AccuroAI
Products
What We Do
Solutions
Company
Resources
Book a demo
← Blog·Frameworks9 min read

AI TRiSM, Explained — and a Map of the Vendors That Matter

Most TRiSM explainers quote a framework Gartner replaced in 2025. The current one has four layers, an acquisition wave tracing its lines ($32B of it from Google alone), and a paywall problem nobody talks about. Every claim here is labeled by where it really comes from.

J
James Okafor
Field CISO
2026-08-25

AI TRiSM is Gartner's umbrella for keeping AI trustworthy, safe, and governed. Since February 2025 it means four layers of technical controls, not the older four pillars, and vendors now sort cleanly onto those layers. Here's the map.

Two versions of TRiSM are in circulation, and most explainers use the stale one

The acronym stands for AI Trust, Risk and Security Management. Gartner's canonical definition, which we're relaying via Securiti's recap because the glossary page itself is gated, covers AI model governance, trustworthiness, fairness, reliability, robustness, efficacy, and data protection.

The framing most blog posts still repeat dates to 2022: four pillars, usually listed as explainability and model monitoring, ModelOps, AI application security, and privacy. That version is a full revision out of date.

In its Market Guide for AI Trust, Risk and Security Management, published February 18, 2025, Gartner redrew the market as four layers of technical capability. One honesty note before we list them. The Market Guide is paywalled. We haven't read the primary document, and unless your company holds a Gartner seat, neither has whoever wrote the last explainer you read. The layer structure below is corroborated across recaps from at least three vendors with licensed access (Mindgard, F5, AvePoint), which is about as solid as public sourcing gets for this report. We'll flag provenance like that throughout, because a strange amount of what "Gartner says" reaches the public only through vendors Gartner named.

The four layers, in plain English

  • AI governance. Know what AI you have. Visibility, cataloguing, traceability, and someone accountable for each asset.
  • AI runtime inspection and enforcement. Watch model and agent behavior as it happens. Block what shouldn't happen.
  • Information governance. AI touches only data that's properly permissioned and classified.
  • Infrastructure and stack. The traditional controls (endpoint, network, cloud) applied to AI workloads.

The structural headline, per those recaps: the top two layers are new to AI and are consolidating into a distinct market segment of their own. The guide's other relayed findings are refreshingly unhysterical. Hacks against enterprise AI remain uncommon; the frequent problems are harmful chatbot outputs and internal data oversharing. Top organizational concerns are data compromise and third-party risk, followed by inaccurate or unwanted outputs. And no single vendor addresses all of it. Gartner said that last part itself, which is useful ammunition the next time a deck claims full TRiSM coverage.

What Gartner says in its own name, and what only reaches us secondhand

Primary, on-the-record Gartner: guardian agents will capture 10 to 15 percent of the agentic AI market by 2030 (press release, June 11, 2025). And AI TRiSM sat at the Peak of Inflated Expectations on the 2025 Hype Cycle for AI, with mainstream adoption expected within five years (press release, August 5, 2025).

Widely relayed press material, still reasonably sourced: organizations that operationalize AI transparency, trust and security should see a 50 percent improvement in AI adoption and business outcomes by 2026, a line that traces to Gartner's 2024 strategic trends materials. A prediction that 70 percent of AI applications will use multi-agent systems by 2028 circulated through press coverage of the guardian-agents release.

Then there are numbers we're deliberately not repeating. A claim that TRiSM adopters eliminate up to 80 percent of faulty information used in decision-making, and another promising 35 percent more revenue growth, trace only to secondhand recaps with no locatable primary source. Plenty of competitor explainers run them anyway. We'd rather publish fewer stats than launder one.

The vendor map

Two caveats before the table. Vendors self-map onto TRiSM generously, so the mapping here is ours, built from what each product demonstrably does. And since nobody covers all four layers (per the guide, via those recaps), a "complete TRiSM platform" pitch is a red flag, not a differentiator.

Layer / segmentRepresentative vendorsWhat they demonstrably doStatus and consolidation
Model validation and AI red teaming (pre-deployment)HiddenLayer, Mindgard, Cisco AI DefenseModel scanning, attack simulation, continuous automated red teaming across the lifecycleCisco AI Defense was built from Cisco's 2024 acquisition of Robust Intelligence
Runtime inspection and enforcementLakera (Check Point), Lasso Security, Zenity, AccuroAIInspect and block prompts, outputs, and agent actions in real time; defense against prompt attacks and data leakage, including RAG and MCP flowsCheck Point signed to acquire Lakera in 2025 (the companies put closing in Q4 2025)
AI governance platformsCredo AI, Holistic AI, IBM watsonx.governancePolicy orchestration, EU AI Act mapping, bias and algorithmic audits, lifecycle documentationCredo AI: Reported Forrester Wave Leader (Q3 2025, per Credo’s own announcement); featured in the 2025 Market Guide
AI-SPM (posture management)Noma Security, Wiz AI-SPM, Bosch AIShieldAI asset discovery, misconfiguration detection, attack-path analysis across cloud AI servicesNoma raised a $100M Series B in July 2025; Google closed its $32B acquisition of Wiz in March 2026

Last verified: September 5, 2026. Layer definitions per Gartner's February 2025 Market Guide as summarized by vendors with licensed access; funding and acquisitions per company and press announcements.

For deeper cuts of each segment: our AI-SPM vendor rundown, the AI-SPM explainer behind it, plus a buyer's guide to AI governance platforms.

The acquisition wave is tracing Gartner's lines almost exactly

Watch what the platform vendors bought. Cisco acquired Robust Intelligence in 2024 and turned it into Cisco AI Defense, spanning third-party AI access control, model validation, runtime guardrails, plus inventory. Check Point signed for Lakera in 2025 to get LLM input and output protection. Google closed its $32 billion all-cash acquisition of Wiz on March 11, 2026, the largest deal in Google's history, with Wiz keeping its brand under Google Cloud and AI-SPM squarely in the portfolio.

That's the runtime layer and the posture layer being absorbed into platform security vendors, which is precisely the consolidation the Market Guide called. The independents left standing are raising like they know it: Noma Security's $100M Series B in July 2025 (led by Evolution Equity, $132M raised in total) was pitched explicitly on AI agent security.

When the acquirers' checkbooks agree with the analyst's diagram, the diagram is probably right.

Guardian agents are the runtime layer growing hands. That's our read, not Gartner's.

Gartner's June 2025 release defines guardian agents as "AI-based technologies designed to support trustworthy and secure interactions with AI," running the range from reviewers and monitors up to autonomous agents that can redirect or block actions. Ten to fifteen percent of the agentic AI market by 2030, per the same release.

Here's what Gartner hasn't done in any public document we could find: connect guardian agents to TRiSM's runtime layer in a single sentence. So take this as AccuroAI's synthesis, not Gartner's. Runtime inspection and enforcement is a job description; guardian agents are that job done by software that can act, not just alert. Once agents transact at machine speed, a human review queue stops being a control and becomes a bottleneck with a false sense of security attached. Enforcement has to live inline. That's the design bet behind our own platform, which inspects over 14 million prompts a day at under 38 milliseconds p99, and it's why we track this category closely in our guardian agent vendor map.

What the framework won't do for you

A framework is a filing system, not a control. The sharpest public criticism of TRiSM is the enforcement gap: policies set expectations but can't stop a prompt at the moment it leaves a device. That argument comes mostly from runtime-security vendors and their distributors, who obviously benefit from it. Being self-interested doesn't make it wrong, and the guide's own structure concedes the point by making runtime inspection a quarter of the market.

Gartner's Hype Cycle placement is a second caveat, straight from the source. Peak of Inflated Expectations means, by Gartner's own model, that a trough of disillusionment comes next. The category label is running ahead of deployed reality, and you should assume vendor claims are too.

And one meta-observation from writing this piece: nearly every accessible description of the 2025 Market Guide comes from vendors named in it. The paywalled report gets summarized by the companies it validates, those recaps become the public record, and the public record then justifies the category. That loop doesn't make TRiSM wrong. It does make provenance-checking mandatory, which is why we labeled ours.

The questions people actually ask

Is AI TRiSM a product I can buy?

No. It's a framework for organizing AI risk work, and Gartner's own guide (via the vendor recaps) says no single vendor addresses everything. Buy by layer, starting where your exposure is worst. For most enterprises that's governance, since you can't protect what you haven't inventoried, or runtime.

What's the difference between TRiSM and AI-SPM?

AI-SPM is a slice of TRiSM, not a rival. Vendor literature consistently frames posture management (discovery, misconfigurations, attack paths) as the part of TRiSM's scope that looks like cloud security. That framing is the vendors', not verbatim Gartner, but it's consistent across the market.

Are the four pillars wrong now?

Not wrong. Superseded as a market description. Explainability, ModelOps, AI application security, and privacy still name real work, but Gartner's 2025 guide reorganized the market around layers of technical capability because that's how products actually get built and bought. Cite the layers in anything current; the pillars date a document instantly.

How does TRiSM relate to NIST AI RMF, ISO 42001, or the EU AI Act?

TRiSM organizes controls; those frameworks and laws impose obligations. You'll still be audited against NIST, ISO, or the Act, and TRiSM's layers are a decent way to structure the controls that satisfy several of them at once. We've mapped the overlaps in our unified AI compliance crosswalk.

See AccuroAI in action.
30-minute demo tailored to your top AI risk.
Book a demo
More from the blog
See AccuroAI in action.

Book a 30-minute demo and see how security teams use AccuroAI to discover, govern, and protect every AI asset across their organization.

Book a demoTalk to security