Lasso review: AI governance platform scores (2026)

In brief

Lasso ranks 5 of six with 5.60 on our weights. It is strongest on Policy to runtime enforcement and Testing evidence and weakest on Pricing and trial transparency and Regulatory intelligence and expert support. Lasso offers discovery and AI-BOM, detection and response, red teaming and governance for AI apps and agents, and announced a CPU-based guardrail called LEAP on 3 September 2026.

By The Charter Desk, Agentic Governance Compare · Published 2026-10-01 · Vendor pages read 1 October 2026 · Editorial assessment

§ 1 What is Lasso?

Lasso's platform lists Discovery & AI-BOM, AI Security Posture Management, AI Red Teaming, AI Detection & Response, AI Application Security and Intent Security among its modules.

Source: Lasso home page · read 2026-10-01

LEAP and RAPID
On 3 September 2026 Lasso announced LEAP, a transformer-free guardrail that runs on CPUs at under five milliseconds per decision, and a second engine called RAPID. Lasso says LEAP is in production at enterprises and the U.S. federal government (vendor claims).

Source: Lasso announcement, 3 September 2026 · read 2026-10-01

Funding
The same announcement included $30 million in funding.

Source: Lasso announcement, 3 September 2026 · read 2026-10-01

Red teaming
Automated red teaming mapped to MITRE and OWASP; red, blue and purple teaming in one platform; prompt injection, multi-turn attacks, agent-logic corruption and tool-chain exploitation; closed-loop remediation, auto guardrail patching and CI integration hooks.

Source: Lasso AI red teaming page · read 2026-10-01

Governance
Visibility into every agent interaction, policy enforcement and an audit trail for the EU AI Act, NIST AI RMF and ISO 42001.

Source: Lasso AI agent governance page · read 2026-10-01

Analyst mentions
The vendor cites a Leader placement in the Latio 2026 AI Security Market Report and a mention in the Gartner Hype Cycle for AI 2026.

Source: Lasso home page · read 2026-10-01

Languages and modalities
Not described

Source: Lasso home page · read 2026-10-01

Pricing
Not published

Source: Lasso home page · read 2026-10-01

§ 2 What does Lasso document from policy to report?

Control map: Lasso

  1. 1 Policy

    Policy: what the rule says

    The governance use case describes policy enforcement with visibility into every agent interaction.

    Source: Lasso AI agent governance page · read 2026-10-01

  2. 2 Control

    Control: what enforces it

    AI Detection & Response is a platform module; Lasso says its LEAP guardrail runs on CPUs at under five milliseconds per decision (vendor claim).

    Source: Lasso announcement, 3 September 2026 · read 2026-10-01

  3. 3 Evidence

    Evidence: what proves it worked

    Automated red teaming is mapped to MITRE and OWASP, with closed-loop remediation and auto guardrail patching.

    Source: Lasso AI red teaming page · read 2026-10-01

  4. 4 Report

    Report: what an auditor receives

    An audit trail for the EU AI Act, NIST AI RMF and ISO 42001 is described.

    Source: Lasso AI agent governance page · read 2026-10-01

§ 3 How does Lasso score?

Lasso scores on the eight criteria
CriterionWeightScoreReason
AI discovery and inventory128Discovery & AI-BOM is the first module listed on the platform.

Source: Lasso home page · read 2026-10-01

Policy to runtime enforcement188Policy enforcement and AI Detection & Response are described, and Lasso announced the LEAP CPU-based guardrail on 3 September 2026.

Source: Lasso AI agent governance page · read 2026-10-01

Testing evidence168Automated red teaming is mapped to MITRE and OWASP, with closed-loop remediation and auto guardrail patching.

Source: Lasso AI red teaming page · read 2026-10-01

Framework mapping and audit-ready reports148The governance use case describes an audit trail for the EU AI Act, NIST AI RMF and ISO 42001.

Source: Lasso AI agent governance page · read 2026-10-01

Regulatory intelligence and expert support102A regulatory intelligence feed or expert service is not described on the pages reviewed.

Source: Lasso home page · read 2026-10-01

Third-party AI governance103A registry or assessment of third-party or vendor AI is not described on the pages reviewed.

Source: Lasso home page · read 2026-10-01

Languages and modalities102Language and modality coverage is not described on the pages reviewed.

Source: Lasso home page · read 2026-10-01

Pricing and trial transparency101Pricing is not published.

Source: Lasso home page · read 2026-10-01

§ 4 Where does Lasso lead and trail?

Leads the field on

No criterion.

Beats the median on

Policy to runtime enforcement.

Trails the leader on

  • AI discovery and inventory: 8 against Credo AI and Holistic AI at 9
  • Policy to runtime enforcement: 8 against Alice and Pillar Security at 9
  • Testing evidence: 8 against Alice and Pillar Security at 9
  • Framework mapping and audit-ready reports: 8 against Credo AI, Holistic AI and Pillar Security at 9
  • Regulatory intelligence and expert support: 2 against Credo AI at 10
  • Third-party AI governance: 3 against Credo AI at 10
  • Languages and modalities: 2 against Alice at 9
  • Pricing and trial transparency: 1 against SPLX at 6

§ 5 Who should choose Lasso?

Good fit if

  • You want red teaming that patches guardrails automatically, with CI hooks.
  • Low guardrail latency is a stated requirement and you want to test Lasso's LEAP claim in your own pilot.

Look elsewhere if

  • You need regulatory intelligence or expert support described by the vendor.
  • You need a third-party AI register.

§ 6 How does Lasso compare head to head?

Questions about Lasso

  • What is Lasso LEAP?

    LEAP is a CPU-based guardrail Lasso announced on 3 September 2026. Lasso says it decides in under five milliseconds; that is a vendor claim.

  • Which frameworks does Lasso map to?

    Its red teaming maps to MITRE and OWASP, and its governance use case describes an audit trail for the EU AI Act, NIST AI RMF and ISO 42001.

  • Does Lasso publish pricing?

    No. Pricing is not published on the pages we read.