Fetching from the wire…
Public story · 2026-09-25 · high
None of the five define what counts as risky agent behavior, even as agent identity and audit trails turn into procurement requirements.
Why now: All five vendors made these announcements on September 24, 2026.
Five security and data vendors announced AI-agent governance products on September 24, spanning SIEM, data science, identity, SaaS management and email security. For anyone selling an agent into an enterprise, agent identity, audit trails and OpenTelemetry output are turning into procurement requirements.
Gurucul's AI Risk and Response product went generally available. Dataiku rolled out Agent Management across its platform. CloudEagle.ai launched a browser extension that blocks logins to AI tools nobody approved. Abnormal AI folded AI Agent Security and AI Governance into its email security platform. Omada acquired EmpowerID to govern agent identities at runtime, alongside human ones.
These five don't compete with each other in daily business, spanning SIEM, data science, SaaS management and email security. All five now sell the same feature: an inventory of which agents run where, plus runtime policy to stop ones acting outside their lane. The framing comes from PR Newswire's writeup of the Gurucul launch.
Omada's move differs from the rest. Buying EmpowerID, instead of building agent governance as a bolt-on feature, treats an AI agent as its own identity class rather than another service account.
None of the five say how they define risky agent behavior, or whether their governance policies read across each other's platforms. A customer running Dataiku alongside Abnormal AI ends up with two separate agent-governance layers and no stated way to reconcile them.
Each link below shares sources, entities, or timing with this story.
September 24: Gurucul made AI Risk and Response generally available (SIEM), Dataiku announced cross-platform Agent Management (data science), Omada acquired EmpowerID for runtime agent governance (identity), CloudEagle.ai launched a browser extension blocking shadow-AI logins...
BigID, Cohesity, Semarchy and SereneDB each released agent identity, permissions or recovery tools on September 22.
Most zeroed in on the same three defenses within days, squeezing Arrakis, Hush and Bloom, which sell agent governance as their whole product.
All three built their new agents on NVIDIA's Agent Toolkit, so the fight is now about autonomy depth, not whose model is smartest.
MCP's new roadmap and A2A's move under the Agentic AI Foundation both point at the same target next: agent identity for enterprise deployments.
EU AI Act Article 50 became enforceable August 2, turning audit logs from an enterprise upsell into a shipping requirement.
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.