Full Report
Broadcom and Tetrate are bringing enterprise DLP inline at Agent Router—same policies, same console, new channel
Analysis Summary
# Industry News: Broadcom and Tetrate Bridge the "Agentic AI" Data Gap
## Summary
Broadcom (Symantec) and Tetrate have partnered to integrate enterprise Data Loss Prevention (DLP) directly into the Tetrate Agent Router. This collaboration allows organizations to inspect and control sensitive data flowing through AI agents and LLMs using existing Symantec DLP policies and consoles.
## Key Details
- **Date:** Announced October 6, 2026 (Preview status)
- **Companies Involved:** Broadcom (Symantec) and Tetrate
- **Category:** Product Partnership / Technology Integration
## The Story
As enterprises shift from simple chatbots to "agentic AI"—autonomous agents that call tools, access databases, and interact with other services—a new security blind spot has emerged. Traditional DLP (focused on email, web, and endpoints) cannot see machine-to-machine API traffic or the internal reasoning loops of an AI agent.
The integration places Symantec DLP inline at the **Tetrate Agent Router**, which acts as the data plane for AI traffic. As agents send prompts to models, receive responses, or execute tool calls (e.g., pulling a customer record or drafting an email), the traffic is intercepted at four key points. If the AI attempts to pass regulated data (like credit card numbers or internal documents) to an unauthorized model or tool, the system can monitor or block the action in real-time. Crucially, this happens without requiring developers to change a single line of code in the AI agents themselves.
## Business Impact
### For the Companies Involved
- **Broadcom (Symantec):** Reaffirms Symantec’s relevance in the AI era by extending its legacy DLP dominance into cloud-native, agentic workflows.
- **Tetrate:** Validates Tetrate’s Agent Router as a critical piece of enterprise infrastructure, moving it beyond a performance/routing tool into a core security enforcement point.
### For Competitors
- **DLP Competitors (Forcepoint, Netskope):** Faces pressure to provide similar "agent-aware" inspection that goes beyond simple browser-based GenAI protection.
- **AI Security Startups:** May find it harder to displace incumbents if Symantec can successfully cover AI channels using existing customer licenses and workflows.
### For Customers
- **Reduced Complexity:** Security teams can use the same policies and incident response queues they already use for email and endpoint protection.
- **Faster AI Adoption:** Compliance and risk teams are more likely to approve autonomous AI projects if they have "prevent" mode controls over the data those agents handle.
### For the Market
- Signals a shift toward **AI Gateway** architectures as the standard way to govern enterprise AI usage, rather than relying on decentralized security controls.
## Technical Implications
- **Four Interception Points:** Inspection occurs at the Prompt, Model Response, Tool Call, and Tool Result stages.
- **Zero SDK/Code Changes:** Integration is handled at the network/router level (Envoy-based), making it invisible to AI developers.
- **Data Sovereignty:** Detection runs alongside the data plane within the customer’s trust boundary, ensuring raw data isn't sent to a third-party cloud for scanning.
## Strategic Analysis
- **Market Positioning:** Broadcom is positioning itself as the "Data Safety Net" for the autonomous enterprise.
- **Competitive Advantage:** The use of **Exact Data Matching (EDM)** and **Indexed Document Matching (IDM)**—technologies Symantec has refined for decades—gives this solution higher accuracy than basic keyword-based AI security tools.
- **Challenges:** Performance overhead. Inline inspection of high-velocity API traffic can introduce latency, which may impact the "machine speed" efficiency of agents.
## Industry Reactions
- **Analyst Perspective:** This is seen as a necessary evolution. As agents begin acting as "digital employees," they require the same oversight as human employees, but at a much higher scale and speed.
- **Market Response:** Likely positive for heavily regulated industries (Finance, Healthcare) that have been hesitant to deploy agentic AI due to data leakage fears.
## Future Outlook
- **In-line Redaction:** Future updates are expected to allow the system to "mask" or redact sensitive data on the fly rather than just blocking the entire request.
- **Expanded Coverage:** Deeper integration with Model Context Protocol (MCP) and a wider variety of LLM providers.
## For Security Professionals
- **Action Item:** Review existing DLP policies to ensure they are "AI-ready" (e.g., identifying fingerprints for internal documentation used to train RAG systems).
- **Deployment Strategy:** Follow the "Day 1 Monitor, Day 2 Prevent" methodology suggested to understand how agents use data before turning on blocking mode, which could break automated workflows.