{"slug": "exaforce-extends-its-ai-security-tool-to-monitor-more-than-just-claude", "title": "Exaforce extends its AI security tool to monitor more than just Claude", "summary": "Exaforce expanded its AI Security product beyond its June Claude Compliance API integration to monitor AI agents from OpenAI, Gemini and Microsoft Copilot, along with OAuth-connected AI apps, using security telemetry enterprises already collect rather than a new endpoint sensor. Exaforce co-founder Ariful Huq said the tool inventories every AI app and agent, links each to the person, device and permissions behind it, and contains threats through existing controls, while analyst Avivah Litan cautioned that such passive, agentless oversight is weaker for runtime inspection and automatic blocking. The launch comes as a March 2026 Cloud Security Alliance survey found 68% of organizations could not distinguish human activity from AI-agent activity, 74% said their AI agents received more access than necessary, and 52% said agents sometimes inherited access intended for humans.", "body_md": "Exaforce is offering to help enterprise security teams discover and monitor AI agents using security telemetry they already collect, rather than requiring yet another endpoint sensor.\n\nBy combining usage data from agentic AI platforms with endpoint, cloud, SaaS and code data, Exaforce AI Security can identify risks, detect suspicious behavior, and respond to threats, the company said.\n\n“Exaforce uses data the SOC already collects to inventory every AI app and agent, connect each one to the person, device and permissions behind it, detect misuse and threats that look legitimate action by action, and contain them through the controls already in place,” said Exaforce co-founder Ariful Huq.\n\nThe new product builds on the Claude Compliance API integration Exaforce announced in June.\n\nExaforce AI Security extends that to monitor other model providers, including OpenAI, Gemini and Microsoft Copilot, along with OAuth-connected AI apps and endpoint context. This can be correlated with existing [SOC](https://www.csoonline.com/article/4198016/socs-face-a-human-challenge-as-ai-speeds-alerts-and-threats.html) data to identify what an AI agent is doing, who is operating it, what it can access and whether its behavior poses a threat.\n\nOsterman Research Principal Analyst [Michael Sampson](https://www.linkedin.com/in/michael-sampson-analyst/) said that Exaforce is looking at the right signals, because AI agents work across devices, data sources, repositories, and identities.\n\nExisting solutions such as EDR, IAM, SaaS security or model-provider logging tools alone may not be sufficient, he said: “Something needs to bring the behaviors and actions together across the whole and determine whether what is happening should be happening or not.”\n\n[Exaforce said it needs no new gateway, browser extension, or endpoint agent to assemble all that data, instead gathering it from EDR systems, audit and usage logs from model providers, and activity from productivity suites to build a contextual picture of what AI agents are doing.]\n\nIndependent analyst [Avivah Litan](https://www.linkedin.com/in/avivahlitan/) said this approach “lowers friction, avoids endpoint politics, and matches how most early guardian-agent deployments actually start.” But, she said, such “passive, agentless oversight is weaker for the runtime inspection and automatic blocking the market still largely lacks.”\n\nExaforce is not limiting itself to passive monitoring: It said that when a threat is detected it can use existing EDR, identity and model-provider admin controls to take actions including revoking a session, deactivating a model-provider API key, isolating a device, or ending an agent’s process.\n\n[Its competitors are taking markedly different approaches to the problem of agentic AI security.]\n\nWith the launch of [Prisma AIRS 3.0](https://www.csoonline.com/article/4148974/palo-alto-updates-security-platform-to-discover-ai-agents.html) in March, Palo Alto Networks focused on centralized AI agent visibility, policy enforcement, and controls around MCP servers to secure the agentic AI lifecycle. SentinelOne also targeted MCP discovery with its Prompt AI Agent Security, also tackling risk assessment, least privilege enforcement and runtime blocking of malicious interactions such as prompt injection. And with its September launch of Falcon Guardian, CrowdStrike introduced a new endpoint software agent specifally to detect and respond to AI.\n\nWhile most of these efforts focused on AI agent discovery, a recent study showed that this is only part of the puzzle that enterprises need to solve. A March 2026 survey by the Cloud Security Alliance found 68% of organizations could not distinguish human activity from AI-agent activity, necessitating agent discovery. But even the agents they did know about were not necessarily under control: 74% of respondents said their AI agents received more access than necessary, and 52% said agents sometimes inherited access originally intended for humans.\n\nThat makes the AI-agent security problem more complicated, and it remains to be seen whether Exaforce’s bet on correlating existing security telemetry can provide enough control without dedicated agent identities, tightly scoped permissions and controls enforced at the point where an agent acts.\n\n“Most current offerings remain observation and posture management, with very limited in-line blocking or remediation, and platform-native controls typically stop at their own cloud borders,” Litan said, adding that an effective solution would need to “discover sanctioned and unsanctioned agents across clouds and hosting environments, map the human and machine owner, tie activity to the right nonhuman identity when no global agent registry exists, and enforce policy once an agent leaves the platform that created it.”\n\nExaforce’s Huq said Exaforce AI Security is getting there: It brings AI and agent data into a system that has all relevant data to provide the required context to distinguish between a human identity and the agent that has inherited that identity.\n\nExaforce AI Security is generally available now on the Exaforce Agentic SOC platform, self-operated or through Exaforce MDR.", "url": "https://wpnews.pro/news/exaforce-extends-its-ai-security-tool-to-monitor-more-than-just-claude", "canonical_source": "https://www.csoonline.com/article/4222191/exaforce-extends-its-ai-security-tool-to-monitor-more-than-just-claude.html", "published_at": "2026-09-15 13:00:00+00:00", "updated_at": "2026-09-15 13:16:01.849502+00:00", "lang": "en", "topics": ["ai-safety", "ai-agents", "ai-products", "ai-policy"], "entities": ["Exaforce", "Ariful Huq", "OpenAI", "Gemini", "Microsoft Copilot", "Michael Sampson", "Avivah Litan", "Cloud Security Alliance"], "alternates": {"html": "https://wpnews.pro/news/exaforce-extends-its-ai-security-tool-to-monitor-more-than-just-claude", "markdown": "https://wpnews.pro/news/exaforce-extends-its-ai-security-tool-to-monitor-more-than-just-claude.md", "text": "https://wpnews.pro/news/exaforce-extends-its-ai-security-tool-to-monitor-more-than-just-claude.txt", "jsonld": "https://wpnews.pro/news/exaforce-extends-its-ai-security-tool-to-monitor-more-than-just-claude.jsonld"}}