When AI agents spread across international market research company Kantar faster than any manual process could keep up, Noma gave them a systematic way to discover, test, and govern agents allowing teams to ship AI worthy of customer trust.
Industry: Marketing data and analytics
Region: Global
Use Cases: Safe AI adoption, AI red teaming, AI discovery and posture, agentic AI security
Challenge
- In a matter of months, teams across Kantar went from working on a handful of AI projects to having a broad fleet of agents, built by employees throughout the business for their own purposes.
- AI introduced attack vectors the security team never had to defend against, from data poisoning to model distillation, on systems that behave differently every time they run.
- The team applied guardrails and manual checks, but could not answer the questions that mattered most: which policies are we enforcing, which standards are we measuring against, and where are the real risks?
Solution
- Noma AI Red Teaming runs continuous, multi-turn adversarial tests against Kantar’s AI applications and agents, mapped to known attack techniques, so issues are caught before customers or attackers find them.
- Noma AI-SPM discovers the agents, models, and data across Kantar’s environments and turns risk into an actionable list inside dashboards that developers and data scientists use.
- Quick to deploy and easy to operate, Noma gave Kantar a repeatable process: find issues, fix them fast, and raise the bar over time.
A Business Built on Trust, A World That Changed Overnight
Kantar helps the world’s largest brands understand their marketing, customers, and brand through data and analytics. That work runs on trust. Generative AI changed how Kantar builds, and within months, agents multiplied across the business, with people on every team building their own. This broad, fast-growing fleet of agents brought a new kind of exposure.
“Every big technology shift comes with new attack vectors. With AI, it’s completely new attack vectors that didn’t exist before. You have to protect against distillation, data poisoning, and other things that nobody had heard about before AI was really mainstream.”
– Jari Koister, CTO, Insights Product and Technology, Kantar
The stakes were concrete: an agent that returns unexpected answers, leaks data, or exposes confidential information puts customer trust at risk.
Guardrails Were a Start, but Left Hard Questions Unanswered
Kantar moved quickly to put protections in place with guardrails and manual checks. But AI applications are non-deterministic. The same input can produce a different output, so teams can’t test once and call the system safe, and new techniques arrive faster than manual review can keep up. The deeper problem was that the team could not measure where they stood.
“When we started without Noma, we used to apply guardrails, we used to do a lot of checks. But what are the different kinds of policies we applied? What are the standards we are looking into? We were not in a position to answer those questions.”
– Anup Mohan, Lead Applied AI Scientist, Product & Platform Engineering, Kantar
Testing Every Agent Before it Reaches a Customer
Kantar started with Noma AI Red Teaming. An adversarial model runs multi-turn attacks against each application, the kind of probing a real attacker would attempt, and it runs continuously, so coverage keeps up as techniques change. Kantar made it a required step before anything ships to production. The payoff showed up fast on a live application.
“I remember the time when we did the scan on one of the applications where it was a multi-turn prompting, and because of which we found some data which shouldn’t be there. But we were able to fix it as soon as possible with the developers. It was really helpful for us.”
– Anup Mohan, Lead Applied AI Scientist, Product & Platform Engineering, Kantar
Tested iteratively, one application’s security score climbed from 65 percent to 85 percent, and the same gate is rolling out across Kantar’s roadmap. Along the way, Noma surfaced risks the team’s existing tooling had not flagged.
The First Scan Was an Eye-Opener
Kantar’s first engagement was a proof of concept scoped around its own goals. Noma was quick to deploy, and it put findings in front of the developers and data scientists who build the systems, in dashboards they could act on. The results reset the conversation.
“Our first Noma scan was a POC we did around our goals, and I think it was an eye-opener for many of the developers and data scientists on what the risks are and what you can actually address with a tool like Noma. It gave them confidence to be able to tell our customers that the system is safe and secure.”
– Jari Koister, CTO, Insights Product and Technology, Kantar
A Partner for a Field Continually Reinventing Itself
The AI security ecosystem is constantly changing, and tools built for last quarter’s threats age quickly. Kantar was looking for something more durable. Says Jari, “Noma helped us, in a systematic way, to detect issues and make them actionable in a way that we had struggled to do on our own. We felt we found a partner who could work with us and improve and constantly evolve as new threats emerge in the market.”
For the leaders accountable for shipping AI safely, the change comes down to one thing.
“I feel more confident around deploying AI.”
– Jari Koister, CTO, Insights Product and Technology, Kantar
Kantar is one of many enterprises turning to Noma to adopt AI safely. Noma is the AI and agent security platform, purpose-built for the enterprise, and the first AI security vendor in the AWS Security Hub Extended program, with strategic partnerships with Databricks, AWS, and Microsoft. Trusted by Fortune 500 companies.


