← News

Gurucul AI Risk and Response dashboard showing AI inventory and threat use cases

24 Sep 2026

Gurucul

Gurucul ships AI Risk and Response to catch Shadow AI and risky agents

Gurucul announced general availability of Gurucul AI Risk and Response, bringing behavioral AI to SOC and Insider Risk teams monitoring Shadow AI, excessive access, and risky autonomous agents — with AI Prevention controls in preview.

TECH desk — when agents can act, security teams need to see who (or what) acted, what they touched, and stop the high-risk moves — not just log another chatbot prompt.

What the lede says the product is. Gurucul calls itself the leader in Unified Entity Intelligence and security analytics. Leader is the company’s word. It says it announced general availability of Gurucul AI Risk and Response, bringing behavioral AI to the growing attack surface created as AI moves from assistant to actor. With hundreds of AI detections connecting activity to identity, access, data, and broader security telemetry, the solution is supposed to help SOC and Insider Risk teams see who or what is acting, recognize threats as they develop, investigate the evidence, and respond before risk escalates. AI Prevention, now available in preview, adds controls designed to stop selected high-risk AI interactions at the point of use. General availability means a normal customer can get the product. Preview means the prevention controls are a first look, not the same general release. Gurucul is also offering organizations an AI Risk Assessment and Report on real data, at no cost. At no cost is the company’s offer. It is not a price card this desk was quoted. These lines are the release’s.

The examples the release uses for why the product exists, and only as the release’s examples. It points at recent incidents involving AI systems interacting with real-world environments, including the compromise of Hugging Face systems by rogue OpenAI agents, and says those incidents showed autonomous AI behavior has security consequences beyond traditional prompts and chatbot interactions. It says Anthropic’s latest threat intelligence report documents increasingly sophisticated cyber operations using Claude, including autonomous agents conducting reconnaissance, exploitation, and data theft with limited human involvement. It says AI systems such as Google Gemini are becoming capable of interacting directly with computers and executing complex tasks, so security teams need to understand not only what AI is asked to do, but what it is actually doing, what it can access, and how its behavior connects to the rest of the environment. Those sentences are the release’s scene-setting. This desk did not re-investigate Hugging Face, and it did not re-read the Anthropic report for this filing.

How the release says the product puts AI activity in context. Gurucul AI Risk and Response is supposed to bring AI activity into the security context around it: who or what initiated it, which identity and privileges were used, what data and systems were reached, and how behavior changed over time. Built on more than a decade of behavioral AI, it analyzes users and autonomous agents as persistent entities to reveal shadow AI, excessive access, and emerging behavioral risk. A persistent entity, here, is a person or an agent the system keeps as one identity across events, instead of a pile of unrelated alerts. Security teams get an evidence-backed view of what happened, why it matters, and how to respond, using playbooks and existing controls. A playbook is a written set of response steps. The release says the product helps teams find risky behavior early and stop it before it escalates. These lines are the company’s aims. This desk did not watch a playbook run.

What preview prevention adds, and what the release says it is not. With prevention capabilities now in preview, organizations gain a layer that identifies and stops risky AI activity at the source. The solution builds on Gurucul’s security information and event management, shortened to SIEM, its user and entity behavior analytics, shortened to UEBA, and its AI insider risk management, shortened to AI-IRM. SIEM is the system that collects security logs. UEBA is the analysis of how a person or an account usually behaves, so a change stands out. AI-IRM is the insider-risk product aimed at AI use. The release says those pieces detect, investigate, and respond to AI-related risk in real time. Unlike standalone AI gateways and other point solutions, it says, this product gives a broader behavioral view of AI risk across the enterprise. A gateway, here, is a middle box that sees only the AI traffic that passes through it. A point solution is a tool that covers one job. The release says it combines AI-platform data with existing proxy, endpoint detection and response, identity, operating system, and cloud telemetry. A proxy is a server traffic passes through. Endpoint detection and response, shortened to EDR, is the software on a laptop or server that watches what runs there. Telemetry is the stream of logs those tools already send. By applying behavioral AI to that connected context, along with hundreds of detections mapped to all 16 MITRE ATLAS tactics and the OWASP Top 10 for LLM Applications, the release says teams can detect, investigate, and respond with machine-speed analysis. MITRE ATLAS is a public framework for how attacks on AI systems are described. The OWASP Top 10 for LLM Applications is a public checklist of common risks in apps built on large language models. A large language model, shortened to LLM, is the software that reads a prompt and writes a reply. The release says the hundreds of detections span five AI security families. It does not name the five families. Do not invent the names. It does not list the 16 tactics or the 10 checklist items. Do not invent those lists. All 16, and the Top 10, are the release’s coverage claims. This desk did not count the detections.

Who the release says needs more than a usage chart. For managed security service providers, shortened to MSSPs, protecting customers from AI risk requires more than visibility into AI usage. An MSSP is a company that runs security monitoring for other companies. The release says they need evidence-rich findings that can be deployed quickly across different customer environments and acted on without adding operational complexity. That sentence is the release’s. It is not a customer count.

What the release says a team can do, in five blocks, and only those. First, reveal AI activity and exposure using data already available. AI data pipelines ingest and normalize activity from leading AI platforms, including Anthropic Claude AI, Gemini Enterprise Agent Platform, Google Gemini, OpenAI ChatGPT, Azure AI Foundry Inventory, and Microsoft 365 Copilot, alongside existing proxy, EDR, identity, operating system, and cloud telemetry. Organizations can identify sanctioned and unsanctioned AI use, build an inventory of agents, models, tools, and hosts, and connect that activity to owners, permissions, and accessible resources. Teams can begin with data they already collect and add direct AI platform integrations for deeper prompt, agent, and audit context. Sanctioned means the company approved the tool. Unsanctioned means someone is using a tool the company did not approve. Second, detect and prioritize known threats and emerging AI risk. Behavioral AI and deterministic detection logic work together to identify Shadow AI, sensitive data exposure, risky autonomous agents, excessive access, AI supply-chain risk, and changes in behavior that fixed rules may miss. Deterministic, here, means a fixed rule that fires the same way each time, beside the behavioral read that looks for a change. Hundreds of detections span five AI security families, with coverage mapped across all 16 MITRE ATLAS tactics and the OWASP Top 10 for LLM Applications. Unified Entity Intelligence combines those findings into an active risk score backed by the evidence that drove it. A risk score is one number for how serious the case looks. The evidence is what the release says sits behind that number. Third, turn AI alerts into identity-resolved investigations. Connect AI activity to the human or non-human identity behind it, along with the systems, tools, data, and relationships involved. A non-human identity is a machine or a piece of software with its own login. Analysts can see what changed, how the activity compares with that entity’s history and with peers, what the AI can access, and how separate events combine into a developing risk. The AI Security Overview, Agent Workspace, and Graph Explorer are the screens the release names as the path from a finding to the affected entities, related activity, and underlying evidence. A graph, here, is that map of connections. Fourth, respond through controls and workflows already in place. Automated and approval-gated playbooks help teams contain risk through connected identity, endpoint, network, and supported AI-platform controls. Approval-gated means a person still says yes before a consequential step. AI-assisted recommendations give analysts response options while keeping them responsible for those actions. Integration with enterprise ITSM routes and tracks remediation through the security and IT processes a company already uses. ITSM is IT service management, the ticket system. The release says that removes the need for a separate response workflow for AI. Fifth, prevent selected high-risk AI activity at the point of interaction. Automated controls identify and stop supported high-risk AI interactions before they escalate. A lightweight browser plug-in is an extra point of control for prompts, pasted content, readable file uploads, and AI destinations, so a company can apply policy where the AI activity happens, while analysts stay in control of enforcement decisions and exceptions. These five blocks are the release’s. This desk did not install the plug-in.

The Blue Mantis quote, as a quote. Jay Martin, CISO and vice president of cybersecurity at Blue Mantis, said customers need to understand not only where AI is being used, but when that use creates risk to sensitive information and critical systems. CISO means chief information security officer. He said Gurucul AI Risk and Response can be enabled quickly using telemetry already available in the customer environment, providing rapid visibility without custom engineering or additional endpoint agents. He said the solution identifies sensitive, non-public information being shared with unapproved generative AI services and correlates that activity with the user and endpoint behavior analysts need to investigate. He said this reduces implementation time, operational overhead, and cost, and lets the security operations team respond more quickly with minimal disruption to customer environments. He said that for an MSSP like Blue Mantis, the difference between seeing AI activity and having the context and evidence behind it is the difference between forwarding another alert and helping a customer understand and address real risk. Those are his sentences on the wire. A quote is not a stopwatch this desk held, and it is not a dollar figure. The page does not print a price next to “cost.” This desk did not interview him.

The chief executive, as a quote. Saryu Nayyar, CEO of Gurucul, said that as AI moves from generating answers to taking action, risk no longer lives inside a single prompt or application. It develops across identities, permissions, data, tools, and actions over time. She said Insider and SecOps teams need to connect those signals to understand what changed, why it matters, and where the risk is headed. SecOps is security operations. She said Gurucul AI Risk and Response applies behavioral AI, entity intelligence, and evidence-backed risk scoring to put AI activity in the context of the broader security environment. She said that gives analysts a clear, actionable view of developing threats and the control to address them early through the workflows they already use. She said that with runtime prevention now in preview, the company is taking the next step: stopping high-risk AI behavior at machine speed at the source. Machine speed is her phrase. It is not a timed response this desk measured. This desk did not interview her. The release says additional supporting quotes can be found at a link it labels “here.” The page this desk read did not print that destination in the body text. Do not invent the URL, and do not invent the other speakers.

When it is on sale, and what the about box adds. Gurucul AI Risk and Response is generally available beginning September 24, with runtime prevention available in Preview. September 24 is the release’s availability day, on a wire stamped the same day. To learn more, the release points at gurucul.com/products/gurucul-ai-risk-and-response/. The about box says Gurucul helps security teams identify and respond to emerging risk earlier by bringing together signals across users, machines, and AI systems. It says more than a decade of expertise in behavioral AI, security operations, and insider risk. It says an open data architecture automatically collects and routes those signals to the customer’s chosen store, reducing data costs by up to 87 percent. Up to 87 percent is the about box’s ceiling. It is not a bill this desk audited, and it is not a measured result for AI Risk and Response alone. Unified entity intelligence, the box says, reasons across the data, fusing behavioral AI and traditional detections into a single active risk score and a contextual case with evidence as known and novel threats develop. Analysts and Gurucul’s agents work cases together and respond at speed within defined controls. The box says Gurucul was named a Leader in the 2025 Gartner Magic Quadrant for Security Information and Event Management, and calls that independent validation of its approach. Leader, and independent validation, are the about box’s words. This desk did not read the Gartner report. The site it names is www.gurucul.com. SOURCE Gurucul is the wire’s last line.

What the still shows, and what the words do not. The card is the Gurucul AI Risk and Response product dashboard from the product page: a dark screen titled AI RISK & RESPONSE, with a View Graph control and a date-range control set to Last 30 Days. Under AI INVENTORY the still prints 236 AI agents monitored, 35 distinct AI models, 130 AI tools used, and 89 hosts with AI projects, each with a change line for that 30-day range. Under AI THREAT USE CASES it prints four cards. Behavioral detection, titled AI Agent Behavioral Anomalies, shows 3 entities and 41 incidents. Agent governance, titled Agents with over-provisioned access, shows 4 entities and 28 incidents. Shadow AI shows 7 entities and 27 incidents. Insider risk, titled Potential insider threat activity, shows 4 entities and 18 incidents. Each card lists sample findings and a priority mark. Those counts, the Last 30 Days control, and the sample rows are the graphic’s. The 24 Sep release does not print them. Do not treat the still as a customer’s books, and do not treat a finding line on the still as an incident this desk investigated. The card has no desk date stamped on it. Last 30 Days is the product’s own range control.

Plain English for the rest of the card. Shadow AI means employees using AI tools the company did not approve. MITRE ATLAS is a threat framework for attacks on AI systems. The release says its detections span all 16 tactics in that framework. The OWASP Top 10 for LLM Applications is a checklist of common risks in AI apps. The release says coverage is mapped to that list. It does not print the ten items. SOC is the security operations center. Insider Risk is the team watching people and accounts inside the company. SIEM is the log system. UEBA is behavior analytics. EDR is the software on the computer that watches what runs. A proxy is a server the traffic passes through. An MSSP is a company that runs security for other companies. General availability is the full release, beginning September 24. Preview is the prevention layer, not that full release. A playbook is the response steps. A risk score is one number backed by the evidence the release says sits behind it. The five AI security families are unnamed on the page. The platforms the release names are Anthropic Claude AI, Gemini Enterprise Agent Platform, Google Gemini, OpenAI ChatGPT, Azure AI Foundry Inventory, and Microsoft 365 Copilot. 08:03 ET is 8:03 a.m. Eastern and 12:03 p.m. UTC. Up to 87 percent is the about box’s data-cost line. The 2025 Gartner Leader line is the about box’s. 236, 35, 130, 89, and the incident counts on the four cards are the dashboard still’s. The free AI Risk Assessment and Report on real data is the company’s offer. This filing is the 24 Sep announcement.

PRIMARY here: Gurucul’s 24 Sep 2026 PR Newswire release, stamped Sep 24, 2026, 08:03 ET and datelined Los Angeles — Tier A PRIMARY, the company’s own announcement. The general-availability launch, the preview line for AI Prevention, the free assessment offer, the leader label, the assistant-to-actor sentence, the Hugging Face and Anthropic and Gemini context sentences, the decade of behavioral AI, the persistent-entity line, the SIEM, UEBA, and AI-IRM sentence, the gateway contrast, the proxy, EDR, identity, operating system, and cloud telemetry, the hundreds of detections, the five unnamed families, all 16 MITRE ATLAS tactics, the OWASP Top 10 for LLM Applications, the MSSP sentence, the six named AI platforms, the five capability blocks, the Martin quote, the Nayyar quote, the September 24 availability line, the up-to-87-percent about-box line, and the 2025 Gartner Leader sentence are that release’s. The inventory counts and the four use-case cards are the product-dashboard still’s. NOT claimed: that this desk installed the product, counted the detections, named the five families, listed the 16 tactics or the 10 checklist items, opened the extra-quotes link, read the Gartner report, audited the 87 percent, treated the dashboard counts as a customer’s books, a dollar price, a named customer beyond Blue Mantis on the quote line, a stock tip, or investment advice. Distinct from the already-filed omada-empowerid-ai-agents, microsoft-eviltokens, salt-security-aidr, and proofpoint-agentic-dai.

RELATED

ONLINE…

article thread

guidelines

warming…

warming…

On 24 Sep 2026 Gurucul announced general availability of Gurucul AI Risk and Response. The record is the company’s PR Newswire release, “Gurucul Launches AI Risk and Response to Detect and Stop Risky AI Behavior Before It Escalates.” The visible stamp is Sep 24, 2026, 08:03 ET, which is 8:03 a.m. Eastern and 12:03 p.m. UTC. The dateline is Los Angeles, Sept. 24, 2026. The source line is Gurucul. The subhead says SOC and Insider Risk teams uncover Shadow AI, excessive access, and risky agents with behavioral AI, identity and security context, and hundreds of detections spanning all 16 MITRE ATLAS tactics and the OWASP Top 10. AI Prevention is now in preview. SOC, a security operations center, is the team that watches alerts and answers them. Insider Risk is the team that watches people and accounts inside the company. These lines are the wire’s. This desk did not open a customer console.

Sources