04
LLM05
LLM06
LLM07
LLM08
LLM09
LLM10
HealthcarePatient data pasted into AI tools
EducationTop risks, rules and the Sophos stack
FinancialWire fraud and AI-made impersonation
LogisticsTop risks, rules and the Sophos stack
LegalClient confidences in AI tools
HospitalityTop risks, rules and the Sophos stack
ProfessionalTop risks, rules and the Sophos stack
MiningTop risks, rules and the Sophos stack
ManufacturingDrawings and controlled data leaking out
StartupsCode and customer data in personal AI accounts
Want this set up for you?Send us what you run today. We size Sophos AI Defense or TrendAI for it and quote in CAD or USD within two to three business days.
Sources

