Salt Security has expanded its Policy Hub to include 100 pre-built security policies, as organisations look for practical ways to govern AI agents across enterprise environments.
The company says the milestone creates one of the industry’s largest libraries of governance policies for agentic AI, covering APIs, Model Context Protocol (MCP) servers, authentication, access controls, compliance and runtime behaviour. The announcement comes as organisations rapidly adopt AI agents that can interact with enterprise systems and perform tasks autonomously. Because these agents rely on APIs to access data and invoke tools, Salt argues that traditional API governance has become an essential part of governing AI systems.
Rather than requiring organisations to build governance frameworks from scratch, the Policy Hub provides a library of policies that can be activated immediately and customised to suit different environments. Salt describes the approach as similar to an “app store” for agentic security, allowing security teams to deploy pre-built governance policies across the infrastructure that supports AI agents.
The expanded library includes more than a dozen policies designed specifically for agentic AI, covering areas such as MCP server configuration, agent authorisation and the risks associated with autonomous agent behaviour. Other policies address data security, OAuth, API architecture, third-party risk and compliance with frameworks including GDPR, ISO 27001, HIPAA, PCI DSS and SOC 2.
According to Salt, 61 of the 100 policies are enabled automatically, while the remaining policies can be activated with a single click. Organisations can also create their own custom policies to extend governance beyond the pre-built library. The Policy Hub forms part of the Salt Agentic Security Platform, which provides visibility across what the company calls the Agentic Security Graph, encompassing LLMs, MCP servers, APIs and connected enterprise applications.
Michael Callahan, VP of Strategy and CMO at Salt Security, said many organisations recognise the need for AI governance but struggle to know where to begin. “When we launched the Policy Hub in 2024, the most common thing we heard from CISOs was, ‘We know we need posture governance, but we have no idea where to start.’ That question was killing governance programmes before they launched. The inclusion of 100 policies means that question now has a concrete answer. Security teams can walk in on day one with meaningful protection already active and it can be extended from there without limit.”
Salt said many of the policies were originally developed for API posture governance but now play a broader role as organisations deploy AI agents. As AI systems increasingly depend on APIs, identity platforms and MCP servers to perform actions, the company believes governance must extend across the entire agentic infrastructure rather than focusing solely on AI models or prompts.
The company also highlighted its MCP server discovery capabilities, introduced in 2025, which are supported by dedicated governance policies for identifying configuration issues and controlling how MCP servers interact with enterprise systems.
In June, Salt also launched Salt Code, extending the same governance engine into the software development lifecycle to apply policies to AI-generated code during development.
Aner Gelman, VP of Products at Salt Security, said boards are increasingly asking organisations to demonstrate how AI is being governed.
“The board question CISOs are being asked right now is not whether we have AI governance. It is whether we can prove it. Having 100 policies in active deployment is a concrete, operational answer to that question. Not a roadmap. Not a strategy. An active governance layer running today.”
The 100 pre-built policies are available immediately to customers using the Salt Agentic Security Platform.

