Exaforce is offering enterprise security teams a way to discover and monitor AI agents using security telemetry they already collect, rather than requiring yet another endpoint sensor, according to the company's announcement. By combining usage data from agentic AI platforms with endpoint, cloud, SaaS and code data, Exaforce AI Security can identify risks, detect suspicious behavior, and respond to threats. The new product extends the Claude Compliance API integration Exaforce announced in June to monitor other model providers, including OpenAI, Gemini and Microsoft Copilot, along with OAuth-connected AI apps and endpoint context.

The security tool assembles data from EDR systems, audit and usage logs from model providers, and activity from productivity suites to build a contextual picture of what AI agents are doing, without requiring a new gateway, browser extension, or endpoint agent. When a threat is detected, the system can use existing EDR, identity and model-provider admin controls to revoke a session, deactivate a model-provider API key, isolate a device, or end an agent's process. The Cloud Security Alliance's March 2026 survey found 68% of organizations could not distinguish human activity from AI-agent activity, and 74% of respondents said their AI agents received more access than necessary. Additionally, 52% said agents sometimes inherited access originally intended for humans.

"Exaforce uses data the SOC already collects to inventory every AI app and agent, connect each one to the person, device and permissions behind it, detect misuse and threats that look legitimate action by action, and contain them through the controls already in place," said Exaforce co-founder Ariful Huq. Osterman Research Principal Analyst Michael Sampson said that Exaforce is looking at the right signals, because AI agents work across devices, data sources, repositories, and identities, and existing solutions such as EDR, IAM, SaaS security or model-provider logging tools alone may not be sufficient. Independent analyst Avivah Litan noted this approach "lowers friction, avoids endpoint politics, and matches how most early guardian-agent deployments actually start," though she cautioned such "passive, agentless oversight is weaker for the runtime inspection and automatic blocking the market still largely lacks."

The challenge of securing agentic AI extends beyond simple discovery, according to industry analysts. Litan said an effective solution would need to discover sanctioned and unsanctioned agents across clouds and hosting environments, map the human and machine owner, tie activity to the right nonhuman identity when no global agent registry exists, and enforce policy once an agent leaves the platform that created it. Most current offerings remain observation and posture management, with very limited in-line blocking or remediation, and platform-native controls typically stop at their own cloud borders. Exaforce's approach differs from competitors including Palo Alto Networks, which focused on centralized AI agent visibility and controls around MCP servers with Prisma AIRS 3.0, and CrowdStrike, which introduced a new endpoint software agent specifically to detect and respond to AI with its September launch of Falcon Guardian. Huq said Exaforce AI Security brings AI and agent data into a system that has all relevant data to provide the required context to distinguish between a human identity and the agent that has inherited that identity, and the product is now generally available on the Exaforce Agentic SOC platform, self-operated or through Exaforce MDR. The question isn't whether enterprises will adopt specialized security for AI agents, but which architectural philosophy will prove workable when agents eventually operate at a scale that outpaces human oversight. Organizations betting on agentless correlation are wagering that visibility matters more than enforcement speed, a trade-off that could define the security posture of autonomous systems for years.