Fri, 9 Oct 2026

Thales unveils software protection against AI-led reverse engineering

Thales has launched Sentinel Envelope Plus, a software protection add-on designed to make compiled applications more difficult for artificial intelligence tools to reverse-engineer, analyse for vulnerabilities and exploit.

The offering extends Thales’ Sentinel Envelope platform and is aimed at software vendors whose applications run outside environments they directly control. These include on-premises systems, embedded devices and edge infrastructure, where attackers may obtain software copies and analyse them offline.

According to Thales, AI-assisted tools are reducing the time and specialist expertise required to identify vulnerabilities in software. This increases the risk that attackers could uncover proprietary algorithms, business logic and security weaknesses, potentially exposing vendors to intellectual property theft, operational disruption and damage to customer trust.

Sentinel Envelope Plus applies multiple protection layers to selected parts of an application. Thales said the process does not require source code changes or a special compilation environment, allowing developers to strengthen security-sensitive components while balancing protection against performance requirements.

The technology transforms and recompiles selected application components to add safeguards against decompilation, tampering and runtime inspection. Vendors can also combine the protection with licensing functions designed to secure proprietary logic and the controls underpinning commercial software models.

In a controlled test conducted by Thales, an AI agent identified eight of 10 vulnerabilities in an unprotected application. When the same application was protected with Sentinel Envelope Plus, the agent identified none, despite sustained analysis and consuming 970 times as many tokens. After nearly seven hours, the analysis was halted, with the agent recommending that it be discontinued.

Thales stressed that the vulnerabilities remained in the application code. Instead, the protection made them significantly harder to locate and exploit, potentially giving organisations more time to detect problems, prepare fixes and address them through planned release cycles.

Related:  Commvault adds real‑time governance for structured and AI data

“AI is dramatically reducing the time and expertise needed to analyse software for vulnerabilities,” said Damien Bullot, vice-president, Software Monetisation at Thales. “Our testing shows that the right software protection can make AI-assisted reverse engineering significantly more difficult and resource-intensive.”

For software vendors, Bullot said the additional time created by the protection could provide a larger window to identify issues, deploy fixes and protect customers, while also helping safeguard intellectual property embedded in applications.

The launch reflects a shift in the software security challenge. As AI agents become more capable of automating technical analysis and exploit development, vendors increasingly need controls that protect applications after deployment, rather than relying solely on secure development and perimeter-based defences.

Sentinel Envelope Plus is available immediately as a paid add-on to the Sentinel platform.

Related Stories

MORE STORIES