Drata Extends Trust Management Platform to Continuously Monitor and Govern AI Agents
Now in Limited Availability, AI Agent Governance provides continuous control monitoring and evidence collection for all
Press Release Disclaimer: This is a press release distributed through the XPR Media network. It has not been independently verified by our newsroom.

![]()
Drata, the leading Agentic Trust Management Platform, today announced the Limited Availability of AI Agent Governance, designed to help enterprises discover, monitor, govern, and prove traceability of the AI agents running inside the organization. The product ships first and deepest for Anthropic, with early access customers already running it end-to-end in production.
With EU AI Act enforcement beginning earlier this week, the gap between AI adoption and AI governance has become the single largest unmet expectation in the enterprise. The threat posed by that gap lies in what the industry saw in both the OpenAI/Hugging Face incident and the recent news from Anthropic.
While those incidents occurred inside internal research environments rather than a deployed enterprise agent fleet, the pattern is exactly what AI Agent Governance is built to close: an agent operating past its intended scope, caught only after the fact rather than stopped inline. What no one is yet discussing is that the same pattern can just as easily surface inside a single company, driven by an organization’s own agents reaching for access they were never granted to complete a task.
“When Anthropic pulled the guardrails off its own agents, those agents went rogue almost immediately—and that’s Anthropic, with more safety infrastructure than almost anyone,” said Adam Markowitz, CEO of Drata. “But most enterprises don’t even have guardrails on their agents, or a way to trace their access and actions. What we just watched play out with the two biggest frontier AI labs can happen even easier inside enterprises with missing or limited AI governance programs. The ability to proactively discover, monitor, and govern those AI agents in real time is how security teams are getting ahead of it.”
Designed with the same Continuous Control Monitoring that has been core to automating and proving compliance for years, AI Agent Governance from Drata is built on three layers:
- The Drata Sensor: Watches AI activity on managed devices, including desktop and browser AI and local models, via an installed background service.
- The MCP Proxy: Sits at the point every agent’s tool call passes through and evaluates each request against policy.
- Telemetry: Reduces and masks activity on-device before it flows into a durable, tamper-evident evidence feed.
The full lifecycle ships end-to-end for Anthropic today, with native coverage for OpenAI, Google Vertex AI, and AWS Bedrock in active development.
“Every enterprise already has a playbook for two populations with access to sensitive systems: employees and third-party vendors. Agents are a third population moving at machine speed, without that playbook,” said Tushar Badlani, a security and governance specialist focused on proving customer trust and third-party risk. “Agent identity needs the same rigor we built for human and third-party risk: discovery, ownership, and proof an auditor can stand behind. The gap isn’t a shortage of vendors; it’s the lack of a shared bar for what ‘governed’ actually means. Whoever helps the industry converge on that bar first is doing the real work, and the gap only widens the longer we wait to close it.”
Most tools available today stop at surface-level discovery, with a dashboard that shows what agents did after the fact. In contrast, Drata’s approach delivers three core capabilities:
- Discover: Connects to AI tools through a proprietary, multi-dimensional method to surface every shadow AI agent running within the environment.
- Monitor: Simulates policies and controls against real traffic, then puts them into practice, logging every action, scoring each agent’s trust, and flagging drift as it happens.
- Govern: Acts on those signals, surfacing recommended actions for manual approval or, where authorized, enforcing them autonomously.
With Drata, an early warning becomes an intervention before an agent acts—not after. Policy is authored as plain-English intent, compiled into machine-enforceable rules, and enforced inline so a violating action is stopped before it executes. Every policy can be simulated against a year of real historical traffic before enforcement is switched on, so teams can validate with zero false-positive risk in production. And because AI Agent Governance maps to the same controls and evidence logic that already power compliance programs, agent governance becomes part of the trust story a company already tells, especially as they work to comply with the EU AI Act, AIUC-1, ISO 42001, and other AI-focused frameworks.
Customers are already running AI Agent Governance end-to-end today. “We connected our environment and had a real inventory of what was running almost immediately,” said Macky Ruiz, IT Systems Administration Manager at Sonatus. “We said what we wanted in plain English and tested it against real traffic before we turned it on. It gives us one standard every agent is held to, instead of chasing down what each developer is doing on their own.”
AI Agent Governance is available now in Limited Availability to qualified enterprises running agents on Anthropic. Connecting an Anthropic environment to a live agent inventory takes only minutes and provides immediate visibility into the agents running within the enterprise. Companies interested in participating can apply at drata.com/products/agent-governance.
About Drata
Drata provides the trust network that enables businesses to operate, scale, and partner with confidence. Powered by AI and designed to operationalize trust, the Drata Agentic Trust Management Platform continuously interprets controls, risk, and assurance signals — reducing repetitive manual work while improving visibility into internal and third-party risk, enabling always-on audit readiness across compliance frameworks, and accelerating security reviews.
Purpose-built for enterprise complexity, Drata unifies governance, risk, compliance, and assurance to deliver faster time-to-value, reduce operational overhead, and enable continuous trust for 8,500+ organizations worldwide. For more information, visit drata.com.
View source version on businesswire.com: https://www.businesswire.com/news/home/20260804704925/en/
Media gallery


