Cybersecurity company Gurucul has launched AI Risk and Response, a new security offering designed to help organisations detect, investigate and respond to risks arising from the growing use of artificial intelligence tools and autonomous agents across enterprise environments.
The solution became generally available on September 24 and is aimed at Security Operations Centre and Insider Risk teams. Gurucul said it brings AI activity together with identity, access, endpoint, cloud and other security data to help organisations understand who or what is behind potentially risky behaviour.
As enterprises deploy generative AI tools and autonomous agents, security teams are increasingly dealing with activity that extends beyond employee prompts. AI agents can interact with systems, access information and perform tasks using permissions provided by organisations, creating new challenges around visibility, identity and data access.
Gurucul AI Risk and Response is designed to identify sanctioned and unsanctioned AI usage, commonly referred to as Shadow AI. It can also create an inventory of AI agents, models, tools and hosts while connecting activity with owners, permissions and the resources those systems can access.
The platform ingests information from AI services including OpenAI ChatGPT, Anthropic Claude, Google Gemini, Gemini Enterprise Agent Platform, Microsoft 365 Copilot and Azure AI Foundry Inventory. Gurucul said this information can be combined with existing proxy, endpoint detection and response, identity, operating system and cloud telemetry.
According to the company, the platform includes hundreds of detections across five AI security categories, with coverage mapped to all 16 MITRE ATLAS tactics and the OWASP Top 10 for Large Language Model Applications. It uses behavioural AI alongside deterministic detection methods to identify risks including sensitive data exposure, excessive access, risky autonomous agents and AI supply-chain threats.
Gurucul has also introduced AI Prevention in preview. The capability is intended to stop selected high-risk AI interactions at the point of use. A lightweight browser plug-in can provide controls around prompts, pasted content, readable file uploads and AI destinations, while organisations can determine enforcement policies and exceptions.
The company said response workflows can connect with existing identity, endpoint, network and IT service management systems, allowing security teams to investigate AI-related incidents through established processes rather than creating separate workflows.
Gurucul is positioning the offering as part of its broader security analytics portfolio, which includes Security Information and Event Management, User and Entity Behaviour Analytics and insider risk management.
The launch reflects a wider shift in enterprise cybersecurity as AI evolves from tools that primarily generate content to systems capable of independently performing actions, increasing the need for organisations to monitor AI behaviour alongside traditional users and machines.
Disclaimer: This article may include information derived from interviews, press releases, public statements, research, company communications and other publicly available or third-party sources. Such material may be summarised, paraphrased or contextualised for journalistic and editorial purposes. All rights in third-party content remain with their respective owners.