
21 Sep 2026
BigID launches AgentIQ for agentic data & AI security
BigID launched AgentIQ, an agentic automation layer that lets customers operate data security and compliance from a prompt or an agent — inside BigID or via Claude, Copilot, GPT, and Gemini — including remediation actions with permission inheritance and audit logs.
SECURITY desk — DSPM, short for data security posture management, is becoming something you prompt, not only something you click — with the audit trail riding along.
Where it runs, still the release. Customers can operate a data security and compliance program from a prompt or an agent, inside BigID or directly from Claude, Copilot, GPT, or Gemini. A prompt is the instruction someone types. The same page also names custom enterprise agents, internal AI platforms, and BigID’s secure MCP. MCP, short for Model Context Protocol, is a shared way for an agent to call a tool. The release does not print a version number for that protocol. File those surfaces as BigID’s. This desk did not open a customer account.
What the release says a person can ask it to do. Ask about the data and AI landscape across cloud, SaaS, on-prem systems, databases, and files, and get a report back. SaaS means software you use through a browser. On-prem means the machines sit in the customer’s own building. Investigate data and access violations and see who and what was affected. Consult a model of the customer’s choice on industry practice, regulatory compliance, and security frameworks. Assess risk ranked by sensitivity, exposure, activity, and business context. Act: revoke access, remediate exposure, apply retention, quarantine, enforce policy, and fulfill requests. Automate those fixes so BigID’s agents, or agents the customer brings, keep running them. Remediate means fix the exposure. Retention is a rule for how long data is kept. Quarantine means isolate it so people cannot keep using it. File that list as BigID’s. This desk did not watch a fix run.
The chief executive’s line, on the same page. Dimitri Sirota, CEO and co-founder of BigID, said: “Every data & AI program is capped by how many people you can put on it. AgentIQ removes the cap.” He also said you describe the outcome you want and the program delivers it: find the risk, decide what matters, act on it, prove it happened. And that an agent without deep data context will give confident, wrong answers about the most sensitive data. File those sentences as his, via BigID. They are not a count of staff this desk checked.
No new console, as the release puts it. AgentIQ is available from inside BigID, and it can also deliver BigID where teams already work, with no new interface to adopt and no security analyst required to run a query. The surfaces named there are Claude, GPT, Gemini, and Copilot; custom enterprise agents and internal AI platforms; and BigID itself. A console, in this sentence, is another screen a security analyst would have to learn. File that no-new-interface line as BigID’s. This desk did not time a query.
Four examples the release says the agent can carry from one request. Find sensitive data exposed to the internet, rank it by business risk, and revoke public access on the top ten. Which AI systems are touching regulated data, and which violate policy — including shadow AI, systems the company did not approve, and sanctioned ones it did. Who has access to customer PII they no longer need, and remove it. PII is personally identifiable information, data that points to a person. Fulfill a data subject request everywhere that person exists. A data subject request is a person’s ask to see, correct, or delete their data. The release says each example is triggered by a single request. The first example also says the agent logs every action. File the four as BigID’s illustrations. They are not named customer results. This desk did not see a log.
Three ways in, still the release, under the heading Buy. Build. Bring. Buy BigID’s agents and deploy in minutes, with no agent engineering. Build your own on BigID’s AgentIQ platform and action surface, wired to the customer’s workflows and policies. Bring agents from popular AI platforms and have them work with BigID through BigID’s secure MCP. File that split as BigID’s. This desk did not deploy an agent.
A second named voice on the same wire. Nimrod Vax, head of product and co-founder, said customers were clear on two points: nobody wants another console, and nobody wants to bet their security program on a single model. “So we built the layer, not the destination. Whatever agent, model, or surface a customer standardizes on, BigID is the intelligence and action layer underneath it.” File the name, the title, and that line as his, via BigID.
Guardrails the release claims, not a control this desk tested. Agents inherit the requesting user’s permissions, enforced at the API and MCP layer rather than in a system prompt. An API is the door a program uses to ask BigID to do something. Inherit, here, means the agent can do only what that person can already do. Every agent action is logged and attributable to a person. Enterprise controls include password vaulting, BYOK, telemetry, and air-gap support. BYOK means bring your own key: the customer holds the encryption key. Telemetry is the stream of logs about what ran. Air-gap means a setup kept off the public internet. No lock-in to one vendor’s agent, one model, or one interface. File those controls as BigID’s claims.
The reach BigID states for itself. AgentIQ spans BigID’s 200-plus integrations across on-prem, cloud, SaaS, and API data sources, covering data at rest, in motion, and in use. At rest means stored. In motion means moving between systems. In use means opened or processed. Two hundred plus is BigID’s count of connectors. This desk did not count them. The about box on the same page says BigID has been named a market leader in data security posture management, or DSPM. DSPM is the category for tools that find sensitive data and show how it is exposed. That market-leader line is BigID’s. It is not a ranking this desk scored.
Do not read the release as a customer-logo list, a breach statistic, or an independent benchmark. It does not print a customer roster, a breach count, or a score from an outside lab. The about box lists awards. This filing does not turn those awards into a new measurement. A prompt that can revoke access is still a company claim until a customer log shows the action.
Plain English for the rest of the card: AgentIQ = BigID’s agentic automation layer for data and AI security and compliance. agentic = the software takes the steps, not only a chat reply. prompt = the instruction someone types. MCP = Model Context Protocol, a shared way for an agent to call a tool. API = the door a program uses to ask another system to act. DSPM = data security posture management, tools that find sensitive data and show how it is exposed. PII = personally identifiable information. data subject request = a person’s ask to see, correct, or delete their data. remediation = the fix, such as revoking access or quarantining a file. permission inheritance = the agent can do only what the person who asked can already do. audit log = a record of who did what. BYOK = bring your own key. air-gap = kept off the public internet. This filing is the 21 Sep release. It is not a test this desk ran.
PRIMARY here: BigID’s 21 Sep 2026 PR Newswire release, “BigID Launches AgentIQ: The Agentic Automation Layer for Data & AI Security and Compliance” — Tier A PRIMARY, the company’s own record, datelined New York, 09:01 ET. The fully agentic interface, the inside-BigID and Claude / Copilot / GPT / Gemini surfaces, custom enterprise agents, BigID’s secure MCP, the ask / investigate / assess / act / automate list, the Sirota quote, the no-new-interface line, the four example requests, the buy / build / bring split, the Vax quote, the permission inheritance and audit-log guardrails, BYOK, vaulting, telemetry, air-gap support, the no-lock-in line, and the 200-plus integrations are the release’s. The DSPM market-leader line is the about box on that same page, BigID’s self-description. NOT claimed: customer logos, a breach count, an independent benchmark, that this desk ran a remediation or audited a permission check, a connector count beyond BigID’s 200-plus, a stock tip, or investment advice. Distinct from the already-filed meta-muse-0day, amazon-blocks-meta-muse, and amazon-perplexity-amended-complaint.
RELATED
On 21 Sep 2026, BigID launched AgentIQ. The record is BigID’s PR Newswire release, datelined New York, stamped Sep 21, 2026, 09:01 ET. BigID calls AgentIQ a fully agentic automation interface to BigID. Agentic, here, means the software can carry out the steps, not only answer a question. An interface is the way a person or another program talks to that software. These lines are BigID’s. This desk did not run AgentIQ.