AI agents are moving beyond experimentation and into business-critical workflows, creating a security challenge that traditional application and infrastructure controls were not necessarily designed to handle. Barcelona-headquartered NeuralTrust is responding to that shift by opening a dedicated London office, expanding its presence in a UK market where financial institutions, airlines, technology companies and other enterprises are increasingly deploying autonomous AI systems.
NeuralTrust Takes Its AI Agent Security Push to London
The enterprise AI conversation is entering a more complicated phase.
For several years, businesses have focused on deploying generative AI assistants, copilots and chatbots. The next stage involves AI agents that can do more than generate an answer. They can call tools, access information, interact with applications and execute actions on behalf of users or organisations.
That additional autonomy changes the security equation.
NeuralTrust, a Barcelona-headquartered platform focused on securing AI agents, has opened a new office at 167 Great Portland Street in London to support customers, partners and hiring across the UK.
The expansion comes as enterprises increasingly experiment with or deploy agentic AI in production. For security leaders, that creates a new class of operational questions: What can an agent access? Which actions can it take? How can its behaviour be monitored? And what happens if an otherwise trusted agent is manipulated?
Those questions are becoming central to enterprise AI adoption.
Why AI agents create a different security problem
Traditional cybersecurity programmes are built around familiar assets: applications, endpoints, networks, identities and data.
AI agents introduce another layer.
An agent can potentially interpret instructions, interact with external tools, retrieve information and make decisions within a defined workflow. A compromised or poorly configured agent could therefore expose sensitive information or perform an action at machine speed.
One of the risks is prompt injection, in which malicious instructions are introduced into the information an AI system processes. Other risks include excessive permissions, insecure tool access, data leakage and unintended autonomous actions.
Gartner has predicted that by 2027, 40% of enterprises will demote or decommission autonomous AI agents because governance weaknesses only become visible after deployment.
The implication for CIOs and CISOs is straightforward: AI governance cannot remain an afterthought once an agent reaches production.
NeuralTrust builds around the agent lifecycle
NeuralTrust’s platform is structured around several stages of securing AI systems.
TrustGate operates as an AI gateway between applications, agents, tools and models. The objective is to provide policy enforcement, access control and traffic management around AI interactions.
TrustGuard focuses on runtime security, identifying and blocking potentially malicious or unsafe agent behaviour as it occurs across platforms and endpoints.
Then there is TrustTest, a red-teaming product designed to proactively test AI systems for weaknesses before those vulnerabilities can be exploited by attackers.
Together, the products point toward an emerging category of AI security infrastructure designed specifically for systems that can act rather than simply respond.
The security perimeter is changing
The rise of agentic AI could force enterprises to rethink what they consider a security boundary.
A traditional application generally executes according to predefined rules. An AI agent can interpret changing inputs and determine which tools or workflows it should use within its permissions.
That means security teams may need visibility into not only whether a system is authenticated, but also what the AI is attempting to do.
This is where runtime monitoring becomes particularly important.
An agent might be legitimate, properly authenticated and operating within a valid application, yet still behave in a way that creates risk because of a malicious instruction, unexpected input or misconfiguration.
Security controls therefore need to account for behaviour as well as identity.
London becomes an important AI security market
NeuralTrust’s decision to establish a UK base also reflects London’s importance to enterprise technology and financial services.
Banks, insurers and other regulated businesses are among the organisations exploring AI agents while simultaneously facing strict requirements around data protection, operational resilience, governance and accountability.
For these companies, the business case for agentic AI cannot be separated from risk management.
A financial-services organisation may want an agent to assist with customer service, analyse documents, support employees or automate operational processes. But each additional capability potentially expands the system’s access to corporate data and applications.
That creates demand for security architectures that allow enterprises to adopt AI without giving autonomous systems unrestricted authority.
AI security is becoming part of AI adoption
For organisations still approaching AI cautiously, security can sometimes appear to be a barrier to experimentation.
The more mature approach is likely to treat security as an enabler.
If enterprises can establish clear permissions, monitor agent behaviour, test systems before deployment and intervene when an agent behaves unexpectedly, they can potentially expand AI adoption while maintaining stronger controls.
This is particularly relevant to CISOs, who are increasingly being pulled into AI strategy discussions rather than being consulted only after systems have been selected.
The role of the security team is evolving from protecting a relatively fixed technology environment to helping define how autonomous systems should operate inside that environment.
Human oversight remains critical
Greater autonomy does not eliminate the need for people.
In fact, it can make human governance more important.
Organisations still need employees who understand what AI agents are authorised to do, when an action requires escalation and how to investigate anomalous behaviour.
That creates a parallel workforce requirement: AI literacy for security and business teams.
Developers need to understand secure agent design. Security teams need visibility into AI behaviour. Business leaders need to understand the operational consequences of granting agents access to sensitive systems.
AI security is therefore becoming a cross-functional discipline rather than a narrowly technical product category.
The next AI security battle will be about control
NeuralTrust’s London expansion comes at a point when the enterprise AI market is moving from isolated pilots toward more autonomous systems.
That transition could make the distinction between an AI assistant and an AI agent increasingly important for security leaders.
An assistant primarily helps a person. An agent can potentially act on a person’s or organisation’s behalf.
The latter creates greater productivity opportunities—but also a larger blast radius when something goes wrong.
As businesses deploy agents across customer service, software development, finance, operations and internal workflows, the ability to establish permissions, test systems and observe behaviour will become increasingly important.
For NeuralTrust, London provides a local base for pursuing that market.
For enterprise security teams, the larger development is harder to ignore: once AI can act, securing what it does becomes just as important as securing what it is.
Market Landscape
The AI security market is expanding from protecting models and data toward securing the entire agentic AI runtime.
Enterprises adopting AI agents need controls across identity, access permissions, tool use, data movement, model interactions, runtime behaviour and governance.
This is creating overlap between traditional cybersecurity categories and emerging AI-specific security platforms. Established security ecosystems from companies such as Microsoft, Google, Amazon and Palo Alto Networks are also increasingly relevant as organisations integrate AI into enterprise environments.
The competitive opportunity is shifting toward platforms that can provide security teams with centralised visibility and policy enforcement without preventing useful AI automation.
Top Insights
- NeuralTrust has opened a London office to expand its UK customer, partner and recruitment operations as enterprise AI-agent adoption accelerates.
- AI agents introduce risks involving tool access, autonomous actions, prompt injection and sensitive-data exposure that conventional security controls may not fully address.
- NeuralTrust’s platform combines AI gateway controls, runtime protection and proactive red teaming through TrustGate, TrustGuard and TrustTest.
- The rise of agentic AI is turning AI governance into an operational security requirement, particularly for highly regulated industries such as financial services.
- Enterprise AI security increasingly requires collaboration between CISOs, developers, business leaders and employees, making AI literacy part of the security equation.
Join thousands of HR leaders who rely on HRTechEdge for the latest in workforce technology, AI-driven HR solutions, and strategic insights





