Arcjet vs Datadog AI Guard
Datadog AI Guard is an evaluator that your application calls through the Datadog tracer or an HTTP API. AI Guard returns an allow, deny, or abort verdict on prompts, responses, and tool calls, with policy set in Datadog. Arcjet is an AI agent runtime security platform that enforces policy in the path of the action: in your code for agents and applications you build, and in the hooks of Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code.
The key differences are coverage and data handling. Arcjet covers coding agents through their hooks, and Arcjet's sensitive information detector can run inside your process, while AI Guard receives the content it evaluates. Choose Datadog AI Guard when your AI services already run on Datadog tracing and you want AI verdicts in the same place. Choose Arcjet when you need policy with application context, coverage for coding agents, or content inspection that stays in process.
Arcjet publishes this comparison. Competitor details come from Datadog's public documentation, reviewed on September 25, 2026.
What is Datadog AI Guard?
Datadog AI Guard is a Datadog security product that inspects user inputs, assistant outputs, and tool calls in real time, inline with your AI application or agent. Datadog lists detections for prompt injection and jailbreaking, exfiltration of sensitive data such as PII and secrets, and destructive tool calls. Datadog marks some AI Guard features as Limited Access or Preview, and AI Guard isn't available on Datadog government sites.
You integrate AI Guard through the SDK in dd-trace for Python, Node.js, Java, and Ruby, which requires dd-trace-py 3.19.0, dd-trace-js 5.69.0, dd-trace-java 1.54.0, or dd-trace-rb 2.25.0 or later, or through an HTTP API. Automatic integrations cover LangChain, OpenAI, and Anthropic in Python, the AI SDK and OpenAI in Node.js, and RubyLLM in Ruby. Amazon Strands and LiteLLM Proxy take manual configuration.
The AI Guard API returns ALLOW, DENY, or ABORT with a reason meant for auditing. The SDK can raise AIGuardAbortError on a deny when the service has blocking enabled.
You configure AI Guard policy in Datadog under Security > AI Guard > Settings: per-service policies, a tool blocklist, and a choice between monitoring only and blocking unsafe requests. Datadog documents that AI Guard ignores instructions in the system prompt that try to disable or weaken its checks. Ignoring those instructions is a deliberate design choice that keeps the application from loosening a control that the security team set.
AI Guard arrives with the rest of Datadog. If your traces, logs, and detections already live in Datadog, AI evaluation lands in the same place, with the same access model and the same on-call surface.
What is Arcjet?
Arcjet is an AI agent runtime security platform that discovers the agents running in your organization, enforces policy across every action, prompt, and tool call, and keeps the evidence to prove what happened. Arcjet enforces in the path of the action, in code or in the agent's hook, not on the network.
For agents and applications you build, the Arcjet JavaScript, TypeScript, Python, and Go SDKs provide guard() for tool calls, queue workers, and MCP handlers, and protect() for HTTP routes. Arcjet integrates with 15 agent frameworks, including the Claude Agent SDK, LangChain, LangGraph, Mastra, OpenAI Agents, the Vercel AI SDK, CrewAI, Google ADK, and Strands Agents. You write Guard policies in Rego or a builder, run them in dry run, and publish them from the Arcjet Console or MCP server.
For coding agents, Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code call Arcjet from the hooks they already fire, with no SDK and no code change. One Arcjet policy applies across all five agents, installed through managed settings so developers can't remove it without admin access.
Arcjet detectors cover prompt injection, sensitive information, destination threat analysis with Arcjet threat intelligence, and token budgets. The same SDK covers bots, rate limiting, Shield WAF, and email validation on HTTP routes. On the Enterprise plan, Arcjet decisions export to Datadog, Splunk, SentinelOne, Panther, and Amazon S3.
How do Datadog AI Guard and Arcjet differ?
Datadog AI Guard and Arcjet differ in nine areas, from how each integrates to whether each covers web application security. The following table lists them, and the sections after it cover the three that shape most decisions: coding agents, where content is inspected, and who authors the rule.
| Area | Datadog AI Guard | Arcjet |
|---|---|---|
| Integration | dd-trace SDK or HTTP API call from the application | SDK in the application, or the coding agent's own hooks |
| Coding agents | Not documented for AI Guard | Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code through their hooks |
| Languages | Python, Node.js, Java, and Ruby | JavaScript, TypeScript, Python, and Go |
| Where content is inspected | Prompts, responses, and tool calls are sent to Datadog | Sensitive information detection can run in process; prompt injection detection runs in the Arcjet Cloud API; coding-agent hooks use a server-side detector |
| Where rules are authored | In Datadog, under AI Guard Settings | Guard policies in Rego or a builder from the Console or MCP server; app-specific rules in code |
| Rules with application context | System prompt context adds evaluation input but can't disable or weaken checks | Policies read inputs your code supplies, such as tenant, plan, amount, or recipient |
| What it takes to block | The SDK raises an error on a deny when the service has blocking enabled | Your application or the hook receives a deny before the side effect |
| Destinations | Not documented | Destination threat analysis, egress allowlists, and MCP allowlists |
| Web application security | Covered by other Datadog products, not AI Guard | Bots, rate limiting, Shield WAF, and email validation in the same SDK |
Coding agents
Datadog AI Guard evaluates calls that your instrumented services make. Coding agents such as Claude Code run on developer laptops and in CI, outside those services, and Datadog's AI Guard documentation doesn't describe a hook integration for them.
Arcjet enforces one policy on Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code tool calls through their hooks, so a destructive command or a read of a credential file is denied before it runs. For more information, see how to secure AI coding agents.
Where does each product inspect content?
Datadog AI Guard inspects content in Datadog's service, while Arcjet's sensitive information detector can inspect content inside your process. AI Guard evaluates by receiving the content, which is how an external evaluator works, so prompts and tool calls leave your environment for evaluation. If your prompts aren't regulated content, the inspection location might not matter to you, and the rest of the comparison is where to look.
Arcjet's sensitive information detection can run in your process: a built-in local engine, plus an optional on-device ML model for names, addresses, and government or financial identifiers, so the raw request body isn't sent for that check. A separate server-side detector runs for coding-agent hooks. Rate limiting and prompt injection detection call the Arcjet Cloud API, so the in-process claim covers sensitive information inspection, not every rule. For more information, see keeping security inspection local.
Who authors the rule in each product?
In Datadog AI Guard, the security team sets policy in Datadog. In Arcjet, the security team publishes a central policy that reads context your application supplies.
AI Guard centralizes policy in Datadog and ignores system prompt instructions that try to weaken it. For an organization whose main risk is an application team turning a control down, centralized policy is the right default. The trade-off is that a rule needing application context has nowhere to go: "This refund is above the threshold for this plan tier" requires the plan tier, the refund amount, and the account, and only your application knows them.
Arcjet supports both models. An Arcjet Guard policy is published centrally from the Arcjet Console or MCP server, runs in dry run before going live, and takes effect in real time. The policy reads inputs that your code supplies, so the security team owns the rule and the application supplies the context.
Operational HTTP remote rules for bots, Shield WAF, filters, and rate limits change the same way. For more information, see application-native vs remote security policies.
When an Arcjet check can't finish, you choose what happens next. The direct guard() call fails open and returns ALLOW with an error result that hasFailedOpen() detects. Agent framework wrappers fail closed by default unless you opt in to continuing. For more information, see the Guards reference.
Which fits: Datadog AI Guard, Arcjet, or both?
Choose Datadog AI Guard when your organization is standardized on Datadog, Arcjet when you need coding-agent coverage, in-process inspection, or rules with application context, and both when you want Arcjet decisions next to AI Guard signals in Datadog. The following sections describe the fit for each product.
When to choose Datadog AI Guard
Datadog AI Guard fits when both of the following apply:
- You're standardized on Datadog, and you want AI evaluation to arrive through the same tracer, access model, and alerting as everything else.
- Your AI services run on Python, Node.js, Java, or Ruby, and centrally set policy that application code can't weaken is the property you want most.
When to choose Arcjet
Arcjet fits when any of the following apply:
- You run Claude Code, GitHub Copilot, Cursor, OpenAI Codex, or Muse Code and need one policy on their tool calls.
- Sensitive information inspection needs to stay in your process.
- Rules need application context, such as tenant, plan, or amount.
- You want the same enforcement layer on tool calls, queue workers, and HTTP routes, with bots, rate limiting, and WAF rules.
Using both
Datadog AI Guard and Arcjet can coexist. Datadog remains the place your traces and detections live, and on the Enterprise plan Arcjet exports its decisions to Datadog so you can alert on them next to AI Guard signals. Arcjet tags related decisions with a correlation ID so a run is reconstructable for investigation.
What are the alternatives to Datadog AI Guard?
The alternatives to Datadog AI Guard include enforcement at the action, content-screening APIs, and AI security suites from other security vendors. If you're evaluating Datadog AI Guard, the following products cover overlapping ground:
- Arcjet: enforcement on the action in code and in coding-agent hooks, with in-process sensitive information detection and destination threat analysis.
- Lakera (Check Point): a Guard API that screens prompts, outputs, and agent steps, with a self-hosted option.
- Prompt Security (SentinelOne): employee AI use, homegrown AI applications, and agent controls.
- Prisma AIRS (Palo Alto Networks): runtime security at the network or code layer, plus red teaming and supply chain scanning.
For more comparisons, see Arcjet vs Rein Security and the AI agent security platform category map.
Frequently asked questions
What is the difference between Arcjet and Datadog AI Guard?
Datadog AI Guard is an evaluator that your services call through the Datadog tracer or an HTTP API, returning allow, deny, or abort with policy set in Datadog. Arcjet enforces policy in the path of the action, in your code and in the hooks of Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code, and its sensitive information detector can run inside your process.
Is Arcjet an alternative to Datadog AI Guard?
Yes, for prompt injection, sensitive information, and tool-call policy in AI applications. Arcjet adds coding-agent hooks, destination threat analysis, Go support, and web application security. AI Guard adds Java and Ruby SDKs and lands verdicts in Datadog next to your traces.
Does Datadog AI Guard send my prompts to Datadog?
Yes. The SDK or HTTP API sends prompts, responses, or tool calls to Datadog for evaluation, which is how an external evaluator works. Arcjet's sensitive information detector can run in process so the raw body isn't sent for that check, while prompt injection detection runs in the Arcjet Cloud API.
Can application code change a Datadog AI Guard policy?
Not through the system prompt. Datadog documents that AI Guard ignores system prompt instructions that try to disable or weaken its checks, and that the SDK raises an error on a deny only when the service has blocking enabled. Centralized policy keeps control with the security team, and it also means a rule needing application context, such as a plan tier or refund amount, has nowhere to go.
Can you use Datadog AI Guard and Arcjet together?
Yes. Datadog remains where traces and detections live, and on the Enterprise plan Arcjet exports its decisions to Datadog, so you can alert on Arcjet denials next to AI Guard signals. Arcjet also covers what AI Guard's documentation doesn't describe, such as coding-agent tool calls in Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code.
AI runtime security in your code
Protect your AI agent workflows with Arcjet
Arcjet runs inside your application, where it can use runtime context to enforce agent actions and budgets, detect prompt injection, and protect sensitive information before a workflow acts.