Skip to content

Product1 publisher3 min readPublished

Omnissa pitches Elara at the unapproved AI assistants employees run on work devices

Omnissa launched Elara for AI governance, citing its own report that AI-assistant use on work devices grew nearly 1,000% in 2025, mostly via unapproved tools. For endpoint teams it is a new category to assess, and the controls Omnissa described attach most clearly to agents IT has already granted access.

The Product Desk · Product desk

Illustration accompanying Omnissa pitches Elara at the unapproved AI assistants employees run on work devices

What happened

  • Omnissa built three of its new agents for IT administrators, handling troubleshooting, Windows app packaging and vulnerability patching.
  • Outside agent tools can connect through a hosted Model Context Protocol server and reach only what the administrator's existing role permits.
  • Horizon Delegate runs inside an employee's virtual desktop under that worker's approved identity and can keep working after the employee disconnects.
  • Omnissa Cloud PC is a desktop service the company runs itself, bundling the underlying compute with its endpoint management and employee experience tools.
  • Omnissa did not give availability dates for any of the new products.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • exposure Because Delegate can keep acting after the employee disconnects, audit logs will show a worker's identity on tasks that worker was not present for.
  • capability Administrators can point a third-party agent tool at Omnissa's platform without handing it more reach than their own role already has.
  • constraint Shops standardised on a cloud other than AWS have to wait for Omnissa to add their provider before Cloud PC can run there.
  • decision Without availability dates, Elara can go on an endpoint team's shortlist but cannot yet be scheduled into a pilot.

Take an employee who opens an AI assistant on a work laptop to summarise a contract. By Omnissa's count, the odds are about three in four that IT never approved that assistant [4]. Omnissa's State of Digital Workspace 2026 report puts usage of such apps on enterprise endpoints at nearly 11 times its starting level by the end of 2025 [3][1]. Sanctioned tools held roughly a quarter of it [2]. These are the vendor's own figures, cited as it launched products at its Omnissa ONE 2026 conference in Orlando [1].

On Omnissa's numbers, most users pick an assistant themselves [4]. Omnissa says the gap is getting worse as employees adopt AI tools faster than IT departments can approve them [2].

Omnissa was spun out of VMware in 2024, after Broadcom bought VMware and sold its end-user computing business to KKR for $4 billion [19]. It pitches Elara as "the authority layer" for AI governance and high-impact enterprise actions [14]. As SiliconANGLE describes the product, it pulls signals from systems that normally run separately, so IT and security leaders can see how AI apps, models and agents are used. It then applies policies set against business conditions before a consequential action goes through [15]. Chief product officer Bharath Rangarajan said AI "is compressing the distance between insight and action" [5].

Each permission control in the launch, including the MCP server's role limits and Delegate's identity scoping, applies to access IT has already granted [11][12]. Whether Elara can stop an employee from opening an unapproved assistant, the behaviour behind the three-quarters figure, is not addressed in the launch coverage [4].

The patch agent has a timing problem of its own. Omnissa says language models are speeding up the discovery of flaws and the time to exploit one has fallen below a day [10]. The agent ranks vulnerabilities and prepares patches, and a human approves before deployment [9]. Phil Hochmuth, a research vice president at IDC, said, "IT leaders need clear visibility into human and AI-driven activity, along with the controls to govern actions at machine speed" [16].

I'd sort any Elara evaluation on a 2x2. One axis is who granted the AI its access, IT or the employee. The other is whether the action only reads or also changes something, such as deploying a patch.

The troubleshooting agent, which recommends fixes from existing playbooks and past support sessions [7], sits in the IT-granted, read-only box; judge it on time to a fix. Delegate, the patch agent, outside MCP tools and the app packaging agent, which tests each app before an administrator reviews it [8], sit in the IT-granted, state-changing box. Their test is the audit trail and how long approvals take. The contract summary from the opening is employee-chosen and read-only, and Elara should be judged there on what its signal feeds detect. The fourth box, an employee-chosen tool that changes something, is the one the launch coverage describes least, and I'd want a live demo of it before any budget moves.

If most of an organisation's AI activity sits in the IT-granted row, Elara is a control panel for agents it was deploying anyway. If most sits in the employee-chosen row, Elara's case rests on seeing tools IT never approved.

What to watch

  • Omnissa publishing availability dates and prices for Elara, the IT agents and Cloud PC.
  • A demonstration of Elara detecting and applying policy to an assistant IT never approved, the use behind Omnissa's three-quarters figure.
  • Any independent measure of AI-assistant growth on company endpoints that confirms or undercuts Omnissa's nearly 1,000% figure.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories