The nightmare scenario isn't hard to imagine: an AI agent accidentally refunds a thousand orders instead of one, or pushes code to production that takes down payment processing for hours. These aren't hypothetical risks anymore—they're Tuesday afternoon for engineering teams deploying autonomous systems at scale.
Salus, a two-person outfit from Y Combinator's Winter 2026 batch, thinks it has spotted a gap in the tooling. Rather than logging what AI agents did wrong after the damage is done, the San Francisco startup intercepts risky actions milliseconds before they execute. If an agent is about to transfer funds without first checking account balances, or modify database records without verifying permissions, Salus blocks it.
"We're validating all your agent's actions before they execute," co-founder Vedant Singh said in materials accompanying the company's mid-February launch. Not after. Before.
That temporal distinction—catching mistakes at the execution boundary rather than in post-mortem analysis—has become the new battleground in AI infrastructure. It's also attracting a surprising amount of company formation. NVIDIA, Akto, HaliosAI, and a handful of academic labs have all released variants of pre-execution guardrails in the past few months. The question is whether the market needs yet another layer in an already complex stack, or whether Salus has found something its competitors missed.
Evidence, Not Just Rules
Most guardrail systems work like bouncers: they check IDs at the door. Salus wants to be more like an investigator, tracing whether the agent actually gathered the information it claims to have before taking action.
The company calls this an "evidence cache." Throughout an agent's run—whether it's answering customer service inquiries or processing financial transactions—Salus maintains a record of what data the agent has retrieved through previous tool calls. When the agent proposes a new action, the system doesn't just check abstract policy rules. It verifies that the agent possesses the specific evidence required to justify that action.
A customer service bot trying to issue a refund? Salus checks whether it first pulled up order details and verified the customer's identity. An agent modifying production code? It looks for evidence the agent reviewed test results or obtained the right approvals.
Engineering teams write these constraints in YAML, Markdown, or plain English—the system compiles them into version-controlled runtime checks. There are additional layers for PII detection, budget caps, infinite loop protection, and human escalation when the stakes get too high for full automation.
The implementation is deceptively simple. Wrap a Python decorator around each tool function, specify what kind of evidence it produces or requires, add @session.protect. When validation fails, the system raises a PreflightBlockedError.
When Blocks Become Feedback Loops

Here's where it gets interesting, or at least where Salus diverges from the competition. Rather than stopping execution cold when an action violates policy, the system returns structured feedback explaining what went wrong. The agent can then adjust and try again.
Internal benchmarks suggest this retry mechanism works more often than you'd expect. According to the company's YC launch post, 58% of blocked actions recover and complete the task correctly with structured feedback. Which matters, because wasted LLM calls add up fast.
On τ²-bench—a customer service benchmark covering airline, retail, and telecom scenarios—Salus claims agents followed policies more reliably at up to 60% lower cost. The savings appear to stem from avoiding expensive paths that were doomed to fail anyway. On ODCV-Bench, designed to test whether agents cut corners under KPI pressure, Salus reduced policy violations by 52% on average across a dozen frontier models.
Both benchmarks date from early 2026. Independent technical validation hasn't surfaced yet—at least not publicly—which makes the performance claims difficult to verify. But if the numbers hold, they suggest something more valuable than just risk mitigation: a way to make AI agents cheaper to run.
A Crowded Gate

Salus is hardly alone at the execution boundary. NVIDIA's NeMo Guardrails handles dialogue control for customer service bots. Akto launched AgentGuard in January with real-time policy evaluation. HaliosAI, VirtueGuard, and several others offer similar pre-execution enforcement. Academic papers on AEGIS, ToolSafe, and Proof-of-Guardrail all appeared in the first quarter of 2026.
The sudden convergence suggests the industry has decided timing is everything. Observability platforms like LangSmith and Helicone log what happened after the fact. Evaluation frameworks test hypothetical agent behavior. But catching bad actions at the moment of execution—that's the new line of defense.
"Most existing tools are reactive," the Salus launch materials note. "We insert a policy and evidence gate just before actions execute."
Perhaps. Though the competitive moat here looks fragile. Anthropic's Claude Code already includes PreToolUse and PostToolUse hooks for guardrail logic. OpenAI's Agents SDK documentation mentions that built-in guardrails can block execution, though some native tools bypass those pipelines. If the major framework providers bake validation directly into their SDKs—and there's every reason to think they will—the question becomes whether third-party guardrail layers remain necessary at all.
Early Days, Quiet Launch

Salus lists compatibility with OpenAI, Anthropic, LangChain, LangGraph, and CrewAI. The company's website shows Python code snippets with decorator syntax and exception handling, alongside a "book a demo" button. Launch materials reference pip install salus-ai, though the package doesn't appear in the public PyPI index as of mid-March—suggesting invite-only distribution or a private repository during early access.
There's no published pricing. No customer logos. Terms of service went live January 15, 2026, with standard data processing and liability language defining the product as pre-execution action validation.
The founders, Kevin Pan and Vedant Singh, are Stanford roommates who both studied computer science and are now running everything as a two-person team. Singh's personal site describes his work as "making AI agents reliable"—a framing that tracks with the broader 2026 narrative taking shape across the industry. This is supposedly the year autonomous systems graduate from flashy demos to operational workflows. It's also the year teams start demanding infrastructure to keep those systems from making expensive mistakes.
The technical challenge isn't whether to validate agent actions. Everyone agrees that's necessary. The harder questions are when to validate, at what cost to latency, and whether that validation needs to live in a separate layer or can be folded into the frameworks themselves.
Salus's bet is that blocking risky actions before they produce side effects is cheaper than debugging them afterward. It's a reasonable hypothesis, grounded in benchmarks that will need more scrutiny as real production workloads test the system. For now, the company is one of several racing to define what guardrails mean in practice—and whether developers will pay for them as a standalone product or wait for the platforms to build the capability natively.
That's the unspoken tension in this market: every guardrail startup is also potentially a feature request for OpenAI or Anthropic. Which means Salus and its competitors have a narrow window to prove they've built something defensible—or risk becoming footnotes in someone else's release notes.
