Defender Impact
Organisations deploying AI agents to act on users’ behalf across the internet have had no standardised runtime control plane to enforce behavioural boundaries — doxx.net’s ADN platform directly addresses this gap by inserting a supervision layer between agent intent and real-world action. For security teams, this represents the first commercially funded product explicitly scoped to the ‘agent acting as user on the open web’ problem.
Capability Overview
doxx.net has raised $38 million to bring its Agentic Defense Network (ADN) platform to market. The platform is designed to prevent what the company calls ‘agentic misadventure’ — situations where an AI agent, operating under a user’s delegated authority, takes actions that are unintended, out-of-scope, or harmful. The product intervenes while the agent is actively operating, rather than relying solely on pre-deployment configuration.
The core premise is that AI agents browsing the internet, submitting forms, interacting with third-party services, or managing accounts on a user’s behalf inherit the user’s trust context. Without a mediation layer, there is no mechanism to distinguish between an agent acting within the spirit of its mandate and one that has been manipulated, confused, or simply misconfigured into taking harmful steps. ADN positions itself as that mediation layer — a runtime policy enforcement and monitoring plane for agentic internet activity.
The $38 million funding round signals significant investor confidence that agentic oversight is becoming a distinct product category, separate from traditional endpoint or application security tooling. This is a meaningful market signal for defenders evaluating their agentic AI security architecture.
Defensive Advances
Runtime behavioural enforcement: ADN provides controls that operate while an agent is executing, not just at configuration time. Defenders can now enforce what actions are permissible in real time rather than relying on prompt-level guardrails alone.
Delegated authority visibility: Security teams gain an audit trail for agent activity conducted under user authority — something previously absent from most agentic frameworks. This supports incident investigation and compliance documentation.
Blast radius reduction: By intercepting out-of-scope actions before they complete, ADN reduces the potential damage from an agent that has been misdirected — whether through prompt injection, context poisoning, or simple misconfiguration.
Dedicated agentic security posture: ADN represents a purpose-built control for agentic surfaces, moving defender capability beyond repurposed web proxies or LLM output filters into a category designed for the agent-as-user threat model.
Residual Gaps
The article provides limited technical detail on ADN’s architecture, making it difficult to assess coverage depth at this stage. Key maturity questions include:
- Protocol and channel coverage: It is unclear whether ADN covers non-browser agentic interactions — API calls, file transfers, MCP tool invocations — or is primarily scoped to web browsing agents.
- Policy definition maturity: Effective enforcement depends on organisations having well-articulated agent behaviour policies. Teams without these in place will face an integration prerequisite before ADN can be configured meaningfully.
- Integration breadth: Compatibility with the full landscape of agentic frameworks (LangChain, AutoGen, OpenAI Assistants API, custom agent runtimes) is not confirmed from available information.
- Latency and throughput: Runtime interception introduces latency considerations for high-frequency or time-sensitive agentic workflows — an operational trade-off that warrants evaluation.
- False positive management: Overly aggressive enforcement risks disrupting legitimate agent workflows; the platform’s tuning capabilities and default policy sensitivity are not yet publicly documented.
Framework Mapping
ADN most directly addresses LLM08 (Excessive Agency) — the OWASP category covering agents that take actions beyond their intended scope. It also provides a control surface relevant to AML.T0080 (AI Agent Context Poisoning) and AML.T0086 (Exfiltration via AI Agent Tool Invocation) by enforcing boundaries that constrain what a manipulated or misbehaving agent can actually do. Secondary relevance applies to LLM01 (Prompt Injection) in cases where injection attempts are the root cause of the out-of-scope action ADN intercepts.
Deployment Considerations
Organisations should approach ADN adoption sequentially: first inventory all agent workflows that touch external internet surfaces, then document intended behaviour scope for each workflow, and finally configure ADN enforcement policies against that documented baseline. Teams without an existing agent catalogue should complete that exercise before attempting integration. ADN should be treated as a complementary control alongside prompt-level guardrails and output filtering — not a replacement for either.
Defender Checklist
- Inventory all AI agents operating under delegated user authority with external internet access
- Document intended behavioural scope for each agentic workflow before configuring enforcement policies
- Request ADN integration documentation for your specific agent frameworks and runtimes
- Define success metrics for agent supervision (false positive rate, blocked action rate) before deployment
- Align ADN policy review cadence with agent capability updates and model version changes
- Evaluate ADN alongside existing LLM output filtering and prompt guardrail controls to avoid coverage overlap or gaps