Tuesday, 22 September 2026 · Europe
EUR/USD 1.146 EUR/GBP 0.8578 EUR/CHF 0.9393 EUR/PLN 4.348 All rates →
Sign in · Join
EUROPES The European Report
European Edition Tuesday, 22 September 2026
LATEST 'Outstanding' Jacks 'growing in new role' after five-for vs Sri Lanka Le Flash →
Tech & Startups

Bitdefender built a VPN that hides your AI agent, not you

Bitdefender built a VPN that hides your AI agent, not you

Security can no longer stop at protecting the person behind the screen. It has to extend to the agent itself acting on their behalf. Ciprian Istrate said that on Tuesday. He runs consumer operations at Bitdefender, and the Romanian company was launching a VPN built for AI agents rather than for people. It is a […] This story continues at The Next Web

Security can no longer stop at protecting the person behind the screen. It has to extend to the agent itself acting on their behalf.

Ciprian Istrate said that on Tuesday. He runs consumer operations at Bitdefender, and the Romanian company was launching a VPN built for AI agents rather than for people.

It is a public beta, it costs nothing, and it runs on macOS only. Bitdefender announced it from Bucharest and San Antonio.

A conventional VPN holds one tunnel open for everything on the machine. This one sleeps until an agent asks for it.

The rest of the device keeps its normal connection. Your browser carries on exactly as before.

The plumbing is a Model Context Protocol server. Google used the same protocol last week to open its Home platform to outside agents. It has become the standard way anything attaches to an assistant.

Four clients work at launch: Claude Desktop, Cursor, Codex and OpenCode. Each one restarts once to pick up the configuration, and the user consents to telemetry on first run.

Bitdefender lists them, and each applies to every request the agent routes through its tools.

It masks the agent’s IP, so a site sees the exit server rather than a home address. It opens an encrypted tunnel per request, so whoever runs the coffee shop Wi-Fi cannot read what the agent sends.

It isolates sessions, so a site receiving two requests has no network-level way to tell they came from the same prompt. It gives a clean, non-residential exit address. And it can route a single request through a chosen country.

The company suggests three uses. Checking that a geolocalised page renders correctly for another market, running a research agent from a conference network, and stopping a site correlating dozens of daily requests back to one household.

Bitdefender puts the limits on the product page rather than burying them, which is rarer than it should be.

It protects network transport and IP exposure. It leaves prompt content alone, so the model behind the agent still receives everything it normally would, including account identity.

It is not device-wide and not always on. It covers only traffic the agent routes through Bitdefender’s own tools, so anything an agent fetches with its built-in browsing goes out unprotected.

If a tunnel fails, the request dies inside the container. Nothing falls back silently to the user’s real address.

That last detail matters more than it sounds. Apple shipped a bug last month in which Private Relay leaked real IP addresses through WebKit, which is the precise failure this design refuses to allow.

The announcement says agents can work past geo-blocks and region-locked content without exposing a user’s identity.

Both are Bitdefender’s words, published the same day. The gap between them is the one every agent product currently stands in.

That fight is live. Amazon blocked Meta’s Muse from its store on Sunday night, and it is suing Perplexity over shopping agents.

Payments reached the same question from the other end. Visa, Mastercard and Ant International have been building Know Your Agent schemes, on the principle that a merchant should know what is buying from it.

Bitdefender argues the opposite case for consumers. An agent should be able to work without dragging its owner’s home address behind it.

Pew Research Center found that 71% of US adults think more AI use will make their personal information less secure.

The Cloud Security Alliance puts agents in what it calls an identity grey area. They borrow workload identities, shared service accounts, or the credentials of whoever is running them.

That produces the consequence Bitdefender sells against. Without separation, every network an agent touches ties back to its owner’s IP address.

The requirements run heavier than a normal VPN, because containers do the isolating.

It wants macOS 13 or later on Apple silicon, at least 8GB of memory and around 10GB of free disk. It does not support Intel Macs. The download itself is 31MB.

The beta allows four exit locations at once, or eight on the recommended configuration. Bitdefender will publish latency figures after the beta, which it started on 16 September and plans to run for a month.

There are no team features. No single sign-on, no device management, no central configuration. The company says this release targets individual developers and freelancers.

Bitdefender promises Windows and gives no date. It has not set a price either, and says it will wait for usage data first.

Bitdefender started in Bucharest in 2001 and is Romania’s largest cybersecurity company. It says it holds more than 580 patents and has customers in over 170 countries.

Britain moved the other way on this technology last year, when it dropped its plan to restrict consumer VPNs under the Online Safety Act. That argument was about whether people should be able to hide an IP address. This product asks it about software instead.

More from Tech & Startups