As businesses rapidly introduce autonomous AI agents into daily operations, cybersecurity teams face a new challenge: understanding what these agents can access, what actions they perform and whether they remain within their authorised responsibilities.

On 4 August 2026, Drata announced the limited availability of AI Agent Governance, a security and compliance system intended to provide continuous oversight of enterprise AI agents.

The product initially offers its most comprehensive support for organisations running agents through Anthropic. Drata said native coverage for OpenAI, Google Vertex AI and Amazon Web Services’ Bedrock is under development.

Three layers of protection

According to Drata, the platform operates through three principal components:

  • Drata Sensor: Monitors AI activity occurring through browsers, desktop applications and locally installed models on managed devices.
  • MCP Proxy: Reviews tool requests made by AI agents and compares them with an organisation’s security policies.
  • Telemetry system: Processes and masks activity on the device before transferring it into a durable, tamper-evident evidence record.

This structure is designed to give companies an inventory of the AI agents operating across their environment while recording the actions performed by each system.

Stopping unauthorised actions

Many existing monitoring tools alert security teams after an AI system has already performed an action. Drata claims its new platform can intervene before a prohibited action is executed.

Companies can describe their policies in plain English. The platform then converts those instructions into enforceable rules that determine what an agent may or may not do.

Before activating a policy, organisations can test it against historical activity to understand how it would affect real AI traffic. This could help security teams identify incorrectly configured rules before applying them to production systems.

The platform can also log agent activity, calculate trust scores and identify changes in behaviour. Depending on the permissions established by the organisation, it can recommend action for human approval or automatically block an agent’s request.

AI agents becoming a new security category

Employees and external suppliers have traditionally represented the main groups requiring controlled access to corporate information. Autonomous agents now represent another category because they can interact with databases, business applications, files and other sensitive systems at machine speed.

Without proper governance, an agent might receive excessive permissions, access confidential information or perform tasks outside its intended purpose.

Drata’s announcement reflects a wider shift in the technology industry as businesses move from simply adopting generative AI to establishing formal systems for governing it.

Limited availability

AI Agent Governance is presently available only to qualified enterprises using Anthropic agents. Drata says early-access customers are already operating the system in production environments.

Although the company has presented several strong capability claims, independent testing will be important for determining how reliably the platform prevents unauthorised actions without blocking legitimate business operations.