
1 Oct 2026
Classie ships Supervise to watch and stop enterprise AI agents in real time
Classie said Classie Supervise is generally available, giving CIOs and CISOs a way to monitor sanctioned and unsanctioned AI agents as they run, enforce policy inline, and keep a chain-of-custody record of what each agent did and what it cost.
Enterprises are putting agents into production faster than they can inventory them. Supervise’s bet is that governance has to sit on the path where the agent is running, with a transcript of what it did and a way to stop it, rather than in a quarterly spreadsheet of approved tools.
On Thursday, 1 October 2026, Classie said it unveiled its AI supervision platform, and that Classie Supervise is generally available. The GlobeNewswire page is titled “Classie launches Supervise to track, control and account for enterprise AI agents in real time.” The page stamps October 01, 2026, 08:00 ET. The dateline is San Jose, California. The source line is Classie.AI Inc. Classie calls itself an enterprise AI supervision company. The line under the headline says Supervise monitors agent activity and enforces policy across browsers, endpoints, and enterprise compute environments, while providing real-time spend attribution and a chain-of-custody record. An endpoint is a laptop or another device a person uses. Enterprise compute is the company’s own servers and cloud machines. Spend attribution means the usage can be tied to who ran the work. A chain-of-custody record is a log of what happened, in order, that a later review can follow. Those lines are the wire’s.
What the opening says a customer can do. The release says the platform gives chief information officers and chief information security officers one view of AI agent activity across the company. A chief information officer runs the technology. A chief information security officer runs security. With Supervise generally available, the release says, an organization can monitor sanctioned and unsanctioned agents as they run and enforce policy in real time. Sanctioned means the company approved the agent. Unsanctioned means people are using it without that approval. Real time means the watch happens while the agent is acting, not in a report after the quarter. Those lines are Classie’s.
The adoption figures on the wire belong to Gartner, as Classie cites them. Gartner predicts that 40 percent of enterprise applications will include task-specific AI agents by the end of 2026, up from less than 5 percent in 2025. Forty percent is two in five. Less than 5 percent is a small slice of those applications. An enterprise application, here, is software a company runs for its own work. A task-specific agent is software built to do one job. The same paragraph says coding agents can already write and deploy code, and that knowledge-worker agents connect to business applications and act on behalf of employees. Those two sentences are the release’s description of the shift. They are not a count of Classie customers. The 40 percent and the less-than-5 percent are Gartner’s predictions, as the release cites them. They are not a result Classie measured for Supervise.
The governance figure is Gartner’s as well. The release says Gartner reports that only 13 percent of organizations believe they have the right AI agent governance in place. Thirteen percent is about one in eight. Gartner, as the release cites it, warns that growing agent sprawl is increasing the complexity of a company’s technology and exposing companies to risks that include oversharing and data loss. Sprawl, here, means more agents than the company can keep track of. Oversharing means an agent shows data to a person, or a system, that should not have it. The release says Gartner recommends that organizations keep a central inventory of agents and keep watching how those agents are used. An inventory is a list of what is running. Those lines are Gartner’s, as Classie cites them. They are not a survey Classie ran, and they are not a before-and-after score for Supervise.
Poonacha Kongetira, co-founder and chief executive of Classie, is quoted on the release. “AI agents are already becoming part of daily work, often faster than companies can understand how they are being used,” he said. “Real-time supervision is not only about stopping an agent when something goes wrong. Enterprises need to know who initiated the activity, what the agent did, what information it used, and what it cost, and be able to produce a defensible record of what happened afterwards.” He said that by creating that runtime transcript as the workflow happens, Classie gives those technology and security leaders one operational view across the AI tools their employees and developers use, so they can take agents into production with greater confidence. A runtime transcript is the running record of the session, written while the work is happening. Defensible, in his sentence, means a record a company could show later and stand behind. That quotation is his, in the release. The release does not attach a customer count or a price to it.
What Supervise watches, as the release states it. Supervise provides runtime security for sanctioned and unsanctioned agents. It combines an AI posture assessment with inline monitoring and control. A posture assessment is a look at which AI tools are in use and how exposed the company is. Inline means the check sits on the path of the action, so it can act before the action finishes. Supervise follows agent activity across endpoints, browsers, and enterprise compute, and it creates a runtime transcript as the workflow happens. That transcript connects the agent’s identity and the user’s identity with the context, the intent, the data accessed, and the actions taken during the session. Context is the surrounding situation. Intent, here, is what the agent was trying to do. Those lines are the release’s.
How a rule gets enforced. Organizations define rules through an Open Policy Agent policy engine. Open Policy Agent, often shortened to OPA, is an open-source way to write a rule once and have software check it before an action is allowed. Lightweight sensors enforce those rules inline. A sensor, here, is a small piece of software, on the device or in the browser, that watches the agent and applies the rule. The release says signals from sensitive-data detectors and from Classie’s Supervisor agents let the platform stop or redirect an action before it becomes an incident. A sensitive-data detector is a check for information the company treats as confidential, such as a password or a financial record. A Supervisor agent, in this release, is software Classie runs to watch the other agents. The capabilities list says the intervention can alert, restrict, reroute, or stop an agent action as it happens. Alert means tell a person. Restrict means narrow what the agent may do. Reroute means send the action somewhere else. Stop means the action does not complete. Those lines are Classie’s.
The spend record, as the release states it. Because Classie can tie activity and token consumption back to the people, agents, and environments involved, the release says organizations get real-time attributable spend alongside the chain-of-custody record. A token is the unit many AI services use when they bill for usage. Token consumption is that usage. The capabilities list is more specific. It says the platform connects AI activity and token consumption to the users, agents, sessions, and environments that generated it, so a company can see where the AI spend starts. A session is one stretch of work. An environment is the place it ran, such as a laptop, a browser, or a company server. A separate line calls the record an agentic chain of custody: a traceable, auditable log that connects the activity with identity, context, and intent, and that the release describes as tamper-evident provenance for investigation, compliance, and governance. Tamper-evident means a later change to the record would show. Provenance is where the action came from. The release does not print a dollar price for Supervise. For deployment and pricing, it says to contact Classie at letstalk@classie.ai.
The install claim, kept as the company’s. The release says Classie can be installed in 15 minutes and begins discovery immediately. It says the platform is designed to deliver a monitored enterprise posture within five days. Fifteen minutes is the install window the company prints. Five days is the window it says the design is aimed at, for a state in which the company is being watched under the rules. Designed to, in that sentence, is a goal Classie states. It is not a stopwatch the release printed for a named customer and offered as a guarantee on every install. Those lines are Classie’s.
Where Supervise sits in the product line. The general availability of Supervise follows Classie Discover, in April 2026, and Classie Analyze, in July 2026. Discover, the release says, finds sanctioned and unsanctioned AI tools, agents, and models, then maps the people and the data connected to them. A model, here, is the AI system doing the work. Analyze examines agent behavior and intent, replays interactions, and flags activity that needs attention. Supervise applies the company’s rules in real time and steps in when an agent moves outside the boundaries the company approved. The release says the order matters, because a control is reliable only after a team knows what is running and how it behaves, and that Classie builds that context before enforcement starts. It says the platform works across AI vendors, so a company can carry one set of operating rules across a mix of products. Those lines are Classie’s. The release does not say a customer must buy Discover and Analyze before Supervise.
Theresa Lanowitz, principal analyst for cybersecurity at Omdia, is quoted on the release. “AI is a fundamental shift in the way we work, and enterprises want new tools built for AI and the AI era,” she said. She said today’s workforce increasingly includes agents, and that Classie is providing a fresh approach to problems organizations face, including fitting AI into the tools they already use, data leakage, agent behavior, and the economics of AI spending, including where and how the money is being used. Data leakage means information leaving a place it should have stayed. That quotation is hers, in the release. The release gives her the Omdia title. It does not say the quotation summarizes a paid Omdia study, and it does not print an Omdia score.
Where the learning runs, as the release states it. Classie runs its continual-learning infrastructure in the customer’s private cloud. Continual learning means the supervision models keep updating from what they see. A private cloud is computing reserved for that customer, rather than a public service shared with other companies. The release says this lets the customer keep control of the data used to adapt the supervision models, and of the resulting model weights. Model weights are the numbers inside a model that decide how it behaves. The release says the approach keeps what the company has learned about its own work inside the enterprise, and that it helps automate new guardrails over time. A guardrail is a limit on what an agent may do. A capabilities line says private deployment keeps enterprise data inside the customer’s environment. Those lines are Classie’s. The release does not name the cloud vendor, and it does not say the weights are a file the customer can download.
Two customer sketches, and neither names the company. The release describes a healthcare deployment. Classie was installed in 15 minutes and, within 24 hours, identified the known and previously unknown AI tools employees were using. The security team could see complete sessions and the files being accessed, including use of personal AI applications the company had not seen before, and cases where sensitive information was being shared with AI tools the company had neither licensed nor sanctioned. A personal AI application, here, is a tool a person signed up for on their own, not one the company bought. The release says those findings gave the security team a concrete view it could take to leadership and use when it set its rules. The second sketch is a high-growth AI company. The release says Classie surfaced every live AI session within five minutes of installation, including several agent harnesses the company had not tracked. An agent harness is the software frame that runs an agent. The release says that company now uses Classie to put agent transcripts and spend in one place, so leadership can see the activity while it works out how to supervise the agents and how well they are being used. Both sketches are Classie’s. The release does not print either company’s name, and it does not print a dollar figure for either deployment.
Who the about box says Classie is. Classie helps organizations understand and govern AI activity in real time. The platform works across sanctioned and unsanctioned AI systems and runs inside each customer’s environment. The about box says Classie’s founders and leaders have built large-scale AI and machine-learning systems at Google, NVIDIA, and VMware, and that they have deep roots in Stanford AI research. Those employer names are the about box’s account of where the founders have worked. The release does not say Google, NVIDIA, or VMware is a Supervise customer. The trademark line says Classie and the Classie logo are trademarks of Classie AI, Inc. The wire’s source line spells the company Classie.AI Inc. Media inquiries on the release go to classie@watersagency.com. Supervise, and the rest of the Classie platform, the release says, are generally available today.
The picture is Classie’s Supervise product screen, letterboxed on a dark field. The section is labeled Sensitive data detectors, with a Critical label beside it. One detector is labeled Credentials. The line under it says it detects authentication data or patterns, and a status line reads that it was triggered 41 times, 26 minutes ago. A second detector is labeled Financial Information. A control reads Block personal account login. The line under it says it prevents users from logging in to AI services with personal, non-managed Google or Microsoft accounts. A status line says that control is off now, that it was triggered once in this period, and that it was last triggered 28 days ago. Another control reads Block chat sharing on personal account. The line under it says it blocks public chat sharing when the active session is using a personal account. The action choices on the panel read Block, Warn, and Off, and a severity mark reads High. The counts and the times are labels on that screen. The release does not say they are a named customer’s totals. The screen does not print a calendar date.
In plain terms, Classie said on Thursday that Supervise is generally available, so a company can watch approved and unapproved AI agents while they run, on laptops, in browsers, and on the company’s own machines. Rules are written for Open Policy Agent and applied by small sensors that can alert, limit, reroute, or stop an action as it happens. The same record is supposed to show who started the work, what the agent did, what data it touched, and what the tokens cost. Classie says an install takes about 15 minutes, and that the design aims at a monitored posture within five days. The product follows Discover, from April 2026, and Analyze, from July 2026. The two sketches in the release, a healthcare deployment and a high-growth AI company, do not name the companies. Pricing on the wire is a contact address, not a dollar figure. The 40 percent and 13 percent figures are Gartner’s, as Classie cites them.
RELATED
Sources
- GlobeNewswire — Classie launches Supervise, 1 Oct 2026
globenewswire.com
- Classie — Supervise launch, 1 Oct 2026
classie.ai
- Classie — company site
classie.ai