SentinelOne announced that its Prompt Security offering is now available through Amazon Web Services’ (Sydney) region. The deployment, one of the first in the region, gives organisations a local data-residency option for discovering, governing and securing AI systems that employees, developers, and autonomous-agents use, including visibility into the information being shared and the external tools and systems AI agents can access.
The local deployment comes as Australian government agencies and regulated industries face tighter expectations around the security, control and location of sensitive data. Government hosting requirements and sector risk frameworks are placing greater scrutiny on technology services that process employee prompts, model responses and autonomous-agent activity.
“AI has moved into the daily operations of Australian organisations faster than most security and governance programs were built to accommodate. As of July, Australia ranked number one on Anthropic’s Claude usage index and security must be prioritised to support this rapid adoption”, said Jason Duerden, Area Vice President, Australia and New Zealand at SentinelOne. “For government, financial services, insurance and critical infrastructure, data location can determine whether an AI security service is viable, particularly when it may inspect employee prompts, customer data, proprietary information and autonomous-agent activity. Local hosting removes a major barrier, while SentinelOne Prompt Security gives organisations the visibility and controls to stop sensitive information leaving through AI and set clear boundaries around what agents can access and do.”
That demand is already translating into partner investment, with AU Cyber and New Zealand-based Advantage among the first regional partners investing in services built on the Sydney-hosted platform.
The need for greater control is also reflected in Australian regulatory guidance. APRA has warned that information-security practices are failing to keep pace with AI adoption, identifying prompt injection, data leakage, insecure integrations and autonomous-agent misuse among the emerging risks regulated entities must address. ASD and its Five Eyes partners have also advised organisations to apply continuous monitoring, strict privilege controls and strong identity management to agentic AI, particularly where agents interact with connected tools outside traditional security boundaries.
SentinelOne’s Prompt Security protects AI across three areas:
- Employee & Developer AI security: discovers sanctioned and unsanctioned AI tools, applies usage policies and prevents sensitive data, credentials, source code and intellectual property from leaking through prompts.
- AI application security: tests applications for prompt injection, jailbreaks and data poisoning, then applies runtime controls to block malicious prompts and unsafe outputs.
- Agentic AI security: discovers AI agents, tools and Model Context Protocol servers, enforces least-privilege access and creates a searchable audit record of agent actions and interactions with enterprise systems.
SentinelOne’s Prompt Security is model-agnostic and works across all major AI providers, including OpenAI, Anthropic, Microsoft and Google, as well as self-hosted models. It operates across browsers, desktop applications, AI agents and APIs.
“AI security has to operate where the risk occurs, in the live exchange between a person, model, agent and the tools it can call. Prompts can contain customer records, financial data, source code and credentials, while agents can hold persistent access to enterprise systems. Prompt Security gives security teams real-time visibility and enforcement across those interactions, allowing organisations to use AI productively without giving employees or autonomous agents unchecked access to sensitive information,” said Itamar Golan, General Manager of SentinelOne’s Prompt Security.
Prompt Security was acquired by SentinelOne in 2025 and is a key component of SentinelOne’s AI security portfolio, which secures the use of AI across employees, applications, infrastructure and autonomous agents.











