Summary
- Darktrace SECURE AI is now generally available after an earlier product introduction.
- The system is intended to identify unapproved AI use, analyse prompts, apply policies, and monitor identities associated with enterprise AI.
- Integrations include AWS, Anthropic, Microsoft, and OpenAI, although efficacy claims remain vendor-supplied.
Darktrace has made its SECURE AI product generally available, extending its behavioural-security platform into the monitoring and governance of generative AI services, prompts, and AI identities.
The Cambridge-based company says the product can identify unsanctioned or unexpected AI use, analyse interactions with AI services, apply enterprise policies, and monitor activity involving sanctioned platforms and autonomous systems.
General availability includes integrations with Amazon Web Services, Anthropic, Microsoft, and OpenAI. Darktrace says those integrations support prompt analysis and visibility of AI usage across enterprise environments.
The launch follows an earlier expansion of Darktrace’s security architecture around AI agents and infrastructure. The company is now moving those capabilities from product direction into a generally available commercial service.
Darktrace says more than 80% of customers represented in aggregated telemetry from roughly 8,200 monitored deployments use generative AI services, while the average customer organisation interacted with five different AI providers during August. Those figures come from Darktrace’s own telemetry and should not be treated as representative of every enterprise.
They do illustrate a governance problem becoming common in large organisations: AI adoption rarely occurs through one controlled platform. Employees may use browser-based assistants, embedded SaaS functions, developer tools, copilots, model APIs, and locally deployed agents at the same time.
That fragments visibility. Conventional web controls may identify access to a service without understanding what data is being entered, while data-loss prevention tools can struggle with newer agent workflows in which information moves through APIs or tool calls rather than a human copying a document.
AI identities create a related problem. An agent may possess credentials or delegated access allowing it to interact with enterprise applications, while its behaviour changes dynamically according to context, instructions, external content, or other agents.
Darktrace’s answer is to apply the behavioural modelling it already uses elsewhere in its portfolio to those interactions. The company says SECURE AI can distinguish expected use from anomalous behaviour and help enforce policies around AI activity.
Those performance claims require evaluation in real deployments. Behaviour-based systems can create value when they provide context unavailable to static controls, but their usefulness depends on telemetry coverage, integration depth, false-positive handling, and whether organisations can turn alerts into enforceable policy.
The product also enters an increasingly crowded market. Identity providers, data-security vendors, cloud companies, and dedicated AI-security startups are all extending controls towards agent discovery, runtime monitoring, prompt protection, data governance, and non-human identity.
That convergence reflects a broader architectural shift rather than a single product category. AI systems increasingly span identity, data, cloud infrastructure, model providers, and application permissions, leaving security responsibilities distributed across teams that previously managed those domains separately.
Darktrace’s general-availability launch gives organisations another way to consolidate part of that visibility. The more consequential test will be whether such platforms can enforce governance consistently as enterprise AI moves from employees asking questions of assistants towards software agents carrying out business processes on their behalf.





