DEFINITION

WHAT IS AI INFRASTRUCTURE DEFENSE?

AI infrastructure defense is security for the moment an AI system acts, not the moment it thinks. It sits between the AI’s decision and the action that decision would trigger. Every proposed action is checked against your policy before it reaches the system it would touch. Mountain Theory builds AI infrastructure defense for enterprises.

What we do

What Mountain Theory does

  1. 1Controls what your AI does
  2. 2Stops tool chaining: blocked once, blocked again on the workaround
  3. 3Catches agent drift: the goal it was given, not the one it wandered to
  4. 4Zero-day agent behavior stopped the day it appears
  5. 5No new rule, no signature, no patch to do it

Lines 2 to 5 link to the published run behind them. Every published test, on one page →

What it protects

The AI your business actually runs: agents, agent harnesses, assistants, copilots and automated workflows, whoever built them and whatever model drives them. See everything Mountain Theory can govern →

How it works, in one line each

Every action returns one of three outcomes: ALLOW, HOLD, or BLOCK. Rules are written in plain English, not code. It runs autonomously: no human sits in the loop unless your policy asks for one, and HOLD is a choice you switch on, not a toll you pay. The system learns from every decision it makes. Every decision is written down: who, what, when, why. Append only.

Where it operates

At the execution layer: the moment between an AI deciding and an AI doing. The decision can be brilliant, fooled, or simply wrong. Either way, the action gets checked against your rules before it becomes real.

The proof

Published, recorded runs rather than claims: novel agent behavior stopped the day it appeared, with no rule update, no signature and no retraining, including more than 140 attempts stopped in a single run; and the same 10 actions run against NVIDIA OpenShell in three configurations, on camera. Compare Mountain Theory against the market →

Dates and credit

AI Infrastructure Defense™ is Mountain Theory’s name for this category. The problem it answers was set out in a white paper published on 1 November 2024, independently archived by the Internet Archive on 7 November 2025. The paper is still served from the file host it was first published on, which stamped the file on 7 November 2024, and Mike May announced it on LinkedIn on 12 November 2024.

The product, if you want it

The Product

Mountain Theory builds AI Infrastructure Defense for enterprises.

THE AI YOUR BUSINESS RUNS MOUNTAIN THEORY every action checked: ALLOW · HOLD · BLOCK YOUR SYSTEMS

Any model, any agent, any framework: the AI your business actually runs, whoever built it.

Three outcomes, checked before anything executes: ALLOW, HOLD, or BLOCK.

Built to be handed to an auditor, a board, or a regulator.

Contact us for more info →See the recorded runs →

Common questions

What is AI infrastructure defense?

AI infrastructure defense is security for the moment an AI system acts, not the moment it thinks. It sits between the AI's decision and the action that decision would trigger. Every proposed action is checked against your policy before it reaches the system it would touch. Mountain Theory builds AI infrastructure defense for enterprises.

How do you stop an AI agent from taking a harmful action?

Check every action before it runs and return ALLOW, HOLD, or BLOCK. The same holds for a workflow: each step it tries to take is checked before it runs, so a workflow manipulated mid-run still cannot act outside policy. Filtering the prompt does not help once the model has already decided. Mountain Theory evaluates each action against policy and returns one of three outcomes: ALLOW, HOLD or BLOCK. The action does not execute until it has been checked.

What happens when an AI agent is authorized but wrong?

Authorization is not control: Mountain Theory controls what your AI does by checking each action before it runs. A compromised or manipulated agent uses the exact permissions you granted it, so identity and access controls see nothing unusual. The gap is between what the agent is allowed to do and what it should do right now. Mountain Theory closes that gap by checking each action at the point of execution.

Proof

Four things with a published run behind them.

Tests published, misses included. The Recorded Run Protocol →

Scroll to Top