Ent, the intent-aware workspace security company, today announced major platform enhancements that help organizations protect sensitive data and control the applications and AI tools used at the endpoint. The release follows the company’s launch from stealth in June and extends Ent’s prevention-first approach across more of the modern workspace.

A 2026 Protiviti AI Pulse Survey found that 47% of large organizations lack full visibility into the AI tools their employees use, while 65% report challenges with shadow AI. Security teams need to know which tools are active, what data they can access, and whether that activity creates risk. At the same time, the 2026 Verizon Data Breach Investigations Report found that threat actors are using generative AI for targeting, initial access, vulnerability research, and malware development, shrinking the window for defense from months to mere hours. Security teams face more AI activity to govern and faster-moving attacks to stop.

Ent was built ground-up for addressing this exact problem by evaluating and acting on user and agent activity and intent on the endpoint as it happens. It uses context from browsers, applications, AI tools, and files to distinguish routine work from activity that requires intervention. This release extends that intent-aware approach across the data, applications and AI tools attackers abuse, and AI agents through one programmable policy.

“Cybersecurity is shifting from explaining what happened after an incident to stopping incidents, to counter the speed of AI-era threats,” said Elias Manousos, CEO and co-founder of Ent. “The AI-scaled attacks expose the limits of cloud-dependent security. Prevention needs context from browsers, applications, and files so it can distinguish legitimate work from a hijacked user or rogue AI agent. These capabilities bring that control and decision to the endpoint while keeping sensitive context inside the customer’s environment.”

“Modern work creates signals that can look identical on the surface, even when the intent is completely different,” said Andrew Cal, CISO at WestCap. “We use Ent to secure our workspace by understanding the intent behind what users and AI agents are doing, tracking sensitive data movement, and stepping in before the damage occurs, all through one coordinated approach at the endpoint.”

New Prevention Capabilities

AI visibility and control. Ent gives security teams a live view of the AI tools like OpenAI Codex, Claude Code, Claude Cowork, GitHub Copilot, Cursor, workflows and agents that are active in the workspace. They see who is using them, what data is going into them, and whether that activity fits the person’s role. Ent applies the same policy to humans and AI agents. It steers users to sanctioned tools, flags sensitive content before it reaches an AI application, and blocks risky agent behavior where needed.

Endpoint data protection. Ent uses a custom Small Language Model (SLM) on the endpoint to classify sensitive data at the point of use and track how it is created and moved. The classification is attached to the data, and drives the same policy for both humans and AI agents, so data is protected no matter how it is used, moved, or manipulated. Ent moves past just content patterns and uses behaviors to separate routine work from real risk, reducing alert fatigue. Teams can see what data is sensitive, where it came from, where it resides, and where it is going across applications and AI tools.

Threat-aware application control. Ent closes current EDR gaps by identifying applications and AI tools most often abused by attackers and enforcing custom policy-driven interventions to allow, block, deny or restrict usage. Customers can reduce their attack surface by controlling unsanctioned software, shadow AI, weaponized remote management tools, living-off-the-land binaries, and vulnerable drivers.

These build on Ent’s core prevention platform: behavioral context-rich visibility across users and AI-driven work, policy enforcement based on intent, just-in-time customized interventions, and natural-language investigation timelines. Ent runs as a single lightweight agent across Windows, macOS, Linux and modern browsers. Customers can deploy it as SaaS or self-hosted in their own cloud with complete data sovereignty.

Ent will showcase its platform innovations at booth #5341 during Black Hat USA 2026, taking place August 1-6 in Las Vegas.

To learn more, visit ent.ai or request a meeting at ent.ai/contact.

About Ent

Ent is the industry’s first intent-aware Workspace Security platform powering the AI-native enterprise, extending endpoint protection into a real-time layer of prevention across human and AI-driven work. Ent understands not just what users and agents do but why, and intervenes at the moment of risk before incidents occur. Founded by Elias Manousos and Brandon Dixon, co-founders of RiskIQ (acquired by Microsoft) and the team behind Microsoft Security Copilot, Ent is deployed within Global 2000 customers across hospitality, financial services, and defense. Backed by Decibel, Sequoia, Crosspoint Capital, Craft Ventures, Shield Capital, Felicis, and In-Q-Tel.

Protect work as it happens. Learn more at ent.ai.

Connect with us on X and LinkedIn.

Media gallery

About The Author