
Gurucul Tracks AI Agents Across Identity and Data—Prevention Is Still Preview

In a September 24, 2026, announcement datelined Los Angeles, Gurucul made AI Risk and Response generally available for SOC and insider-risk teams. The released product connects AI-agent activity to identities, access and data for detection, investigation and analyst-directed response. Prevention intended to stop selected interactions at the point of use remains in preview.
A WindowsForum review draws the same line between the general release and preview blocking. It also notes that public accounts of the product’s capabilities largely rely on Gurucul’s descriptions, without an independent test of detection quality. General availability establishes the status of the investigation workflow; it does not establish how completely that workflow will cover any particular organization’s agents or data.
What Gurucul released
The Gurucul product page lists AI activity inventory, detection, entity risk scoring, Link Chain Analysis, historical search, retained evidence and analyst-approved response as generally available functions. Its availability statement places prevention outside that release. The listed functions give analysts a way to move from an observed AI action to the identities and resources involved, then examine the evidence behind a finding.
The inventory covers supported applications, agents, models, tools, projects and identities where connected records expose them. An agent is treated as an entity with its own behavior and risk, while remaining linked to an owner, associated accounts, permissions and accessible resources. That relationship is central to the title’s tracking claim: an agent event becomes more useful when an investigator can determine which identity authorized it and which data or systems it could reach.
Known-pattern detections address defined threats and policy conditions; behavioral analysis looks for changes against an entity’s history and relevant peers. Related signals contribute to an active risk score and a case that retains the underlying activity, timestamps and relationships. Link Chain Analysis joins AI activity with user and entity behavior analytics and insider-risk context. These functions can organize evidence for an analyst, but a score cannot resolve an identity or reconstruct an event that the connected sources did not record.
Which telemetry supports the investigation
Gurucul describes two sources of visibility. Existing proxy, secure web gateway, CASB, endpoint, identity, cloud, DLP, OAuth, SSO, SaaS and operating-system telemetry can reveal use of approved or unsanctioned AI services and connect it to broader security activity. Direct AI-platform integrations can add prompt, audit, inventory and agent details where provider APIs, customer licensing and permissions make those details available. The general release does not require a new Gurucul endpoint or browser agent for detection, investigation or response.
The distinction affects what a case can establish. A proxy record may show that an account reached an AI service or made an unusual upload, while leaving the prompt, agent tool call or data sensitivity unknown. An AI-platform audit event may describe an agent action without supplying the employee, endpoint or service identity that granted access. Correlation across those records is the product’s proposition, but the answer depends on fields available in the deployment and on whether identities can be matched reliably.
The advertised use cases include shadow AI, sensitive-data exposure, agents with excessive access, behavior that shifts toward new tools or destinations, and possible prompt injection or agent hijacking. Each needs different evidence: discovering an unapproved service is a narrower finding than proving what an agent sent to it or why its behavior changed. Framework mappings describe the scope Gurucul intends its detections to address; they are not measured detection rates or proof that every mapped condition is observable with a customer’s connected data.
Response is available; prevention is preview
In the general release, analysts can assess a case and use supported, configured controls to respond. Depending on integrations and permissions, a response may restrict an identity, isolate an endpoint, block a destination or invoke an available provider action. Recommendations and playbooks can help route the case, while consequential actions remain subject to human approval and the customer’s policies. A listed response type therefore does not mean that its connector, API permission or approval route is already configured in a customer environment.
Preview prevention addresses a different point in the sequence: selected high-risk interactions before they execute. Gurucul describes supported browser and coding-agent activity and a browser plug-in that can apply policy to prompts, pasted content, readable file uploads and AI destinations. That is distinct from detecting an event and approving containment afterward. The public material does not establish universal coverage across browsers, applications or agents, or give a date for prevention to become generally available.
What remains to be demonstrated
The release defines available functions, but their reach depends on the environment connected to them. For SOC and insider-risk teams, the evidence needed to assess the released functions falls into five concrete areas:
- Identity correlation: Whether a case can trace an agent action to its owner, initiating account, service identity, permissions and affected data while preserving the sequence of events.
- Source coverage: Which fields arrive through existing enterprise telemetry and which prompt, audit, inventory or agent details require a direct AI-platform integration.
- Detection evidence: Whether analysts can inspect the events and relationships behind a changing score, rather than relying only on its summary.
- Response approval: Which identity, endpoint, network or provider actions are configured, who may approve them and where the decision is recorded.
- Retention and permissions: How long historical events and case evidence remain available, who can view sensitive context, and which licensing terms and API scopes permit each integration.
Those details determine how much of Gurucul’s released detection and investigation capability a particular deployment can use. Point-of-use blocking has a separate status: prevention is still in preview, and its supported environments and eventual general-availability terms remain open.
Also read:
Related articles


Plugin4Shell Bypasses Hash Pinning—Audit Every Agent Plugin Path

Deleting Google My Activity Leaves Browser History—Clear Both Records

Two Check Point Flaws Are Under Attack—One Patch Misses the Zero-Day

Palo Alto’s AI Defense Uses Multiple Models—None Found More Than 40%

Slackforce Makes Conversations Executable—Define the Agent Boundary First
Subscribe to our newsletter
Get the latest Web3, AI, and crypto news delivered straight to your inbox.