Providing security against anomalous autonomous agents requires instantaneous detection, evaluation and action – a circuit breaker for AI rather than a circuit breaker for electricity.
Such a ‘device’ has now been developed and released by Capsule Security.
The firm was founded in 2025 by Naor Paz (CEO) and Lidan Hazout (CTO). They had seen how autonomous AI agents create a dangerous security gap and decided to build a missing runtime security layer. Their latest solution was announced on September 2, 2026, and is described as an ‘AI circuit breaker’. It is designed to prevent damage from agents operating outside their intended scope, in real-time.
“The defining AI security risk is no longer only what people can do with agents. It is what autonomous agents can decide to do by themselves,” explains Paz in announcing the product. “When software can reason, use tools and take action, a wrong decision can become a real-world incident in seconds. Human trust in AI depends on our ability to stop that action before it happens.”
The problem is not simply the reach of autonomous agents; it is also the speed at which they operate. While it may be possible to review an agent’s behavior before it happens, doing so commonly introduces latency that may be too slow and too expensive for the agent’s intended action.
Capsule’s solution uses its own specialized AI for real-time intervention. The firm used NVIDIA Nemotron 3 Ultra to support the training process, combining real agent traces, human review and adversarial examples designed to teach its AI models the boundary between authorized and rogue behavior.
They developed two models capable of providing strong detection without the cost and latency of sending every agent action to a large general-purpose model for review. The more accurate model attained 96.9% detection accuracy, compared with 86% for the strongest third-party model evaluated.
The models could also make a decision in as little as 71 milliseconds, meaning they could operate within the agent’s workflow without creating any meaningful delay. Capsule then reduced the infrastructure for its larger model, reducing its memory requirement by almost 50%.
The result is Capsule’s own evaluator running within the agent’s execution path able to evaluate the agent’s intention before the action takes place and stop it before execution if necessary. This is the AI circuit breaker.
“The model evaluates an agent’s intended action immediately prior to execution, giving organizations the ability to allow, flag or block it in real time. This creates an independent control layer for agents that can access sensitive data, write code, operate infrastructure and interact with other systems,” says Capsule. “Post-incident monitoring only identifies the problem after the damage has occurred.”
Capsule claims 98% efficiency for the circuit breaker’s decision maker when tested against StepShield – an independent academic benchmark that can be used to measure whether security systems can identify and stop rogue agent behavior before damage occurs.
The key lesson from Capsule’s work is that specialized Small Language Models (SLMs) are the key to safely scaling trusted agentic workflows across the enterprise. “Moving beyond general-purpose models to specialized, efficient detectors allows organizations to secure their agentic workflows without sacrificing speed, cost, or performance.” It claims.
Related: AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million
Related: OpenLeash Adds a Human Check to Risky AI Agent Actions
Related: UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge
Related: Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection


