SecurityBrief US - Technology news for CISOs & cybersecurity decision-makers
United States
Gurucul launches AI risk & response for enterprises

Gurucul launches AI risk & response for enterprises

Tue, 6th Oct 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Gurucul has launched AI Risk and Response, a security product designed to detect and respond to risky artificial intelligence activity. The product is generally available, while a prevention feature is in preview.

The Los Angeles-based cybersecurity company said the offering is intended for Security Operations Centre and insider risk teams that need to monitor how AI systems, agents and users interact with data, identities and enterprise systems.

The launch comes as companies face growing scrutiny over how generative AI tools and autonomous agents are used inside organisations. Recent security concerns have centred on AI systems that do more than generate text, including software that can access systems, handle data and carry out tasks with limited human involvement.

The product brings together telemetry from AI platforms and existing security tools so analysts can link AI activity to a human or non-human identity, associated permissions, endpoint behaviour and cloud or operating system events. That allows teams to investigate whether AI use is sanctioned, what resources an agent can access and whether activity patterns have changed over time.

The system includes hundreds of detections mapped to all 16 MITRE ATLAS tactics and the OWASP Top 10 for large language model applications. It is also intended to help identify shadow AI use, sensitive data exposure, excessive access, risky autonomous agents and AI supply-chain risks.

Customer view

Blue Mantis, a managed security services provider, is among the companies commenting on the launch. Gurucul presented the product as a way for service providers to use existing customer telemetry, rather than deploy additional endpoint software, to investigate AI-related risks.

"Our customers need to understand not only where AI is being used, but when that use creates risk to sensitive information and critical systems. Gurucul AI Risk and Response can be enabled quickly using telemetry already available in the customer environment, providing rapid visibility without custom engineering or additional endpoint agents. The solution identifies sensitive, non-public information being shared with unapproved generative AI services and correlates that activity with the user and endpoint behaviour our analysts need to investigate. This reduces implementation time, operational overhead and cost while enabling our Security Operations team to respond more quickly with minimal disruption to customer environments. For an MSSP like Blue Mantis, the difference between seeing AI activity and having the context and evidence behind it is the difference between forwarding another alert and helping a customer understand and address real risk," said Jay Martin, Chief Information Security Officer and Vice President of Cybersecurity at Blue Mantis.

The platform can ingest activity from services including Anthropic Claude AI, Gemini Enterprise Agent Platform, Google Gemini, OpenAI ChatGPT, Azure AI Foundry Inventory and Microsoft 365 Copilot. Those feeds can be combined with proxy, endpoint detection and response, identity, cloud and operating system data already collected by security teams.

Gurucul is seeking to address a shift in enterprise security as AI tools move from employee assistants to systems that can perform tasks directly. In that environment, the challenge for defenders is not only to review prompts or chatbot sessions, but also to understand what an AI system did, what it accessed and whether it behaved differently from previous patterns.

Prevention layer

Alongside the generally available detection and response product, AI Prevention is available in preview. The feature is intended to stop selected high-risk AI interactions at the point of use, including through controls applied via a browser plug-in covering prompts, pasted content, file uploads and AI destinations.

Response actions can be handled through existing identity, endpoint, network and supported AI-platform controls. Remediation can also be routed through established IT service management workflows rather than requiring a separate process for AI incidents.

Security suppliers have increasingly sought to distinguish between narrow AI gateways and broader monitoring tools that operate across enterprise systems. Gurucul said its approach provides a wider behavioural view by connecting AI-platform events with established enterprise telemetry and then applying risk scoring based on the evidence collected.

That strategy builds on Gurucul's existing presence in security information and event management, user and entity behaviour analytics and insider risk management. The latest product extends those systems into AI-related investigations by treating users and autonomous agents as persistent entities that can be monitored for changing behaviour.

"As AI moves from generating answers to taking action, risk no longer lives within a single prompt or application. It develops across identities, permissions, data, tools and actions over time. Insider and SecOps teams need to connect those signals to understand what changed, why it matters and where the risk is headed. Gurucul AI Risk and Response applies behavioral AI, entity intelligence and evidence-backed risk scoring to put AI activity in the context of the broader security environment. This gives analysts a clear, actionable view of developing threats and the control to address them early through the workflows and processes they already use. With runtime prevention now in preview, we are taking the next step: stopping high-risk AI behavior at machine speed at the source," said Saryu Nayyar, Chief Executive Officer of Gurucul.