Forrester just published The Agentic Development Security Tools Landscape, Q2 2026, and Endor Labs is among the 35 vendors included. New categories don't get named until a real problem outgrows the tools built for the last one. This one has a name now: agentic development security, or ADS. Or as we like to say, agentic coding security. We're glad to be in the report, and we're more interested in what it says, because the thesis reads like the bet we made when we founded the company.
Why a new category was inevitable
The old model assumed a human wrote the code. Shift left, give developers feedback in the IDE, gate the pipeline, build a culture of shared responsibility, all good ideals, but they fail to match the pace and output when AI coding agents do the work.
That's the structural break. AI generates large volumes of syntactically correct but semantically risky code with missing input validation, hardcoded credentials, leaked secrets, insecure dependencies, hallucinated packages, and pushes it into automated pipelines faster than human review can keep up.
At the same time, the agents themselves become an attack surface: models, MCP servers, skills, plug-ins, and extensions, all running with elevated permissions and access to sensitive systems. Traditional AppSec was never designed for a non-deterministic actor operating at machine speed. A new toolset had to emerge, and Forrester's report is the market catching up to that reality.
Detection is commoditized. Prevention is the point.
Forrester is blunt about the shift from detection to prevention and remediation. This is the exact problem Endor Labs was founded to solve. When we launched, SCA was broken not because it found too little but because it found too much, often 10,000-finding backlogs no engineering team could act on.
Our answer was function-level reachability: trace whether your application can actually invoke a vulnerable function before you ever flag it, and then help you prioritize fixes based on what would fix the most vulnerabilities without breaking a running application. For our customers, that cuts security ticket backlogs by 10x on average. We’ve always said that detection was never the hard part. Knowing matters, and what to do about it, always was.
Forrester also calls out the winning architecture directly as vendors that combine AI reasoning with deterministic capabilities. It’s hour It's how our AI SAST works today. We’ve built custom agent harness and tools that give agents security context, while using their ability to reason for the design, logic, and intent flaws that pattern matching tools struggle with today. That’s why we outperformed both frontier AI models and last-generation static analysis tools by anywhere from 2-3x at finding true positives.
Endor Labs is pushing the category forward
The most useful part of any Landscape is the forward look. Forrester names three directions ADS tools will grow, and each one maps to something we ship.
- Expand coverage of the AI software supply chain. Forrester expects vendors to move beyond hooking into pull requests toward dependency firewalls that block suspicious or malicious downloads, and to extend that blocking to AI models, MCP servers, skills, and extensions. Endor Labs has already shipped this alongside Cursor, Google, and other partners.
- Secure and govern intent. Forrester describes mapping agents to their tools, identities, permissions, and data sources, and aligning user, developer, role, and organization intent. This is core to how we approach governance for AI coding agents.
- Visibility, governance, and AIBOMs. The report ties ADS to SBOMs and AIBOMs that surface legal, compliance, and operational risk and map to regulations like the EU Cyber Resilience Act and the OWASP Top 10. That's well-worn ground for us: our researchers led the OWASP Top 10 for Open Source Software Risks, and we ship compliance guidance for the CRA and more.
Conclusion
Categories get defined by the problems that force them into existence. Securing code that machines write, at the speed machines write it, is that problem. We've been building for it since before it had a name, and we're glad to see Forrester put one on it.
If you want to see what agentic development security looks like in practice, request a demo.
Forrester, The Agentic Development Security Tools Landscape, Q2 2026, Janet Worthington with Amy DeMartine and Caroline Provost. The full report is available from Forrester with paid access.
Forrester does not endorse any company, product, brand, or service included in its research publications and does not advise any person to select the products or services of any company or brand based on the ratings included in such publications. Information is based on the best available resources. Opinions reflect judgment at the time and are subject to change. This report is part of a broader collection of Forrester resources, including interactive models, frameworks, tools, data, and access to analyst guidance. For more information, read about Forrester's objectivity here.
What's next?
When you're ready to take the next step in securing your software supply chain, here are 3 ways Endor Labs can help:







