Security1 publisher2 min readPublished
BlackFog's ADX Vision 2.0 screens AI agents' prompts on the endpoint before they reach a model
BlackFog's ADX Vision 2.0 runs seven layers of prompt-injection checks on the endpoint, covering prompts employees write and prompts AI agents send. Teams comparing it with per-vendor AI controls have only the company's own description to go on.
The Watch · Security desk
What happened
- BlackFog says the control layer decides what AI may do with corporate data no matter which tool or model an employee or agent is using.
- Administrators can add company- or department-level rules that flag credit card numbers, Social Security numbers and domain-specific terminology in prompts.
- Requests can be redirected to sanctioned LLM services, so an employee who opens a personal ChatGPT account is routed to the company's enterprise AI instance.
- BlackFog is pitching a new view of token consumption across LLMs, broken down by location and user, as a way to catch attackers running up usage with stolen API keys.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision Teams weighing per-vendor AI settings against one endpoint layer get a single policy point across tools, at the cost of another agent on every managed machine and a claim that so far rests on BlackFog's own description.
- constraint Audit coverage is narrower than the control claim: optional prompt auditing is offered for 'leading frontier LLMs', which puts smaller or self-hosted models outside the stated audit scope.
- exposure Agent calls that never cross a managed endpoint fall outside a control placed on it, so server-side agents still need their own governance.
There is no CVE here and no patch deadline. ADX Vision 2.0 is a product launch [1]. It targets the threat that Dr. Darren Williams, BlackFog's CEO, described. "When an agent is sending prompts on an employee's behalf, there's no human in the loop to catch a manipulated instruction or a leak of sensitive data," Williams said [10].
BlackFog's answer is to inspect each outbound prompt on the machine that sends it [2]. The seven layers are context switching protection, obfuscation protection, jailbreak detection, data exfiltration protection, dangerous prompt pattern detection, fuzzy keyword detection and structural anomaly detection [3]. "ADX Vision 2.0 inspects agentic prompts with the same protections as those written by humans," Williams said [11].
Every claim here comes from BlackFog's announcement, published by Help Net Security [1]. The company did not publish detection rates, false-positive rates, independent test results or pricing. Going by their names, two of the seven layers, fuzzy keyword detection and dangerous prompt pattern detection, match against the text of the prompt [1]. I'd want to see those two tested against injections that have been rewritten until they pass. BlackFog lists obfuscation protection as a separate layer [3].
Token theft is the one item that comes with a direct bill. BlackFog describes attackers using stolen API keys or credentials to run up usage at the organization's expense [8]. A key used from an attacker's own infrastructure would show up in the consumption view only if that view pulls provider-side usage data as well as traffic seen on endpoints.
The release builds on ADX Vision's existing Shadow AI discovery and control features. BlackFog says it expands them into a broader security and governance layer for increasingly autonomous AI systems [9].
What to watch
- Independent tests of the seven prompt-protection layers against obfuscated or rewritten injections, with published detection and false-positive rates.
- BlackFog naming which 'leading frontier LLMs' the optional prompt audit covers, and whether self-hosted models are included.
- Whether the token-consumption view uses provider billing data, which decides if it can catch stolen keys used off the corporate network.