Coverage · September 2026 research

Coverage compared

Thirty controls for AI use on company computers, scored for seventeen security products from their public documentation, and for Lamplighter from what ships today. Select any cell in the grid to see the evidence behind its score.

Lamplighter
Endpoint agent and browser extension
67%20/30 shipped · 6 scheduled
Microsoft (Purview / Edge for Business / Defender for Cloud Apps)
Endpoint DLP, browser and CASB
43%13/30, 7 partial
Netskope
SSE and CASB
40%12/30, 5 partial
Zscaler (incl. SPLX)
SSE and SASE
30%9/30, 7 partial
Cyberhaven
Endpoint DLP and data lineage
23%7/30, 7 partial
SentinelOne (Prompt Security)
EDR and AI security
23%7/30, 2 partial
Palo Alto Networks
SASE, enterprise browser and EDR
17%5/30, 5 partial
Harmonic Security
Browser-extension AI DLP
13%4/30, 2 partial
Island
Enterprise browser
7%2/30, 6 partial
LayerX (Akamai Workforce Protector)
Browser-extension security
7%2/30, 5 partial
Nightfall
AI-native DLP
7%2/30, 3 partial
Noma Security
AI security posture and detection
7%2/30, 2 partial
Push Security
Browser-based identity and SaaS security
7%2/30, 1 partial
Check Point (Lakera)
Network security and AI guardrails
3%1/30, 4 partial
CrowdStrike (Pangea)
EDR and AI security
3%1/30, 3 partial
Cisco (Astrix / Robust Intelligence)
Identity and network security
3%1/30, 2 partial
Menlo Security
Browser isolation and extension
0%0/30, 4 partial
Cato Networks (Aim Security)
SASE
0%0/30, 3 partial
ControlLamplighter20/30Microsoft13/30Netskope12/30Zscaler9/30Cyberhaven7/30SentinelOne7/30Palo Alto5/30Harmonic Security4/30Island2/30LayerX2/30Nightfall2/30Noma Security2/30Push Security2/30Check Point1/30CrowdStrike1/30Cisco1/30Menlo Security0/30Cato Networks0/30
Discovery and inventory
F01AI app discovery, catalogue and risk scoring
F02Personal vs corporate account (instance) awareness
F03Installed desktop AI app and CLI inventory and control
F04AI browser-extension inventory and control
F05Local LLM runtime detection and exposure
F06Embedded/SaaS AI visibility (feature or compliance API)
F07OS and browser-native AI control (Recall, AI browsers)
Data in motion
F08Paste/typing inspection with block, warn or coach
F09File-upload inspection
F10Sensitivity-label awareness
F11ML/semantic classification beyond regex
F12Redaction before send
F13Desktop-app and IDE/CLI data gates (non-browser)
F14Response/downstream inspection
F15Share-link and public-exposure control
F16Screenshot/image (OCR) assessment
Agents and connectors
F17MCP server and agent discovery
F18MCP gateway and tool-call inspection
F19Agent autonomy and config-file monitoring
F20Agent action guardrails (file, credential, install)
F21API-key-on-disk scanning
F22OAuth grant and agent-credential governance (API side)
F23OAuth consent interception (endpoint side)
F24Prompt-injection and jailbreak detection
Governance and evidence
F25Coaching with justification capture
F26Request, approval and exception workflow
F27ISO 42001 and audit evidence pack
F28Prompt/event logging, audit trail and SIEM export
F29Monitoring lawfulness (metadata-first, DPIA, notice)
Enforcement
F30Browser, isolation or network blocking of AI apps
  • 0 no evidence found
  • 1 partial or limited
  • 2 documented
  • 3 documented, singled out as a strength
  • Lamplighter:
  • S shipped
  • P scheduled
  • + proposed

Cell basis

Select any cell to see the evidence behind its score.

How we scored this

Thirty controls in five groups, drawn from the categories the security research on AI at the endpoint discusses. Each cell is the level of coverage we could evidence from public product documentation and analyst material reviewed in September 2026. A zero means we found no documentation of that control, not that the product lacks it; a few vendor pages could not be reached, so treat each vendor’s score as a floor.

Lamplighter’s column shows what ships today (S), work already scheduled (P) and controls we have proposed but not yet planned (+); only shipped controls count in its score unless you tick the box above. It blocks sending and uploading to AI apps in the browser; whole sites are blocked through the web-gateway and AppLocker lists it exports. The MCP gateway is in early access.

Think we have scored a product wrongly? Tell us and we will check it and correct this page.

See the whole picture on your own machines.