In the last six months, Fortune 500 companies have witnessed a staggering 480% increase in non-human identities, creating a blind spot for enterprises regarding these new entities.
As soon as an AI agent is activated, it gains enhanced human privileges and operates at unprecedented speeds, accessing data in moments that would otherwise take a human years to reach.
This emerging layer of autonomous workers is quickly becoming the largest and most rapidly expanding area of concern for enterprise security. Until now, there has been no infrastructure designed to manage and regulate what these agents can view and do, which puts sensitive data, critical systems, and compliance obligations at peril.
Black Hat 2026
In an announcement at Black Hat 2026, Cyera unveiled its latest solution, Agent Guardian, aimed at ensuring AI agents are as visible and accountable as human employees. Agent Guardian does more than just monitor exchanges; it also tracks every tool engagement, database inquiry, and logical process.
Additionally, Cyera launched Cyera Endpoint, designed to implement AI safety measures directly on employee devices, especially when these devices are outside corporate network boundaries, where crucial tasks are often completed. Together, these innovations form Cyera's trust framework for managing AI agents in the enterprise environment, defining the extent of agents' reach and their permissible actions.
Enhancing AI Integration with Secure Solutions
Agent Guardian and Cyera Endpoint provide oversight and control for secure AI adoptionAccording to Tamar Bar-Ilan, cofounder and CTO of Cyera, "AI agents have become a new class of enterprise identity. But the fundamental shift isn't that organizations have more identities; it's that the gap between permission and execution has disappeared."
The introduction of Agent Guardian and Cyera Endpoint equips organizations with the necessary oversight and control to manage this new landscape, allowing them to adopt AI technologies rapidly without compromising sensitive information.
Comprehensive Security for AI Deployments
Agent Guardian addresses the crucial divide between rapid AI integration and operational governance, organizing security around a continuous lifecycle. This involves:
- Discover: Keeping an inventory of all AI applications and agents across various platforms and environments, identifying shadow agents, and understanding their data access.
- Govern: Establishing permissible actions for each agent, identifying deviations, and conducting continuous audits for excessive permissions and risky setups.
- Protect: Operating in real-time within execution flows to intercept harmful tool use, block unauthorized data sharing, and quarantine compromised agents before they act.
- Validate: Testing defenses against prompt injection and privilege abuse, and preparing compliance reports for standards like the EU AI Act.
Securing AI Interactions Across Platforms
Agent Guardian enforces policies at crucial points where AI interacts with enterprise data, such as through platform APIs and remote device scans. This capability is crucial for local agents, where activities take place without network oversight.
To supplement these measures, Cyera has introduced Cyera Endpoint, which provides real-time visibility into both authorized and unauthorized agent activities on local devices, safeguards sensitive files from unauthorized access, and blocks data flows to unauthorized AI accounts.
Universal Support for Diverse AI Platforms
Cyera’s solutions span the entire agent ecosystem, covering everything from local coding tools to large-scale enterprise systems such as Microsoft Copilot Studio and Salesforce Agentforce. As noted by Mayank Upadhyay, Chief Security & Trust Officer at Snowflake, "AI is only as trustworthy as the data behind it." Collaborating with Cyera allows Snowflake clients to visualize and understand AI agents' data interactions, fostering a confident adoption of agent-based AI solutions.
To experience Agent Guardian and Cyera Endpoint firsthand, visit Cyera at Black Hat 2026, Booth #4152.
Non-human identities in Fortune 500 companies grew 480% in the last six months alone, and enterprises have no visibility into most of them.
The moment an AI agent is deployed, it inherits elevated human permissions and moves at machine speed, touching data in seconds that would take a human a career to reach.
This invisible layer of the new autonomous workforce is rapidly becoming the fastest-growing attack surface in enterprise security. Until now, there's been no infrastructure purpose-built to govern what agents can see and do, leaving sensitive data, critical systems, and regulatory obligations increasingly at risk.
Black Hat 2026
Today at Black Hat 2026, Cyera launched Agent Guardian, built to make every AI agent as visible and accountable as a human employee. Agent Guardian goes beyond the prompt and the response, monitoring every tool call, database query, and reasoning step in between.
Alongside Agent Guardian, Cyera also introduced Cyera Endpoint, bringing AI guardrails directly to employee devices for local agents that operate outside corporate network controls, where they are increasingly doing their most sensitive work. Together, they extend the trust layer Cyera is building for the agentic enterprise, answering what an agent can reach and what it should be allowed to do with it.
Accelerate AI adoption
“AI agents have become a new class of enterprise identity. But the fundamental shift isn't that organizations have more identities; it's that the gap between permission and execution has disappeared," said Tamar Bar-Ilan, cofounder and CTO of Cyera. “Agent Guardian and Cyera Endpoint give organizations the visibility and runtime control to govern this new reality, enabling them to accelerate AI adoption without putting sensitive data at risk.”
Built to secure the agentic enterprise, from the device to the cloud
Agent Guardian fills the critical gap between rapid agentic adoption and operational control, organizing the agent security journey around a continuous, systematic operational lifecycle:
- Discover—Account for every agent: Automatically inventories every AI application and agent running across endpoints, SaaS platforms, and cloud environments, including shadow agents and MCP servers security teams didn't know existed, and maps exactly what data each one can reach.
- Govern—Set the rules: Defines what each agent is allowed to do, flags when it drifts from its intended purpose, and continuously audits for overprivileged access and risky configurations.
- Protect—Stop threats in real time: Operates inline within the execution path and uses AI-driven policy and content evaluations to intercept dangerous tool calls, block unauthorized data transfers, and quarantine compromised agents before execution.
- Validate—Prove the guardrails hold: Continuously red-teams defenses against prompt injection, jailbreaking, and privilege escalation, and generates audit-ready compliance reports to satisfy frameworks like the EU AI Act.
Whether enterprises are deploying agents built on AWS Bedrock, or managing developer agents running on employee devices or rolling out Microsoft 365 Copilot, Agent Guardian secures the entire agentic surface from one platform, giving security teams the visibility to see every agent, the precision to govern what it touches, and the runtime control to stop it before it causes harm.
AI Guardrails: where agents work
Agent Guardian enforces policy wherever AI interacts with enterprise data, including through platform APIs, AI gateways, browser extension, agent framework hooks, and remote scans of employee devices. That last control point has become increasingly important as developers adopt local agents such as Claude Code and Cursor, where activity never crosses a network boundary and traditional security tools have little or no visibility.
To add runtime protection to where local activity happens, Cyera today also introduced Cyera Endpoint, a lightweight endpoint control that brings Agent Guardian's policies directly to the device. It provides live visibility into sanctioned and shadow local agent activity, classifies and protects sensitive files before they're accessed or leave the machine, and blocks data from reaching unauthorized personal AI accounts, enabling consistent governance across cloud, SaaS, and endpoint environments.
Built for every agent, across every platform
Cyera covers the full agentic surface, from desktop agents like Claude Code and Cursor to enterprise platforms like Microsoft Copilot Studio, Salesforce Agentforce, and Snowflake Cortex AI, to custom cloud deployments on AWS Bedrock, Microsoft Foundry, and Vertex AI.
“AI is only as trustworthy as the data behind it,” added Mayank Upadhyay, Chief Security & Trust Officer at Snowflake. “Working with Cyera lets Snowflake customers see every Cortex AI agent in use and understand exactly what data it can reach, so they can adopt agentic AI with the same confidence they place in their data.”
To see Agent Guardian and Cyera Endpoint in action, visit Cyera at Black Hat 2026, Booth #4152.