Breaking
AI & MLDeveloping Story

Exaforce AI Security widens agent watch

Exaforce extends its AI security tool beyond Claude to monitor OpenAI, Gemini and Copilot agents using existing SOC telemetry.

··2 hours ago·4 min read
a man sitting in front of two computer monitors
Photo by Fatemeh Rezvani on Unsplash

Enterprise security teams are struggling to keep tabs on AI agents that operate across devices, clouds, and SaaS apps — often with permissions inherited from humans. Exaforce says it can help them discover and monitor those agents using the security telemetry they already collect, rather than deploying yet another endpoint sensor.

The company this week announced Exaforce AI Security, a product that combines usage data from agentic AI platforms with endpoint, cloud, SaaS, and code data to identify risks, detect suspicious behavior, and respond to threats.

It builds on the Claude Compliance API integration Exaforce announced in June, expanding coverage to other model providers including OpenAI, Gemini, and Microsoft Copilot, as well as OAuth-connected AI apps and endpoint context.

How Exaforce AI Security works

Exaforce said its approach relies on data that security operations centers (SOCs) already gather. Instead of requiring a new gateway, browser extension, or endpoint agent, the product pulls from EDR systems, audit and usage logs from model providers, and activity from productivity suites to build a contextual picture of what AI agents are doing.

That picture can be correlated with existing SOC data to determine what an AI agent is doing, who is operating it, what it can access, and whether its behavior poses a threat.

“Exaforce uses data the SOC already collects to inventory every AI app and agent, connect each one to the person, device and permissions behind it, detect misuse and threats that look legitimate action by action, and contain them through the controls already in place,” said Exaforce co-founder Ariful Huq.

The product is generally available now on the Exaforce Agentic SOC platform, self-operated or through Exaforce MDR.

Not just passive monitoring

Exaforce is not limiting itself to observation. When a threat is detected, the company said it can use existing EDR, identity, and model-provider admin controls to take actions such as revoking a session, deactivating a model-provider API key, isolating a device, or ending an agent’s process.

That response capability distinguishes Exaforce from some competitors that focus primarily on visibility and policy enforcement.

Independent analyst Avivah Litan said the approach “lowers friction, avoids endpoint politics, and matches how most early guardian-agent deployments actually start.” But she added that such “passive, agentless oversight is weaker for the runtime inspection and automatic blocking the market still largely lacks.”

“Something needs to bring the behaviors and actions together across the whole and determine whether what is happening should be happening or not.”

— Michael Sampson, Principal Analyst at Osterman Research

Sampson said Exaforce is looking at the right signals because AI agents work across devices, data sources, repositories, and identities. Existing solutions such as EDR, IAM, SaaS security, or model-provider logging tools alone may not be sufficient, he said.

Competitors take different paths

Other vendors are tackling agentic AI security with markedly different strategies.

Palo Alto Networks launched Prisma AIRS 3.0 in March, focusing on centralized AI agent visibility, policy enforcement, and controls around MCP servers to secure the agentic AI lifecycle. SentinelOne targeted MCP discovery with its Prompt AI Agent Security, also addressing risk assessment, least privilege enforcement, and runtime blocking of malicious interactions such as prompt injection. CrowdStrike introduced Falcon Guardian in September, a new endpoint software agent specifically to detect and respond to AI.

While most of these efforts focus on AI agent discovery, a recent study suggests that is only part of the puzzle.

Discovery alone is not enough

A March 2026 survey by the Cloud Security Alliance found that 68% of organizations could not distinguish human activity from AI-agent activity, necessitating agent discovery. But even the agents they did know about were not necessarily under control: 74% of respondents said their AI agents received more access than necessary, and 52% said agents sometimes inherited access originally intended for humans.

Those findings suggest that the AI-agent security problem is more complicated than simply finding the agents. It remains to be seen whether Exaforce’s bet on correlating existing security telemetry can provide enough control without dedicated agent identities, tightly scoped permissions, and controls enforced at the point where an agent acts.

Litan said most current offerings remain observation and posture management, with very limited in-line blocking or remediation, and platform-native controls typically stop at their own cloud borders. She added that an effective solution would need to “discover sanctioned and unsanctioned agents across clouds and hosting environments, map the human and machine owner, tie activity to the right nonhuman identity when no global agent registry exists, and enforce policy once an agent leaves the platform that created it.”

Exaforce’s Huq said Exaforce AI Security is getting there: It brings AI and agent data into a system that has all relevant data to provide the required context to distinguish between a human identity and the agent that has inherited that identity.

What this means for security teams

The proliferation of AI agents — and their ability to act autonomously across systems — is creating a new class of risk that traditional security tools were not designed to handle. Exaforce’s approach of leveraging existing SOC telemetry could lower the barrier for organizations that want to gain visibility into agent activity without deploying additional agents or gateways.

However, the Cloud Security Alliance data shows that many organizations are already struggling with basic agent discovery and access controls. Until those foundational issues are addressed, even the most sophisticated monitoring may fall short of providing true control over agentic AI.

For security leaders, the key takeaway is that agentic AI security requires more than just visibility. It demands a way to tie agent activity to human owners, enforce least privilege, and respond to threats in real time — capabilities that, according to Litan, the market still largely lacks.

#ai security#agentic ai#exaforce#soc#ai monitoring

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories