C1 — Gap Analysis

High blast radius and low defence risks, but underserved.

These are not gaps because the risks are low-severity. Adversa's AIRQ framework explicitly identifies the agent classes that drive these risks (i.e., multi-agent architectures, computer-use agents, conversational agents) as having the highest blast radius yet currently have the lowest defence controls of any class. The gaps exist for structural, not strategic, reasons.

ASI07
Insecure Inter-Agent Communication
0 / 5 vendors
Messages between agents can be intercepted, spoofed, or injected. An attacker who controls one agent in a chain can influence all downstream agents. OWASP calls this "an entirely new attack class with no equivalent in single-LLM systems."
Why it's not tested Methodologically, testing Insecure Inter-Agent Communication (ASI07) requires ≥2 real agents exchanging messages — a different harness than any current red-team product deploys. All five vendors in this set use a single-endpoint probe model: one attacker, one target. Inter-agent message spoofing is invisible in that architecture. Additionally, true multi-agent A2A systems with exposed message channels are still relatively uncommon in production, so buyer demand has not yet crystallised.
AIRQ context The AIRQ framework is relatively thin on multi-agent classes — it primarily scores single-agent deployment contexts. This suggests the market hasn't fully theorised Insecure Inter-Agent Communication (ASI07) risks at scale. The absence of coverage may partly reflect deployment immaturity, not solely tooling immaturity.
ASI08
Cascading Agent Failures
1 / 5 vendors
One compromised or misbehaving agent causes downstream agents to fail or behave unpredictably. The AIRQ framework names this as a primary driver of blast radius in interconnected agent networks — "the larger and more interconnected the agent network, the greater the blast radius." Adversa is the only vendor with any red-team coverage here, via resource exhaustion testing.
Why it's barely tested Cascading failure is an emergent, system-level property — it only manifests across a connected fleet of agents, not in a single-endpoint probe. You can only observe it by running a compromised or misbehaving agent and watching downstream effects propagate. No current red-team tool has built this multi-agent simulation harness. Noma covers Cascading Agent Failures (ASI08) via runtime blast-radius mapping and attack-path analysis — but that is posture management, not red teaming.
AIRQ context AIRQ explicitly frames blast radius as a primary security metric. Coding and Computer agents both score the worst on blast radius and defence controls — precisely the classes where cascading failure matters most. High severity; zero to minimal red-team coverage. This is the clearest capability-to-defence inversion in the data.
ASI09
Human-Agent Trust Exploitation
0 / 5 vendors
Humans increasingly trust agents to act on their behalf, creating social engineering opportunities. Agents can be manipulated into impersonating trusted entities, or humans can be manipulated into over-trusting agent outputs without verification. AIRQ covers this extensively under conversational and voice agent classes — "identity, intent, and authorization collapse under conversational tempo."
Why it's not tested ASI09 has a structural barrier no other category has: the attack target is a human, not an API endpoint. You cannot point an LLM-attacker agent at a REST endpoint and measure a human being deceived. Red teaming, by definition, probes machine-to-machine attack surfaces. ASI09 sits outside automated red teaming entirely. The closest adjacent coverage in this dataset was Microsoft's attribution-uncertain "Contributor Reputation" item — which screens the human dev pipeline, not runtime agent-to-human social engineering.
AIRQ context AIRQ's Conversational Agents class identifies "time-compressed trust" (voice channels bypassing text-based defences), and Computer Agents class identifies "confirmation mismatch" (humans approving the appearance of an action, not what the agent is about to do). Both are Human-Agent Trust Exploitation (ASI09) risk manifestations. Neither has a red-team product addressing them. This is the most permanently difficult gap in the taxonomy.
The power-protection inversion
The agents with the most power have the least protection, and the agents with the most protection have the least power. The most capable, most dangerous agent classes are the least defended.
  • Coding agents and Computer agents have the widest attack surfaces and largest blast radiuses with the thinnest defenses.
  • Work Copilot and Business Process agents, on the other hand, are among the most heavily defended, despite narrower exposure.
C2 — The 4 AI Harms

Vendor Positions.

The 4 AI Harms framework maps risk along two axes:

Vendor positions on the 4 AI Harms quadrant diagram
Vendor X Axis Y Axis Quadrant(s)
NOMA Exfiltration Both Company Data · People Data
Adversa Both Internal Commerce · Company Data · People Data (secondary)
Microsoft Security Both Internal Company Data · Commerce
Lasso Manipulation Internal Commerce · Reputation (secondary)
Palo Alto Networks Manipulation Internal Commerce
C3 — Strategic Opportunities for Fortify

Where the market leaves room.

Fortify enters as a model and application red-teaming tool with multi-turn capability. Five opportunities are identified — two are capability gaps in the market, two are positioning gaps, and one is a buyer-language gap. Each is grounded in the coverage data and gap analysis above.

01 Capability Gap
Nobody red-teams Insecure Inter-Agent Communication (ASI07) risk.
Inter-Agent Communication (ASI07) is 0/5 across the entire market. The barrier is that testing it requires a multi-agent harness, not a single-endpoint probe. No competitor yet has moved here. First mover with a credible, evidenced ASI07 test can owns this category and answers a gap the framework itself identifies as a structurally new attack class.
02 Capability Gap
Build toward Cascading Agent Failures (ASI08): the highest-blast, lowest-tested category.
Cascading Agent Failures (ASI08) is 1/5 — only Adversa touches it, via resource-exhaustion testing. AIRQ identifies cascading failure as the primary blast-radius amplifier for interconnected agent networks. A full ASI08 test requires simulating a compromised agent and measuring downstream propagation — a more complex harness than ASI07, but on the same multi-agent infrastructure. The Commerce harm mapping makes this commercially legible: cascading failures through payment pipelines are the systemic risk behind the visible transactional attack.
03 Positioning Gap
Expand multi-turn to cover Memory & Context Poisoning (ASI06).
Memory and Context Poisoning (ASI06) is 5/5 — every vendor offers multi-turn. But the differentiation is not in having it; it's in naming it and evidencing it with precision. Fortify already has multi-turn capability. Positioning it explicitly as cross-session memory attack coverage — with a worked example of an attacker planting false context that persists into future sessions — transforms a commodity feature into an evidenced ASI06 claim. The worked example format (Prisma's $900 withdrawal) shows buyers comprehend concrete demonstration over abstract capability claims.
04 Positioning Gap
Evidence-mapped framework fidelity over vague breadth claims.
Several vendors in this set claim "OWASP coverage" without per-category evidence. Adversa and Prisma are the most precisely evidenced by self-mapping specific capabilities to specific ASI codes. Fortify can own the "evidence-backed, per-category framework alignment" position: for each ASI category we cover, we publish the exact capability, the attack scenario, and the evidence that maps to it. In a market where "OWASP Top 10 mapped" is a common but hollow claim, precision can become a strong signal for the buyers.
05 Buyer Language
4 AI Harms as buyer language — bridge technical ASI to business impact.
The 4 AI Harms (People Data, Company Data, Commerce, Reputation) are more legible to non-technical leadership than ASI codes. Prisma demonstrates this with the $900 withdrawal Commerce harm story, on top of "we prioritize ASI01 and ASI02" story. Fortify's findings reports can potentially map every vulnerability to the relevant harm quadrant, giving security teams a familiar language when briefing to product owners and executives. At this time, the commerce harm seems to be the most buyer-salient (concrete financial impact).