Drata launches AI agent governance for Anthropic users
Wed, 5th Aug 2026 (Today)
Drata has launched the limited availability of AI Agent Governance, a product aimed at enterprises using Anthropic-based AI agents.
The offering is designed to help organisations discover, monitor and govern AI agents operating in their environments, while creating records of the actions those agents take. Early access customers are already using the system in production.
The launch comes as companies face growing scrutiny over how they manage AI systems in business settings. Drata tied the need for closer oversight to recent incidents involving AI developers, arguing that the risk is not limited to external tools but can also emerge from internally deployed agents that seek access beyond their intended scope.
Adam Markowitz, Chief Executive Officer of Drata, set out the company's view of the problem.
"When Anthropic pulled the guardrails off its own agents, those agents went rogue almost immediately-and that's Anthropic, with more safety infrastructure than almost anyone. But most enterprises don't even have guardrails on their agents, or a way to trace their access and actions. What we just watched play out with the two biggest frontier AI labs can happen even easier inside enterprises with missing or limited AI governance programs. The ability to proactively discover, monitor, and govern those AI agents in real time is how security teams are getting ahead of it," said Markowitz.
Drata said the product is built around three elements: a device-level sensor to watch AI activity on managed devices, a proxy layer that evaluates each agent tool request against policy, and telemetry designed to create a durable evidence feed while reducing and masking activity on the device before transfer.
The initial rollout focuses on Anthropic, which Drata described as its first and deepest integration. Native coverage for OpenAI, Google Vertex AI and AWS Bedrock is in active development.
Governance gap
The broader argument behind the launch is that businesses have established ways to manage employees and third-party vendors with access to sensitive systems, but have not yet created comparable controls for software agents acting on their behalf.
Tushar Badlani, a Security and Governance Specialist focused on proving customer trust and third-party risk, said the market still lacks a common standard for what responsible oversight of AI agents should look like.
"Every enterprise already has a playbook for two populations with access to sensitive systems: employees and third-party vendors. Agents are a third population moving at machine speed, without that playbook. Agent identity needs the same rigor we built for human and third-party risk: discovery, ownership, and proof an auditor can stand behind. The gap isn't a shortage of vendors; it's the lack of a shared bar for what 'governed' actually means. Whoever helps the industry converge on that bar first is doing the real work, and the gap only widens the longer we wait to close it," said Badlani.
Drata's approach is structured around three steps: discover, monitor and govern. Discovery is intended to surface so-called shadow AI agents in an environment, while monitoring applies policies to live traffic, logs actions and flags drift. Governance then uses those signals to recommend actions for approval or enforce rules automatically where a customer permits it.
Policy can be written in plain English, translated into machine-enforceable rules and applied inline before an action takes place. Customers can also test policies against up to a year of historical traffic before turning enforcement on in production.
According to Drata, the product sits alongside existing compliance and assurance efforts, using the same controls and evidence logic for work linked to frameworks such as the EU AI Act, AIUC-1 and ISO 42001.
Early users
One early customer, Sonatus, said the product quickly provided visibility into the agents operating in its environment and gave it a single standard for policy enforcement.
"We connected our environment and had a real inventory of what was running almost immediately. We said what we wanted in plain English and tested it against real traffic before we turned it on. It gives us one standard every agent is held to, instead of chasing down what each developer is doing on their own," said Ruiz.
Drata said the system can connect an Anthropic environment to a live agent inventory within minutes and is currently available on a limited basis to qualified enterprises running agents on Anthropic.