Gurucul launches AI risk product; agent-blocking controls remain in preview Gurucul announced AI Risk and Response on September 24, a generally available product that ingests activity from Anthropic Claude, Google Gemini, OpenAI ChatGPT, Azure AI Foundry and Microsoft 365 Copilot to detect risky AI agent behavior, while its separate feature for blocking selected risky AI interactions remains in preview. CEO Saryu Nayyar said the product connects AI-platform activity with identity, access, data, endpoint and cloud signals so security operations and insider-risk teams can investigate which person or agent acted and what it could reach. Gurucul claims its detection library contains hundreds of detections mapped to all 16 MITRE ATLAS tactics and the OWASP Top 10 for LLM applications, though its detection-coverage figures remain company claims. Gurucul launches AI risk product; agent-blocking controls remain in preview CEO Saryu Nayyar is extending Gurucul's behavioral-security approach to AI systems; its prevention controls remain in preview. By RuntimeWire Staff https://runtimewire.com/author/runtimewire-staff ยท Published Primary source: PR Newswire https://www.prnewswire.com/news-releases/gurucul-launches-ai-risk-and-response-to-detect-and-stop-risky-ai-behavior-before-it-escalates-302888502.html Why it matters Gurucul is applying its identity-and-behavior security model to AI agents, where the risk lies in what an agent can access and do. The product is generally available, but its blocking controls are still in preview and its detection-coverage figures remain company claims. Gurucul announced https://www.prnewswire.com/news-releases/gurucul-launches-ai-risk-and-response-to-detect-and-stop-risky-ai-behavior-before-it-escalates-302888502.html?ref=runtimewire AI Risk and Response https://gurucul.com/products/gurucul-ai-risk-and-response/?ref=runtimewire on September 24th, extending CEO Saryu Nayyar's long-running focus on identity and behavior from employees and machines to AI applications and agents. The product is generally available; its separate feature for blocking selected risky AI interactions is still in preview. Nayyar's bet is that security teams need to follow the identity, permissions and systems behind an AI action, rather than treat a prompt as the whole security event. Gurucul says the product connects AI-platform activity with identity, access, data, endpoint and cloud signals, helping security operations and insider-risk teams investigate which person or agent acted, what it could reach and how its behavior changed. That approach reflects the problem Nayyar set out to solve before agentic AI became a product category. She studied Management Information Systems at the University of Southern California https://securitycurrent.com/saryu-nayyar-ceo-gurucul/?ref=runtimewire , worked in application security at Disney and information security and risk at Ernst & Young, then co-founded identity-access company Vaau. Sun Microsystems acquired Vaau in 2008 https://securitycurrent.com/saryu-nayyar-ceo-gurucul/?ref=runtimewire ; Nayyar later worked on security products and strategy at Oracle before co-founding Gurucul with CTO Nilesh Dherange. Gurucul's leadership page https://gurucul.com/leadership/?ref=runtimewire lists her experience across those organizations. In a 2025 interview https://pulse2.com/gurucul-profile-saryu-nayyar-interview/?ref=runtimewire , Nayyar described the connection that led her back to company-building: she saw identity access management converging with big data and machine learning. Gurucul's earlier focus on using behavior to distinguish ordinary activity from suspicious activity now gives it a natural route into AI security. The new product applies that premise to software agents, whose actions may use an employee's identity or permissions while reaching data and systems the employee does not directly touch. A familiar security model, pointed at agents Gurucul says AI Risk and Response ingests activity from Anthropic Claude, Google Gemini, OpenAI ChatGPT, Azure AI Foundry and Microsoft 365 Copilot, alongside proxy, endpoint detection and response, identity, operating-system and cloud telemetry. Gurucul says customers can inventory sanctioned and unsanctioned AI use, agents, models, tools and hosts, then connect that activity to owners, permissions and systems. The product's central sales pitch is context. Standalone AI gateways tend to focus on traffic passing through a particular control point; Gurucul says its offering combines AI-platform data with signals already collected across security operations. Its detection library, according to Gurucul, contains hundreds of detections mapped to all 16 MITRE ATLAS tactics and the OWASP Top 10 for LLM applications. That mapping describes Gurucul's stated coverage; the launch announcement does not provide a benchmark showing detection accuracy, false-positive rates or performance against independent testing. Gurucul says analysts can use an AI Security Overview, Agent Workspace and Graph Explorer to examine activity and relationships, then respond through playbooks and existing controls. Those workflows can be automated or require approval, according to the announcement. Gurucul also offers an AI Risk Assessment and Report using customer data at no cost. Gurucul describes AI Prevention as a preview capability intended to stop selected high-risk interactions at their source. The announcement does not establish the full set of supported platforms or actions, so the general-availability launch should not be read as a claim that every risky agent action can already be blocked. Early customer evidence, with a narrow scope Jay Martin, CISO and VP of Cybersecurity at Blue Mantis, said in Gurucul's launch announcement https://www.prnewswire.com/news-releases/gurucul-launches-ai-risk-and-response-to-detect-and-stop-risky-ai-behavior-before-it-escalates-302888502.html?ref=runtimewire the product can use telemetry already present in customer environments and identify sensitive information shared with unapproved generative AI services. He said the context linking activity to a user and endpoint helps analysts investigate without adding custom engineering or endpoint agents. Those are customer comments carried in Gurucul's release, rather than an independently published evaluation of product performance. Blue Mantis is a relevant reference for Gurucul's go-to-market strategy: the managed security provider says it uses Gurucul's platform for its Mantis Protect managed detection and response service https://www.bluemantis.com/wp-content/uploads/2025/09/Brochure-Blue-Mantis-Protect-managed-cybersecurity.pdf?ref=runtimewire . If AI monitoring can be added to that existing environment, it gives a service provider a way to extend coverage across customer accounts without treating each AI tool as a separate deployment. The launch release does not detail a broader rollout or measured results from Blue Mantis. For Nayyar, the product is a direct extension of the identity-centered security thesis she has pursued across multiple product cycles. The change is the entity being watched: software that can act through credentials, tools and delegated privileges. Gurucul is positioning its existing behavioral analytics and security-data integrations as an advantage in that shift, while putting prevention controls in preview as organizations begin testing where visibility should turn into intervention.