MOUNTAIN THEORY VS TROJAI (A10 NETWORKS)
Red teaming that probes models, agents and applications at build time, plus real-time threat protection at runtime. Acquired by A10 Networks, announced 15 June 2026, to support sovereign AI security. These two products solve different problems and most enterprises running agents in production have both. The question is not which one, it is what each is actually responsible for.
| TrojAI (A10 Networks) | Mountain Theory | |
|---|---|---|
| What it controls | Red teaming that probes models, agents and applications at build time, plus real-time threat protection at runtime. Acquired by A10 Networks, announced 15 June 2026, to support sovereign AI security. | The action an AI agent is about to take |
| Where it sits | AI red teaming and runtime protection | Inline at execution, between the decision and the action |
| How policy is set | See vendor documentation | Plain English, no code |
| Deployment reach | See vendor documentation | Model and framework agnostic, including custom and on-prem agents |
| Best fit when | AI red teaming and runtime protection | An AI acting wrongly has physical or regulatory consequences |
Why you might pick TrojAI (A10 Networks)
Red teaming that probes models, agents and applications at build time, plus real-time threat protection at runtime. Acquired by A10 Networks, announced 15 June 2026, to support sovereign AI security. If that is the problem in front of you, they are built for it and Mountain Theory is not a replacement for it.
Why you might pick Mountain Theory
Mountain Theory sits at the execution layer, between an AI system's decision and the action it would take. Every proposed action is checked against policy written in plain English and returned as ALLOW, HOLD or BLOCK. It is model and framework agnostic, so it reaches custom and on-prem agents, and it produces an append-only record built to be handed to an auditor.
The honest verdict
Build-time assurance plus their own runtime layer, now inside a network infrastructure vendor. Their runtime defends the model and the application. Mountain Theory governs the action a clean model triggers, so the two sit at different points and most estates would run both.
What we can actually show
Claims in this category are easy to make and hard to check, so here is ours on the record. The same 10 actions were run in the same order under three configurations. Ungoverned, 10 of 10 executed. Under NVIDIA OpenShell alone, all 5 sandbox-boundary crossings were denied at the kernel, and all 3 in-bounds bad decisions still went through, including a secrets read that printed credentials to the screen. Under OpenShell plus Mountain Theory, those same 3 actions returned HOLD, HOLD and BLOCK, and the secrets read was stopped before it executed, so the credentials never printed. Terminal recordings of all three runs are published, including the two actions Mountain Theory has no policy for.
Separately, when a third-party provider updated the foundation model driving an autonomous agent, the agent began attempting multi-step actions it had never tried before. Nothing on our side changed. Every attempt was stopped on 30 and 31 July 2026, the days the behaviour first appeared. No new rule, no signature, no patch.
Watch the three-configuration run against NVIDIA OpenShell
See novel agent behaviour stopped the day it appeared
Ask TrojAI (A10 Networks), and every other vendor you are evaluating, for the same four things: the exact action set, the ungoverned control condition, the outcome per action including the ones the product did not stop, and the recording. A certification, an integration list or a customer logo answers a different question.
Compare all 56 AI security vendors