# Bitdefender opens a free macOS beta of AI Guardian, a policy layer for Claude Code and OpenClaw agents

> SecurityBrief reports that Bitdefender AI Guardian checks each action of Claude Code and OpenClaw agents against a policy before it runs. Scope and limits for Mac users.

FireAI Security & Research Team (HisnLabs) · Published 2026-10-02
Canonical: https://hisnlabs.com/en/news/bitdefender-ai-guardian-beta-macos-claude-code-openclaw

SecurityBrief Australia reported on 2 October 2026 that Bitdefender has launched AI Guardian, a security tool for autonomous AI agents, as a free public beta for macOS [[1]](https://securitybrief.com.au/story/bitdefender-launches-ai-guardian-beta-for-mac-agents). The tool is aimed at developers, technical practitioners and other users who rely on AI agents to access tools, files and credentials on their behalf [[1]](https://securitybrief.com.au/story/bitdefender-launches-ai-guardian-beta-for-mac-agents). The initial release supports two agents, Claude Code and OpenClaw.

## Background

AI agents of this kind run commands, read files and call tools on the computer of the person who uses them. The article describes the product as giving users more oversight of what those agents can do and as stopping unsafe actions before they happen [[1]](https://securitybrief.com.au/story/bitdefender-launches-ai-guardian-beta-for-mac-agents). It cites independent research that tested 20 leading AI agents against more than 1,300 tool-poisoning attempts and found an average attack success rate of 36.5 percent, with one model manipulated 72.8 percent of the time [[1]](https://securitybrief.com.au/story/bitdefender-launches-ai-guardian-beta-for-mac-agents).

## What the report describes

According to SecurityBrief, AI Guardian works in three stages: it sets a policy baseline for permitted tools, files and actions, checks each attempted action against that baseline in real time, and returns a verdict of allow, flag or block before the action proceeds. All decisions are recorded in an auditable log [[1]](https://securitybrief.com.au/story/bitdefender-launches-ai-guardian-beta-for-mac-agents).

The article lists the coverage as detecting and blocking prompt injection attempts, inspecting Model Context Protocol tools, validating agent skills before execution, and controlling access to exposed application programming interface keys, secure shell keys and system credentials [[1]](https://securitybrief.com.au/story/bitdefender-launches-ai-guardian-beta-for-mac-agents). Prompt analysis is on-device, and some checks use Bitdefender's cloud services [[1]](https://securitybrief.com.au/story/bitdefender-launches-ai-guardian-beta-for-mac-agents).

The supported versions are Claude Code 2.1.121 or later and OpenClaw 2026.6.6 or later. The release is for macOS only, with no stated timeline for other operating systems, and is available in English only [[1]](https://securitybrief.com.au/story/bitdefender-launches-ai-guardian-beta-for-mac-agents). Bitdefender's senior vice president Ciprian Istrate is quoted as saying that AI agents are becoming a direct extension of the users who rely on them, inheriting the same security risks [[1]](https://securitybrief.com.au/story/bitdefender-launches-ai-guardian-beta-for-mac-agents).

> FireAI, the on-device firewall for macOS developed by HisnLabs, works at the network layer: it asks before an app, including an agent, connects to a destination it has no rule for. A 17-day trial is available. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Implications for Mac users

The report describes a control placed between an agent and the actions it takes on the Mac. It applies to two named agents on macOS and, per the article, does not cover other agents or other operating systems [[1]](https://securitybrief.com.au/story/bitdefender-launches-ai-guardian-beta-for-mac-agents). A person who runs a different agent, or an older version of either one, is outside the stated scope.

The figures about tool poisoning and exposed secrets come from research the article cites, not from a test of AI Guardian. The article, as fetched, does not report how well the product blocks the attacks it describes [[1]](https://securitybrief.com.au/story/bitdefender-launches-ai-guardian-beta-for-mac-agents).

## Recommendations

1. Check the installed agent against the supported versions before relying on any agent-side control: Claude Code 2.1.121 or later and OpenClaw 2026.6.6 or later [[1]](https://securitybrief.com.au/story/bitdefender-launches-ai-guardian-beta-for-mac-agents).
2. Treat a beta as a beta: read what the tool logs and where its cloud checks send data, since the article states that some checks use Bitdefender's cloud services [[1]](https://securitybrief.com.au/story/bitdefender-launches-ai-guardian-beta-for-mac-agents).
3. Keep API keys and secure shell keys out of directories an agent works in where possible, since credential access is one of the listed risks [[1]](https://securitybrief.com.au/story/bitdefender-launches-ai-guardian-beta-for-mac-agents).
4. Review the Model Context Protocol tools and agent skills installed, and remove those that are not needed.

## Relevance to FireAI

FireAI and the product in the report act at different layers. As described, AI Guardian judges an agent's action, such as using a tool or reading a file. FireAI is a firewall for one Mac: it identifies an app by its code signature or path, shows the connections the app opens, and applies [per-app rules](https://hisnlabs.com/en/docs/per-app-rules) to them. A Mac that runs an agent appears in FireAI as the program that starts it, so a rule applies to everything that program runs, and the [Activity](https://hisnlabs.com/en/docs/activity-and-connection-history) page lists the destinations it contacted.

FireAI does not read the instructions given to an agent, does not detect prompt injection, does not inspect Model Context Protocol tools or agent skills, and does not read the inside of an encrypted connection. It does not stop an agent from reading or deleting local files, and it does not control which keys a program may open. It supports neither Claude Code nor OpenClaw as an integration; it sees only their network connections.

> An agent that has been misled still needs an outbound connection to send anything away. FireAI asks before an app contacts a destination it has no rule for. Try it free for 17 days. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Limitations

This item relies on one trade report. Bitdefender's own announcement could not be retrieved, so product details are as SecurityBrief states them, and the article contains no link to a Bitdefender page [[1]](https://securitybrief.com.au/story/bitdefender-launches-ai-guardian-beta-for-mac-agents). The research figures are cited by the article without a named study, and this item did not verify them. No independent test of the product is cited.

Try [FireAI, by HisnLabs](https://hisnlabs.com/en/download) free for 17 days.

## Sources

- [SecurityBrief Australia, 2 October 2026: Bitdefender launches AI Guardian beta for Mac agents](https://securitybrief.com.au/story/bitdefender-launches-ai-guardian-beta-for-mac-agents)
