Bitdefender on September 30 announced AI Guardian, a free public beta for macOS that checks what AI agents try to do on a computer and blocks actions that break a policy the user sets. It is aimed not at conventional malware but at software agents that can run commands, read files and call online tools on a person's behalf, and that can be steered by instructions hidden in what they read.

What happened

The company announced the product from Bucharest and San Antonio, Texas, and made it available as a download from its product page. According to the announcement and that page, AI Guardian is designed to:

  • Detect and block prompt injection, which the product page defines as "an attack where crafted input tricks an AI agent into following instructions it should ignore".
  • Verify MCP tools. MCP, the Model Context Protocol, is a common way to connect agents to outside tools. The product checks for malicious or tampered tools before an agent calls them, a risk the page calls tool poisoning.
  • Vet agent skills before they run, to stop unreviewed code from executing.
  • Guard secrets and sensitive files, detecting API keys and tokens before they leave the machine and blocking access to items such as SSH keys and stored system credentials.
  • Log every tool call, so the user can review what an agent did and what was allowed, flagged or blocked.

The product page describes three stages: set a policy baseline, enforce it at runtime, and monitor. Each action an agent attempts is checked against the baseline and returns a verdict of "allowed, flagged or blocked".

Who can use it

  • Platform: macOS only. Windows and Linux are planned, with no date given. The installer is a 31 MB download and asks for system permissions during installation.
  • Supported agents: recent versions of Claude Code and OpenClaw, plus MCP clients and servers, agent skills and plugins, and command line coding agents. Agents built into code editors are listed as coming soon.
  • Price: free during the beta, with no waitlist or licence key. The page says "it will stay free for early adopters after BETA". Pricing after the beta has not been announced.

What stays on the device

The product page says "prompts never leave your Mac" and that agent actions are analyzed on the device. It also says "some checks (such as URL reputation)" use Bitdefender's cloud services and that only some features work offline. It refers users to Bitdefender's privacy policy and licence agreement for details.

The background

AI agents differ from chat assistants because they act. A coding agent may read a project's files, run shell commands and install add-ons; an MCP server may give it access to email, a database or a web browser. That makes the content an agent reads a possible attack route.

The security community has been describing this risk for some time. The OWASP Top 10 for LLM applications ranks prompt injection first and separates direct injection, typed by the user, from indirect injection, where instructions hidden in a website or file change the model's behavior. OWASP's recommended mitigations include enforcing "privilege control and least privilege access" and requiring human approval for high-risk actions, and it notes that it is unclear whether prompt injection can be fully prevented.

The Model Context Protocol's own security best practices warn that local MCP servers "may have direct access to the user's system", and list risks including arbitrary code execution and data exfiltration. They give as an example a malicious startup command that sends the user's SSH key to an outside server, and recommend that clients show the exact command and require explicit approval before running a new local server.

Bitdefender says AI Guardian is its third product for AI agents this year, alongside Agent Skill Scanner and VPN for AI Agents. Its announcement cites two figures to make its case: independent research on 20 leading AI agents that found "an average attack success rate of 36.5%, with one model manipulated 72.8% of the time" across more than 1,300 tool poisoning attempts, and an analysis that found "more than 1.2 million exposed AI service secrets in 2025, up 81% year over year". The announcement does not name either study, and we have not been able to check them.

Why it matters

The risks AI Guardian targets are described in OWASP's guidance and in the MCP specification itself, so the product addresses a recognized problem rather than an invented one. Bitdefender's senior vice president of operations for its Consumer Solutions Group, quoted in the announcement, put it this way: "AI agents are becoming a direct extension of the users who rely on them, inheriting the same security risks that come with that role."

At the same time, Bitdefender is careful about what the product is. Its own page says AI Guardian is "not a traditional endpoint antivirus, network firewall, VPN, or content filter", that support is per agent rather than automatic for everything on the machine, and that "no security product guarantees complete protection". The performance impact is described as "designed to be minimal; not yet measured".

The approach also has limits that follow from the design. A policy baseline is only as good as the policy, and a product that works through integrations with named agents does not cover agents it does not support. Those are not criticisms of a beta so much as reasons to treat it as one layer among several.

What we do not know yet

  • How well it works. No independent testing has been published. The vendor's own page says performance impact has not been measured.
  • The research behind the statistics. The studies cited in the announcement are not named.
  • Pricing after the beta. Early adopters keep free access, but there is no price or date for anyone else.
  • What data is sent to the cloud. The page names URL reputation as one cloud check but does not list the others or detail telemetry and retention.
  • The release timeline. There are no dates for Windows, Linux or editor-based agents. The product page also describes the open beta as running since September 21, nine days before the announcement.

What it means for you

  1. If you do not use AI agents that act on your computer, nothing changes. Your existing security software remains the relevant protection.
  2. If you do, limit what agents can reach. OWASP's guidance is least privilege: give an agent access only to the folders, tools and accounts it needs, and require your approval for risky actions.
  3. Keep secrets out of reach. Do not leave API keys, tokens or SSH keys in files an agent can read without need.
  4. Be careful with add-ons. Install MCP servers and agent skills only from sources you trust, and read the command a client asks you to approve before you approve it, as the MCP security guidance recommends.
  5. If you try the beta, treat it as an extra layer, not a replacement for your existing security software, and read the privacy policy and licence first. Bitdefender's own page says no product guarantees complete protection.