Arcjet vs Datadog AI Guard

Datadog AI Guard observes and scores LLM traffic. Arcjet blocks unsafe agent actions in your request path.

12 min read
In short: Datadog AI Guard is an evaluator your services call through the Datadog tracer, with policy set in Datadog. Arcjet enforces policy in the path of the action, in your code and in the hooks of Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code, with sensitive information inspection that can stay in process.

Arcjet vs Datadog AI Guard

Datadog AI Guard is an evaluator that your application calls through the Datadog tracer or an HTTP API. AI Guard returns an allow, deny, or abort verdict on prompts, responses, and tool calls, with policy set in Datadog. Arcjet is an AI agent runtime security platform that enforces policy in the path of the action: in your code for agents and applications you build, and in the hooks of Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code.

The key differences are coverage and data handling. Arcjet covers coding agents through their hooks, and Arcjet's sensitive information detector can run inside your process, while AI Guard receives the content it evaluates. Choose Datadog AI Guard when your AI services already run on Datadog tracing and you want AI verdicts in the same place. Choose Arcjet when you need policy with application context, coverage for coding agents, or content inspection that stays in process.

Arcjet publishes this comparison. Competitor details come from Datadog's public documentation, reviewed on September 25, 2026.

What is Datadog AI Guard?

Datadog AI Guard is a Datadog security product that inspects user inputs, assistant outputs, and tool calls in real time, inline with your AI application or agent. Datadog lists detections for prompt injection and jailbreaking, exfiltration of sensitive data such as PII and secrets, and destructive tool calls. Datadog marks some AI Guard features as Limited Access or Preview, and AI Guard isn't available on Datadog government sites.

You integrate AI Guard through the SDK in dd-trace for Python, Node.js, Java, and Ruby, which requires dd-trace-py 3.19.0, dd-trace-js 5.69.0, dd-trace-java 1.54.0, or dd-trace-rb 2.25.0 or later, or through an HTTP API. Automatic integrations cover LangChain, OpenAI, and Anthropic in Python, the AI SDK and OpenAI in Node.js, and RubyLLM in Ruby. Amazon Strands and LiteLLM Proxy take manual configuration.

The AI Guard API returns ALLOW, DENY, or ABORT with a reason meant for auditing. The SDK can raise AIGuardAbortError on a deny when the service has blocking enabled.

You configure AI Guard policy in Datadog under Security > AI Guard > Settings: per-service policies, a tool blocklist, and a choice between monitoring only and blocking unsafe requests. Datadog documents that AI Guard ignores instructions in the system prompt that try to disable or weaken its checks. Ignoring those instructions is a deliberate design choice that keeps the application from loosening a control that the security team set.

AI Guard arrives with the rest of Datadog. If your traces, logs, and detections already live in Datadog, AI evaluation lands in the same place, with the same access model and the same on-call surface.

What is Arcjet?

Arcjet is an AI agent runtime security platform that discovers the agents running in your organization, enforces policy across every action, prompt, and tool call, and keeps the evidence to prove what happened. Arcjet enforces in the path of the action, in code or in the agent's hook, not on the network.

For agents and applications you build, the Arcjet JavaScript, TypeScript, Python, and Go SDKs provide guard() for tool calls, queue workers, and MCP handlers, and protect() for HTTP routes. Arcjet integrates with 15 agent frameworks, including the Claude Agent SDK, LangChain, LangGraph, Mastra, OpenAI Agents, the Vercel AI SDK, CrewAI, Google ADK, and Strands Agents. You write Guard policies in Rego or a builder, run them in dry run, and publish them from the Arcjet Console or MCP server.

For coding agents, Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code call Arcjet from the hooks they already fire, with no SDK and no code change. One Arcjet policy applies across all five agents, installed through managed settings so developers can't remove it without admin access.

Arcjet detectors cover prompt injection, sensitive information, destination threat analysis with Arcjet threat intelligence, and token budgets. The same SDK covers bots, rate limiting, Shield WAF, and email validation on HTTP routes. On the Enterprise plan, Arcjet decisions export to Datadog, Splunk, SentinelOne, Panther, and Amazon S3.

How do Datadog AI Guard and Arcjet differ?

Datadog AI Guard and Arcjet differ in nine areas, from how each integrates to whether each covers web application security. The following table lists them, and the sections after it cover the three that shape most decisions: coding agents, where content is inspected, and who authors the rule.

AreaDatadog AI GuardArcjet
Integrationdd-trace SDK or HTTP API call from the applicationSDK in the application, or the coding agent's own hooks
Coding agentsNot documented for AI Guard

Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code through their hooks

LanguagesPython, Node.js, Java, and RubyJavaScript, TypeScript, Python, and Go
Where content is inspectedPrompts, responses, and tool calls are sent to Datadog

Sensitive information detection can run in process; prompt injection detection runs in the Arcjet Cloud API; coding-agent hooks use a server-side detector

Where rules are authoredIn Datadog, under AI Guard Settings

Guard policies in Rego or a builder from the Console or MCP server; app-specific rules in code

Rules with application context

System prompt context adds evaluation input but can't disable or weaken checks

Policies read inputs your code supplies, such as tenant, plan, amount, or recipient

What it takes to block

The SDK raises an error on a deny when the service has blocking enabled

Your application or the hook receives a deny before the side effect

DestinationsNot documented

Destination threat analysis, egress allowlists, and MCP allowlists

Web application securityCovered by other Datadog products, not AI Guard

Bots, rate limiting, Shield WAF, and email validation in the same SDK

Coding agents

Datadog AI Guard evaluates calls that your instrumented services make. Coding agents such as Claude Code run on developer laptops and in CI, outside those services, and Datadog's AI Guard documentation doesn't describe a hook integration for them.

Arcjet enforces one policy on Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code tool calls through their hooks, so a destructive command or a read of a credential file is denied before it runs. For more information, see how to secure AI coding agents.

Where does each product inspect content?

Datadog AI Guard inspects content in Datadog's service, while Arcjet's sensitive information detector can inspect content inside your process. AI Guard evaluates by receiving the content, which is how an external evaluator works, so prompts and tool calls leave your environment for evaluation. If your prompts aren't regulated content, the inspection location might not matter to you, and the rest of the comparison is where to look.

Arcjet's sensitive information detection can run in your process: a built-in local engine, plus an optional on-device ML model for names, addresses, and government or financial identifiers, so the raw request body isn't sent for that check. A separate server-side detector runs for coding-agent hooks. Rate limiting and prompt injection detection call the Arcjet Cloud API, so the in-process claim covers sensitive information inspection, not every rule. For more information, see keeping security inspection local.

Who authors the rule in each product?

In Datadog AI Guard, the security team sets policy in Datadog. In Arcjet, the security team publishes a central policy that reads context your application supplies.

AI Guard centralizes policy in Datadog and ignores system prompt instructions that try to weaken it. For an organization whose main risk is an application team turning a control down, centralized policy is the right default. The trade-off is that a rule needing application context has nowhere to go: "This refund is above the threshold for this plan tier" requires the plan tier, the refund amount, and the account, and only your application knows them.

Arcjet supports both models. An Arcjet Guard policy is published centrally from the Arcjet Console or MCP server, runs in dry run before going live, and takes effect in real time. The policy reads inputs that your code supplies, so the security team owns the rule and the application supplies the context.

Operational HTTP remote rules for bots, Shield WAF, filters, and rate limits change the same way. For more information, see application-native vs remote security policies.

When an Arcjet check can't finish, you choose what happens next. The direct guard() call fails open and returns ALLOW with an error result that hasFailedOpen() detects. Agent framework wrappers fail closed by default unless you opt in to continuing. For more information, see the Guards reference.

Which fits: Datadog AI Guard, Arcjet, or both?

Choose Datadog AI Guard when your organization is standardized on Datadog, Arcjet when you need coding-agent coverage, in-process inspection, or rules with application context, and both when you want Arcjet decisions next to AI Guard signals in Datadog. The following sections describe the fit for each product.

When to choose Datadog AI Guard

Datadog AI Guard fits when both of the following apply:

  • You're standardized on Datadog, and you want AI evaluation to arrive through the same tracer, access model, and alerting as everything else.
  • Your AI services run on Python, Node.js, Java, or Ruby, and centrally set policy that application code can't weaken is the property you want most.

When to choose Arcjet

Arcjet fits when any of the following apply:

  • You run Claude Code, GitHub Copilot, Cursor, OpenAI Codex, or Muse Code and need one policy on their tool calls.
  • Sensitive information inspection needs to stay in your process.
  • Rules need application context, such as tenant, plan, or amount.
  • You want the same enforcement layer on tool calls, queue workers, and HTTP routes, with bots, rate limiting, and WAF rules.

Using both

Datadog AI Guard and Arcjet can coexist. Datadog remains the place your traces and detections live, and on the Enterprise plan Arcjet exports its decisions to Datadog so you can alert on them next to AI Guard signals. Arcjet tags related decisions with a correlation ID so a run is reconstructable for investigation.

What are the alternatives to Datadog AI Guard?

The alternatives to Datadog AI Guard include enforcement at the action, content-screening APIs, and AI security suites from other security vendors. If you're evaluating Datadog AI Guard, the following products cover overlapping ground:

For more comparisons, see Arcjet vs Rein Security and the AI agent security platform category map.

Frequently asked questions

What is the difference between Arcjet and Datadog AI Guard?

Datadog AI Guard is an evaluator that your services call through the Datadog tracer or an HTTP API, returning allow, deny, or abort with policy set in Datadog. Arcjet enforces policy in the path of the action, in your code and in the hooks of Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code, and its sensitive information detector can run inside your process.

Is Arcjet an alternative to Datadog AI Guard?

Yes, for prompt injection, sensitive information, and tool-call policy in AI applications. Arcjet adds coding-agent hooks, destination threat analysis, Go support, and web application security. AI Guard adds Java and Ruby SDKs and lands verdicts in Datadog next to your traces.

Does Datadog AI Guard send my prompts to Datadog?

Yes. The SDK or HTTP API sends prompts, responses, or tool calls to Datadog for evaluation, which is how an external evaluator works. Arcjet's sensitive information detector can run in process so the raw body isn't sent for that check, while prompt injection detection runs in the Arcjet Cloud API.

Can application code change a Datadog AI Guard policy?

Not through the system prompt. Datadog documents that AI Guard ignores system prompt instructions that try to disable or weaken its checks, and that the SDK raises an error on a deny only when the service has blocking enabled. Centralized policy keeps control with the security team, and it also means a rule needing application context, such as a plan tier or refund amount, has nowhere to go.

Can you use Datadog AI Guard and Arcjet together?

Yes. Datadog remains where traces and detections live, and on the Enterprise plan Arcjet exports its decisions to Datadog, so you can alert on Arcjet denials next to AI Guard signals. Arcjet also covers what AI Guard's documentation doesn't describe, such as coding-agent tool calls in Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code.

AI runtime security in your code

Protect your AI agent workflows with Arcjet

Arcjet runs inside your application, where it can use runtime context to enforce agent actions and budgets, detect prompt injection, and protect sensitive information before a workflow acts.