Summary
- Darktrace / SECURE AI is generally available with integrations spanning AWS, Anthropic, Microsoft, and OpenAI environments.
- The product monitors shadow AI, prompts, agent identities, permissions, and development environments.
- Darktrace telemetry says more than 80% of monitored customer deployments used generative AI services in August.
Darktrace has made SECURE AI generally available, extending security monitoring into the prompts, agents, development tools, and AI services spreading through enterprise technology estates.
The Cambridge-founded cybersecurity company has added integrations covering Amazon Web Services, Anthropic, Microsoft, and OpenAI environments. The product is designed to identify unapproved AI use, analyse prompts, monitor agent identities and permissions, and detect activity moving outside an organisation’s intended policies.
Darktrace says aggregated telemetry from around 8,200 monitored deployments showed more than 80% using generative AI services in August 2026, while the average organisation interacted with five AI providers during the month.
Those are vendor telemetry figures rather than a representative market survey, but they illustrate a security problem appearing before organisations reach the more complicated issue of autonomous agents: employees can expose data through unsanctioned services and approved tools can be used in ways policy teams did not anticipate.
Shadow AI becomes more than an inventory problem
Security teams have dealt with shadow IT for years, particularly as cloud software allowed departments to adopt products without central procurement. Generative AI changes the shape of that problem because one web service can process source code, customer information, contracts, strategy, or other sensitive material without a conventional software deployment.
Businesses consequently need to distinguish prohibited use from legitimate experimentation, inappropriate data handling, and authorised tools behaving in unexpected ways.
Darktrace is extending prompt analysis into environments including enterprise AI assistants and model platforms, while its policy controls are intended to compare actual AI usage with an organisation’s stated rules.
Agents turn permissions into security architecture
The problem becomes more consequential when AI is allowed to act. An employee using a chatbot remains between the model and most company systems, whereas an agent can hold credentials allowing it to search repositories, call tools, modify records, generate code, or trigger workflows without another person approving each step.
Security teams therefore inherit another identity class to manage. Agents need permissions, ownership, intended purpose, monitoring, and revocation mechanisms much as employees and service accounts do, although an agent can generate activity at a speed and volume human users generally cannot.
SECURE AI is designed to expose which agents exist, what they can reach, and whether their behaviour continues to match their expected role. It also extends into development environments where overly broad privileges or configuration errors can be introduced before an agent enters production.
Behaviour still needs context
Darktrace applies the behavioural-security approach used elsewhere in its platform, looking for activity that deviates from established patterns rather than relying solely on known signatures.
Unusual behaviour is not automatically malicious, particularly when organisations are deliberately experimenting with AI. A newly deployed agent may appear anomalous because it lacks history, while legitimate employees can generate sudden spikes in usage around short projects.
Behavioural detection therefore still needs policy and business context to distinguish activity that is merely new from something technically risky or genuinely outside the user or agent’s intended role.
The release reflects a broader change in enterprise AI security. Controls are moving beyond protecting the model itself towards monitoring the ecosystem around it — employees, prompts, agents, permissions, development environments, data, and downstream actions.
As agents acquire greater authority over business processes, organisations will need that visibility even when they cannot predict every unsafe action beforehand.










