Darktrace SECURE AI is now generally available with shadow-AI discovery, prompt analysis and policy controls spanning major enterprise AI platforms.

Key takeaways

  • General availability adds integrations with AWS, Anthropic, Microsoft and OpenAI.
  • The product focuses on discovering shadow AI, analysing prompts and applying policy to data exposure.
  • Customers still need to validate coverage, response actions and false-positive rates in their own environment.

What became available

Darktrace made SECURE AI generally available on September 22. The product extends the company’s behavioural security approach to enterprise use of generative AI and autonomous agents. Its stated functions include finding sanctioned and unsanctioned AI activity, analysing prompt behaviour, connecting activity to identities and data, enforcing policy and helping teams respond. SiliconANGLE independently reported the availability and named platform integrations.

Why shadow AI is the first problem

Security teams cannot govern tools they cannot see. Employees can access public chatbots, connect assistants to corporate documents or activate AI features embedded in existing software. Darktrace says SECURE AI establishes a behavioural baseline and surfaces unexpected use. Discovery is useful, but buyers should test whether it identifies browser, API and embedded traffic without treating every novel model interaction as an incident.

Prompt context changes data-loss analysis

Traditional data-loss controls often inspect content and destinations. AI interactions add intent, tool use and multi-step actions. A harmless-looking prompt can cause an agent to retrieve sensitive records or invoke another system. Darktrace says its product combines prompt analysis with behavioural and data context. Enterprises should confirm which prompts are captured, how sensitive content is protected, where logs reside and whether encrypted or local-model traffic remains visible.

Automation needs firm boundaries

A security product that responds automatically to agent activity can reduce containment time, but it can also interrupt legitimate workflows. Teams should begin in observe-only mode, document response authority and require human approval for disruptive actions. Tests should cover compromised accounts, prompt injection, bulk data access, unexpected tool calls and normal high-volume jobs. False positives, missed detections and investigation time matter more than a feature checklist.

What buyers should verify

Darktrace lists integrations with AWS, Anthropic, Microsoft and OpenAI, but integration depth can vary by service and deployment. Buyers should ask which events are collected, whether controls work at prompt, identity, network or application layers, and how policies map to existing governance systems. General availability marks commercial readiness, not proof of universal coverage. A controlled pilot should measure visibility, policy precision and operator workload before broad enforcement.

Darktrace SECURE AI operating pathThe event moves from disclosure through deployment to measurable outcome.DisclosureDeploymentOutcome
The event moves from disclosure through deployment to measurable outcome.

Facts table

Availability date 22 September 2026
Status Generally available
Named integrations AWS, Anthropic, Microsoft and OpenAI
Core functions Discovery, prompt analysis, policy and response
Deployment focus Enterprise AI services and agents

Frequently asked questions

What is Darktrace SECURE AI?

A security product for discovering, analysing and governing enterprise AI use and agents.

Which platforms are named?

Darktrace names AWS, Anthropic, Microsoft and OpenAI among its integrations.

Does it automatically block AI tools?

It supports policy and response, but organisations should define and test enforcement settings.

Is general availability proof of effectiveness?

No. Buyers still need environment-specific coverage and false-positive testing.

Related Lapaas Voice coverage

Verification sources: Darktrace release SiliconANGLE

Get the day’s top stories in your inbox

One concise email. No spam, unsubscribe anytime.