AI Defense · Canada and USA

AI Defense: cybersecurity for the AI your business already uses.

Find the AI tools and agents your people use, keep customer and company data out of the wrong ones, and protect the AI apps you build. Delivered with Sophos AI Defense and TrendAI Vision One AI Security.

In plain terms: AI brings two new problems. Your data can leak into AI tools nobody approved, and the AI apps and agents you run can be tricked into doing harm. AI Defense covers both, mostly through security products you may already own.

Sophos Silver Partner. Sophos and TrendAI quoted in CAD and USD. Offices in Markham, Ontario and Dallas, Texas.

AI risk in numbers

Recent research on how AI is creating new ways to lose data. Each figure links to its source.

82%
of organizations have unknown AI agents running in their IT infrastructure
13%
reported breaches of AI models or apps, and 97% of those lacked AI access controls
62%
of cybersecurity leaders said their organization faced a deepfake attack
26%
of files uploaded to GenAI tools contained sensitive data

TrendAI's global AI study of 3,700 decision makers found 67% felt pressured to approve AI despite security concerns, and only 38% have comprehensive AI policies. Source

Six AI risks, the standard behind each, and what fixes it

Each row shows what can go wrong, which standard or rule covers it, and the products that close the gap. Orange links are Sophos and other products; blue links are TrendAI.

1Shadow AI and data leaking into AI tools

Staff paste customer records, code and contracts into AI tools your business has no agreement with.

One in five organizations reported a breach due to shadow AI, and organizations with high levels of shadow AI saw breach costs $670K higher on average. Source

Standards that apply

OWASP LLM02 Sensitive information disclosureNIST AI RMF GovernISO/IEC 42001

2AI agents nobody approved

Agents connect to email, files and business systems and act on their own, with whatever access they were given.

82% of organizations have unknown AI agents in their IT infrastructure. Source

Standards that apply

OWASP LLM06 Excessive agencyOWASP Top 10 for Agentic ApplicationsNIST AI RMF Map

3Prompt injection

Hidden instructions in an email, web page or file trick your AI into leaking data or taking an action.

32% of cybersecurity leaders said their organization faced prompt-based attacks on its AI applications. Source

Standards that apply

OWASP LLM01 Prompt injectionMITRE ATLAS

4Weak spots in the AI apps you build

Chatbots and AI features can leak their instructions, trust bad output or run up costs if they are not tested and guarded.

13% of organizations reported breaches of AI models or apps; 97% of those lacked AI access controls. Source

Standards that apply

OWASP LLM05 Improper output handlingOWASP LLM07 System prompt leakageOWASP LLM10 Unbounded consumptionNIST AI 600-1

5Exposed AI servers and tool connections

AI servers and MCP tool connectors left open on the internet give attackers a direct way in.

TrendAI found 1,467 exposed MCP servers, nearly triple the 492 it found in July 2025. Source

Standards that apply

OWASP LLM03 Supply chainNIST AI RMF Manage

6AI used against you: deepfakes and AI-written phishing

A cloned voice or video of an executive, or a flawless phishing email, gets money moved or a password handed over.

62% of cybersecurity leaders said their organization faced a deepfake attack. Source

Standards that apply

NYDFS AI guidance (2024)NIST AI RMF Manage
Not sure how much AI your people already use?Ask for an AI use review. A Nuformat specialist recommends the AI Defense setup for what you run today, at no charge.

Two jobs: use AI safely, and build AI safely

Most organizations need the first job now. If you build chatbots, AI features or agents, you need the second as well.

Use AI safely

For every organization whose people use AI tools. Sophos AI Defense works in four steps. Source

  1. 1
    DiscoverReveals AI tools, agents and activity across users and devices, including shadow AI and agents nobody approved.
  2. 2
    AssessScores risk in context, weighing identity, permissions, location, data access and behavior together.
  3. 3
    EnforceApplies guardrails, including controls on prompts and agent behavior, without blocking the work people need to do.
  4. 4
    RespondFeeds AI activity into detection and response as a security signal, for your team or Sophos MDR.
BrowserEndpointNetwork

Sees AI use in three places, through Sophos Workspace Protection, Sophos Endpoint, Sophos Firewall and Sophos MDR. Source Prefer TrendAI? TrendAI ZTSA AI Service Access inspects traffic to GenAI services and stops sensitive data going out. Source

Build AI safely

For organizations that build AI apps, chatbots or agents. TrendAI covers development, deployment and runtime. Source

  1. 1
    See your AI estateAI Security Posture Management watches your AI infrastructure to cut data exposure and overall AI infrastructure risk.
  2. 2
    Test before launchAI Scanner simulates real-world attacks to find weaknesses such as data leakage and prompt injection.
  3. 3
    Guard in productionAI Guard filters prompts and responses in real time to block malicious prompts and sensitive data leaks.
  4. 4
    Govern agentsTrendAI's Agentic Governance Gateway, announced in March 2026, adds visibility and policy over what autonomous agents do. Ask us about availability.

AI Scanner and AI Guard run as a TrendAI-hosted service or self-hosted in your own environment. Source

Sophos AI Defense: what you need

An add-on for the Sophos detection and response products, not a separate product to deploy.

ItemDetails
Base productSophos EDR, Sophos XDR or Sophos MDR. Source
PlatformYour account upgraded to Sophos Fusion, which Sophos describes as the evolution of Sophos Central. Sophos says upgrades begin in October 2026 for partners and MSPs. Source Partner note
DeploymentNo new deployment: it uses the Sophos agents and products you already run. Source
AvailabilityEarly access opened in August 2026 for accounts on Sophos Fusion; general availability scheduled for October 2026. Source
LicensingLicensed as an add-on. Sophos does not publish list prices, so Nuformat quotes it against your seat count and base product.

TrendAI AI security, in the store

TrendAI Vision One modules for AI, each linked to the product in our store. Quoted in CAD or USD.

TrendAI

TrendAI Vision One AI Security

The umbrella module that protects both how your people use AI and the AI you build, across models, data and users, including shadow AI discovery and runtime protection against prompt injection and data exfiltration. Source

See TrendAI Vision One AI Security →
TrendAI

AI Application Security for SaaS

AI Scanner tests your AI apps for weaknesses before launch; AI Guard filters prompts and responses once they are live. Hosted by TrendAI. Source

See AI Application Security for SaaS →
TrendAI

AI Application Security, private cloud and on-premises

The same AI Scanner and AI Guard, self-hosted in your own environment. Source

See AI Application Security, private cloud and on-premises →
TrendAI

ZTSA AI Service Access

Sits between your people or apps and GenAI services, inspects that traffic, applies policy and stops sensitive data going out. TrendAI now calls it AI Secure Access. Source

See ZTSA AI Service Access →
TrendAI

ZTSA Internet and AI Service Access

Secure web access and AI service access in one subscription. Source

See ZTSA Internet and AI Service Access →
TrendAI

TrendAI Code Security

Finds security problems in code and containers, including the code behind your AI apps. Source

See TrendAI Code Security →

The standards and laws for AI security, in plain English

No single law covers AI security in Canada or the US yet, so most organizations work to these frameworks. Start with the OWASP list: it names the ten ways AI apps most often go wrong.

OWASP Top 10 for LLM Applications 2025 Source

LLM01

Prompt injection

Crafted input changes what the model does.

LLM02

Sensitive information disclosure

The model reveals private or confidential data.

LLM03

Supply chain

Risky third-party models, data or plug-ins.

LLM04

Data and model poisoning

Tampered training or fine-tuning data.

LLM05

Improper output handling

Other systems trust the model's output without checking it.

LLM06

Excessive agency

The AI has more access or freedom to act than it needs.

LLM07

System prompt leakage

Hidden instructions, and any secrets in them, get exposed.

LLM08

Vector and embedding weaknesses

Flaws in the search data store behind retrieval (RAG).

LLM09

Misinformation

Confident but false output that people rely on.

LLM10

Unbounded consumption

Runaway use that drives up cost or knocks the service over.

EU AI Act dates, after the 2026 Digital Omnibus Source

Matters to Canadian and US firms that sell AI systems or their output into the EU. EU timeline

  1. Feb 2, 2025Banned AI practices and AI literacy rules apply
  2. Aug 2, 2025Rules for general-purpose AI models apply
  3. Aug 2, 2026Transparency duties, such as labeling AI-generated content, apply; systems already on the market get until Dec 2, 2026 for watermarking
  4. Dec 2, 2027Stand-alone high-risk AI systems, moved from Aug 2026
  5. Aug 2, 2028High-risk AI built into regulated products
WhereStandard or ruleWhat it asks, in plain EnglishStatus
EverywhereOWASP Top 10 for LLM Applications 2025The ten most important security risks for apps built on large language models, used as a test and design checklist. SourcePublished 2025
EverywhereOWASP Top 10 for Agentic Applications 2026The top risks and mitigations for AI agents that plan and act on their own, built with input from over 100 security researchers and practitioners. SourcePublished December 2025
United States, used worldwideNIST AI Risk Management Framework 1.0 and the Generative AI Profile (NIST AI 600-1)Four functions for managing AI risk: Govern, Map, Measure and Manage. The profile applies them to generative AI. SourceVoluntary
InternationalISO/IEC 42001:2023A certifiable management system for AI: set up, run, maintain and keep improving how the organization governs its AI. SourceVoluntary, certifiable
InternationalMITRE ATLASA knowledge base of real-world attack tactics and techniques against AI systems, modeled on MITRE ATT&CK. SourceReference
European UnionEU AI Act, as amended by the Digital Omnibus (Regulation (EU) 2026/1744)Bans some AI uses, sets rules for general-purpose AI, and adds duties for high-risk systems. Applies to Canadian and US firms that sell AI or its output into the EU. SourceProhibitions from Feb 2, 2025; general-purpose AI from Aug 2, 2025; high-risk systems moved to Dec 2, 2027 and Aug 2, 2028
CanadaNo federal AI law yet; Voluntary Code of Conduct on advanced generative AIThe proposed Artificial Intelligence and Data Act (Bill C-27) died when Parliament was prorogued in January 2025. The 2023 voluntary code asks firms to test systems and secure them against attacks. SourceVoluntary
Canada, OntarioEnhancing Digital Security and Trust Act (Bill 194)Gives Ontario the power to regulate how designated public sector organizations use AI, alongside its new cyber rules for hospitals, school boards, colleges and universities. SourceCyber rules in force July 1, 2026
United States, New YorkNYDFS industry letter on AI cybersecurity risksNo new requirements, but tells regulated firms to cover AI in risk assessments, use MFA that resists deepfakes, train staff, monitor AI use and limit the data AI can reach. SourceGuidance, October 2024
United States, ColoradoSB 26-189 (replaces the 2024 Colorado AI Act)A narrower law on automated decision-making technology. SourceTakes effect Jan 1, 2027
United States, lawyersABA Formal Opinion 512Lawyers using generative AI keep their duties of competence, confidentiality, client communication and reasonable fees. SourceEthics opinion, July 2024

Status as of October 3, 2026. Check the linked source before relying on a date. This is general information, not legal advice.

Where to start

Four steps we take with customers. The first one usually changes the conversation, because most organizations find more AI in use than they expected.

Find the AI already in use

Turn on discovery with Sophos AI Defense to list the AI tools and agents in use, or see which AI services people reach with TrendAI ZTSA AI Service Access.

Write the rules

Decide which AI tools are approved and what data may go into them. The NIST AI RMF Govern function and ISO/IEC 42001 give the structure.

Enforce them

Block unapproved tools, keep sensitive data out of AI prompts and uploads, and guard the AI apps you build.

Watch and respond

Send AI activity into detection and response, so Sophos MDR or your team can act on it like any other alert.

Want this set up for you?Send us what you run today. We size Sophos AI Defense or TrendAI for it and quote in CAD or USD within two to three business days.

Frequently asked questions

What is AI Defense?

AI Defense is cybersecurity for AI. It finds the AI tools and agents people in your organization use, keeps sensitive data out of tools you have not approved, blocks attacks such as prompt injection, and protects the AI applications you build. Nuformat delivers it with Sophos AI Defense and TrendAI Vision One AI Security.

What does Sophos AI Defense do?

Sophos AI Defense works in four steps. It discovers AI tools, agents and activity, including shadow AI. It assesses risk in context, weighing identity, permissions, location, data access and behavior. It enforces guardrails, including controls on prompts and agent behavior. It feeds AI activity into detection and response. It sees AI use in the browser, on the endpoint and on the network.

Is Sophos AI Defense available now?

Sophos opened early access in August 2026 for accounts on Sophos Fusion and scheduled general availability for October 2026. It is an add-on for Sophos EDR, XDR and MDR customers who have been upgraded to Sophos Fusion, the evolution of Sophos Central, and Sophos says those upgrades begin in October 2026 for partners and MSPs. Nuformat confirms the status for your account when it quotes.

Do I need to install new software for Sophos AI Defense?

No. Sophos says AI Defense needs no new deployment. It builds on Sophos Workspace Protection, Sophos Endpoint, Sophos Firewall and Sophos MDR, so it works through the Sophos products you already run.

What is the difference between Sophos AI Defense and TrendAI AI security?

Sophos AI Defense focuses on how your people and agents use AI: finding it, scoring the risk and enforcing policy through Sophos products you already have. TrendAI covers that too with ZTSA AI Service Access, and adds tools for the AI you build: AI Scanner tests AI apps for weaknesses such as prompt injection before launch, AI Guard filters prompts and responses in real time, and AI Security Posture Management watches your AI infrastructure.

What is prompt injection?

Prompt injection is when someone hides instructions in the text an AI reads, such as an email, a web page or a document, so the AI ignores its own rules and leaks data or takes an action. It is the first item, LLM01, on the OWASP Top 10 for LLM Applications 2025.

What is shadow AI?

Shadow AI is AI use your organization has not approved or cannot see, such as staff using personal AI accounts for work. IBM's 2025 Cost of a Data Breach Report found one in five organizations reported a breach due to shadow AI.

Which AI rules apply in Canada and the United States?

Neither country has a broad federal AI security law. Canada's proposed Artificial Intelligence and Data Act died in January 2025, leaving a 2023 voluntary code. In the US, NYDFS has issued AI cybersecurity guidance for the firms it regulates, and Colorado's SB 26-189 takes effect January 1, 2027. Most organizations use the NIST AI Risk Management Framework, ISO/IEC 42001 and the OWASP Top 10 as their yardsticks, and the EU AI Act applies if you sell into Europe.

Sources
  1. Cloud Security Alliance, survey on unknown AI agents (418 respondents), April 21, 2026
  2. IBM Cost of a Data Breach Report 2025 (press release, July 2025)
  3. Gartner survey of 302 cybersecurity leaders on generative AI attacks, September 22, 2025
  4. TrendAI Global AI Study (3,700 decision makers), March 25, 2026
  5. TrendAI research, Update on exposed MCP servers, April 28, 2026
  6. Harmonic Security, sensitive data in GenAI uploads, November 13, 2025
  7. Sophos, Sophos AI Defense (blog)
  8. Sophos, AI Defense product page
  9. Sophos AI Defense solution brief
  10. Sophos partner news, Sophos AI Defense
  11. Sophos press release, Sophos Fusion, July 2026
  12. Sophos AI Security Report 2026, July 2026
  13. Sophos, Workspace Protection enables safe GenAI adoption (blog)
  14. TrendAI, Proactive AI security (TrendAI Vision One AI Security)
  15. TrendAI, AI Application Security (AI Scanner and AI Guard)
  16. TrendAI documentation, AI Scanner and AI Guard
  17. TrendAI, ZTSA AI Secure Access
  18. TrendAI documentation, AI Security Posture Management
  19. TrendAI press release, Agentic Governance Gateway, March 24, 2026
  20. Trend Micro research, AI-generated media drives real-world fraud, July 9, 2025
  21. OWASP Top 10 for LLM Applications 2025
  22. OWASP Top 10 for Agentic Applications 2026 (announcement, December 2025)
  23. NIST AI Risk Management Framework 1.0 (AI 100-1), January 2023
  24. NIST AI 600-1, Generative AI Profile, July 2024
  25. ISO/IEC 42001:2023, AI management systems
  26. MITRE ATLAS
  27. European Commission AI Act Service Desk, implementation timeline
  28. White & Case, EU AI Omnibus enters into force (Regulation (EU) 2026/1744), July 2026
  29. DLA Piper, Canadian privacy and AI horizon shifts again (Bill C-27), January 2025
  30. Government of Canada, Voluntary Code of Conduct on advanced generative AI systems, September 2023
  31. Government of Ontario, Enhancing Digital Security and Trust Act
  32. NYDFS industry letter, Cybersecurity Risks Arising from Artificial Intelligence, October 16, 2024
  33. Seyfarth, Colorado enacts artificial intelligence replacement law (SB 26-189), May 2026
  34. ABA Formal Opinion 512, Generative Artificial Intelligence Tools, July 29, 2024