Drata launches AI Agent Governance for enterprise control
Drata introduces AI Agent Governance to provide real-time monitoring and control of enterprise AI agents. The platform uses sensors, proxies, and telemetry to enforce policies inline, addressing compliance gaps highlighted by recent industry incidents. Initially available for Anthropic environments, it aims to bring rigorous governance standards to autonomous AI operations.

*this image is generated using AI for illustrative purposes only.
Drata, an Agentic Trust Management Platform provider, has launched its AI Agent Governance solution in limited availability to address the critical gap between enterprise AI adoption and regulatory compliance. As enforcement of the EU AI Act begins, organizations face increasing pressure to prove traceability and control over AI agents operating within their environments. The new platform allows enterprises to discover, monitor, and govern these agents in real time, preventing unauthorized actions before they occur rather than detecting them after the fact.
The platform is built on three core layers: the Drata Sensor, which monitors AI activity on managed devices; the MCP Proxy, which evaluates agent tool calls against policy at the point of execution; and Telemetry, which creates a tamper-evident evidence feed. Adam Markowitz, CEO of Drata, emphasized that while major labs like Anthropic have robust safety infrastructure, most enterprises lack basic guardrails. "The ability to proactively discover, monitor, and govern those AI agents in real time is how security teams are getting ahead of it," Markowitz said.
Core Capabilities
Unlike existing tools that offer only retrospective dashboards, Drata’s approach focuses on inline enforcement and proactive discovery. The system operates through three distinct capabilities:
| Capability | Function | Outcome |
|---|---|---|
| Discover | Surfaces shadow AI agents via proprietary multi-dimensional methods | Complete inventory of running agents |
| Monitor | Simulates policies against real traffic and logs every action | Real-time trust scoring and drift flagging |
| Govern | Enforces plain-English intent as machine-enforceable rules | Autonomous or manual intervention before execution |
Policies are authored in plain English and compiled into machine-enforceable rules that stop violating actions inline. Teams can simulate policies against historical traffic to validate controls with zero false-positive risk before enabling enforcement in production.
Market Context and Adoption
The launch coincides with heightened scrutiny following incidents at OpenAI, Hugging Face, and Anthropic, where agents operated past their intended scope. Tushar Badlani, a security and governance specialist, noted that agents represent a "third population" moving at machine speed without established playbooks for access management. He stated, "Agent identity needs the same rigor we built for human and third-party risk: discovery, ownership, and proof an auditor can stand behind."
Early access customers are already using the platform in production. Macky Ruiz, IT Systems Administration Manager at Sonatus, reported that connecting their environment provided an immediate inventory of running agents. "It gives us one standard every agent is held to, instead of chasing down what each developer is doing on their own," Ruiz said.
What the Numbers Show
The strategic timing of this release highlights a structural shift in enterprise risk management. With 8,500+ organizations worldwide already using Drata’s trust network, the expansion into AI agent governance signals that compliance frameworks are evolving from static documentation to continuous, automated verification. The focus on Anthropic as the initial integration partner suggests a prioritization of high-risk, high-autonomy agent environments where the cost of failure is highest. By mapping agent governance to existing controls for ISO 42001 and AIUC-1, Drata is positioning itself not just as a security tool, but as a foundational component of enterprise audit readiness.
How might Drata's integration with ISO 42001 and AIUC-1 standards influence the broader adoption of automated compliance frameworks across other enterprise sectors?
What potential competitive responses can be expected from traditional cybersecurity vendors as the market shifts from retrospective auditing to inline AI agent enforcement?
Could the 'plain English to machine-enforceable rules' model become an industry standard for defining AI safety policies, or will it face fragmentation due to proprietary implementations?

























