MOUNTAIN THEORY VS THALES

Thales brings a global defence and data-security heritage to AI, controlling what data agents can access. Data control and action control solve adjacent but genuinely different problems.

Mountain Theory compared with Thales. Competitor detail verified August 2026.
 ThalesMountain Theory
What it controlsWhat data an agent may accessThe action an AI agent is about to take
Where it sitsAt the data layer, policy-maskedInline at execution, between the decision and the action
How policy is setDataset access policyPlain English, no code
Deployment reachOn-prem and cloud, regulated sectorsModel and framework agnostic, including custom and on-prem agents
Best fit whenData protection and sovereignty are the driverAn AI acting wrongly has physical or regulatory consequences

Why you might pick Thales

Thales is a trusted defence and government brand with an existing CipherTrust footprint already deployed in the regulated and public-sector accounts Mountain Theory targets. Their AI Security Fabric covers prompt injection, data leakage, model manipulation and insecure RAG, with an MCP security gateway and end-to-end runtime access control on the 2026 roadmap. Encryption, key management and tokenisation heritage, and a name that is safe to put in a board report.

Why you might pick Mountain Theory

The Thales control is data-access and encryption centric: what data an agent can touch, masked by policy. Mountain Theory governs the action the agent takes, not just the data it reads. Encryption does not stop an authenticated agent from executing a destructive command against data it was legitimately allowed to access.

The honest verdict

Thales controls which data an agent may reach and encrypts it properly. The agent your finance team authorised to read the payments table is allowed to read the payments table. When it is manipulated into exporting that table to an external endpoint, every access was permitted and the encryption worked exactly as designed. Mountain Theory governs the export itself, which is the action encryption was never meant to stop.

What we can actually show

Claims in this category are easy to make and hard to check, so here is ours on the record. The same 10 actions were run in the same order under three configurations. Ungoverned, 10 of 10 executed. Under NVIDIA OpenShell alone, all 5 sandbox-boundary crossings were denied at the kernel, and all 3 in-bounds bad decisions still went through, including a secrets read that printed credentials to the screen. Under OpenShell plus Mountain Theory, those same 3 actions returned HOLD, HOLD and BLOCK, and the secrets read was stopped before it executed, so the credentials never printed. Terminal recordings of all three runs are published, including the two actions Mountain Theory has no policy for.

Separately, when a third-party provider updated the foundation model driving an autonomous agent, the agent began attempting multi-step actions it had never tried before. Nothing on our side changed. Every attempt was stopped on 30 and 31 July 2026, the days the behaviour first appeared. No new rule, no signature, no patch.

Watch the three-configuration run against NVIDIA OpenShell

See novel agent behaviour stopped the day it appeared

Ask Thales, and every other vendor you are evaluating, for the same four things: the exact action set, the ungoverned control condition, the outcome per action including the ones the product did not stop, and the recording. A certification, an integration list or a customer logo answers a different question.

Compare all 56 AI security vendors

Read 31 answers on execution-layer control

Book a demo and see it stop a live agent

Scroll to Top