Employees across large companies are quietly spinning up AI agents that no security team ever approved, and in most organizations nobody can say how many exist or what they are allowed to touch. Drata is going after that blind spot. The compliance-automation company has added AI Agent Governance to its Trust Management Platform, a capability built to find those agents, put an owner and a permission set against each one, and enforce policy on what they do.
The discovery piece is the part that matters most, because inventory is the problem. Drata says inline sensors surface every agent an employee has created, including the shadow agents nobody knew about, and build a full inventory in minutes that maps each agent to its owner, identity, permissions, and scope. From there, security teams can authorize access and set an individual policy per agent, and Drata evaluates every action against that policy in real time, blocking violations inline before they execute rather than flagging them after the fact. The system produces a tamper-evident record meant to serve as a single evidence trail for boards, auditors, customers, and regulators, and Drata ties it to frameworks including ISO 42001, SOC 2, and GDPR.
Drata frames the launch around a governance gap it says is widening fast. The company cites a 30 percent rise in AI governance security questions over nine months and claims 89 percent of companies leave those questions unanswered, with only 11 percent of vendors confident in their responses. Chief executive and co-founder Adam Markowitz said extending the platform to govern the agents themselves is "the next required step." Nils Puhlmann, co-founder of the Cloud Security Alliance and a former chief security officer at Twilio, Navan, and Zynga, put the current state more bluntly, saying that answering the questions boards now ask about agents is impossible with today's technology. The vendor numbers are self-interested, but the underlying tension is real: agents act on their own, and the existing compliance toolchain was built to audit people and static systems.
The capability is in early access, aimed first at financial services, healthcare, and software, the sectors where agent adoption and audit pressure are colliding hardest, and Drata says more than 8,500 organizations already use its platform. The bet is that governance can be automated at the same speed agents are being created. Whether discovery keeps pace is the thing to watch, because an inventory that runs in minutes still only counts the agents its sensors can see, and the shadow ones are shadow precisely because they were built to sit outside the sanctioned path.













