Product1 publisher3 min readPublished
Darktrace ships SECURE AI to find the AI services its customers never approved
The general availability release arrives with Darktrace's own sensor data as its evidence. That data shows how widely AI gets used inside customer estates; the unapproved share rests on three deployments Darktrace did not name.
The Product Desk · Product desk

What happened
- Darktrace made SECURE AI generally available, selling it standalone or inside its Behavioral Defense Platform and listing it on the AWS and Microsoft marketplaces, seven months after announcing it in February.
- At one early customer, unmanaged use of several AI platforms by contractors led to an immediate legal review, one of three deployment examples the company offered.
- Sessions in ChatGPT Enterprise, Claude, Microsoft Copilot and Amazon Bedrock are scanned in real time for jailbreak attempts, sensitive data exposure and signs of indirect prompt injection.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- constraint Inspection depth now follows vendor choice: a team on one of the four integrated platforms gets risk-ranked sessions, while the fifth provider in the average estate can only be blocked, so two departments get different security answers for the same behavior.
- decision Security leads have to decide whether an AI inventory justifies a new line item when the evidence for scale comes from the seller's own sensors and three unnamed customer deployments.
- exposure Tying each agent to the human who built it puts a name on permissions that skipped approval, and that name is the person who answers at the next access review.
- capability Checking permissions while an agent is still inside Copilot Studio or Bedrock moves the control point ahead of production, so a platform team can refuse a build instead of hunting for it afterwards.
Somebody at one company wrote a policy naming a single approved AI assistant, and most of the staff used unauthorized services anyway, according to Darktrace's account of an early deployment [5].
The scale case is built on Darktrace's own sensors. More than 80% of about 8,200 monitored deployments showed generative AI use in August, which works out to upwards of 6,560 estates on those numbers [2][22]. The average organization dealt with five different AI providers in the same month [3]. Both figures count use. The unapproved share is carried by three examples from early customer deployments [6][5][4].
Five providers on average, four platforms with session-level inspection [8][3]. At least one provider in the average estate therefore sits outside real-time inspection and falls to the shadow AI detection path, which runs partly through secure access service edge integrations such as Microsoft Entra Global Secure Access [23][10].
The agent work is the part a manual inventory will not reproduce. Darktrace maps each agent to the human user behind it and records what that agent is permitted to reach, including inside Amazon Bedrock and Microsoft Copilot Studio while the agent is still being built [12][13]. The early customer with nearly 90 agents in one low-code environment, all created without any approval process, has nearly 90 sets of permissions and no owner of record [4].
Ed Jennings, who became Darktrace's president and chief executive in March, said the industry spent two decades cataloging known threats. "AI breaks that model," he said [15][16]. The signal he points to instead is behavioral: something that "starts behaving differently from what is normal for the organization" [17]. That approach has a standing staffing cost, and the risk ranking on each session is the product's own acknowledgment of it, since nobody reviews every session [9].
Buyers should also separate what ships from what is described. Darktrace is developing capabilities that pair OpenAI's Daybreak models with its own behavioral data to show defenders which people and systems an AI-related incident has touched [18]. Policy checking in the shipping product means uploading your own AI policies as free-form text and having the software compare them against regulatory and compliance frameworks; enforcement stays with blocking a service or quarantining a device [11][10]. SiliconANGLE did not report a price, standalone or as part of the platform [21].
The count is available before the budget conversation. Thirty days of proxy or SASE logs, a list of every AI provider with traffic in them, and an export of the agent list from each low-code tenant. Then two questions per item: can the sessions be inspected, and does a named person own it. Anything failing both is what the money is for, and in the average estate Darktrace describes, there is at least one such provider [23].
What to watch
- A second month of Darktrace telemetry that splits sanctioned from unsanctioned AI providers would test the shadow AI claim directly.
- Integration coverage beyond AWS, Anthropic, Microsoft and OpenAI. Each platform added shrinks the gap between five providers and four inspected ones.
- Whether Microsoft or OpenAI fold comparable session inspection into their own admin consoles, undercutting a standalone line item.