AI security operations center displaying agent permissions, risk rankings, alerts, integrations, and global activity.
Darktrace made SECURE AI generally available on September 22, 2026, giving enterprise security teams a product for monitoring employee use of AI services and the behavior of AI agents, with integrations spanning Microsoft, OpenAI, Anthropic and Amazon Web Services and tools for investigating unsanctioned activity. Darktrace’s announcement confirms the availability reported by SiliconANGLE. For Microsoft administrators, the important addition is visibility across Copilot interactions and Copilot Studio agents, connected to existing security workflows. The purchasing decision turns on how much of an organization’s actual AI activity those integrations can observe—and which findings administrators can act on.

Darktrace SECURE AI moves from announcement to general availability​

SECURE AI applies Darktrace’s behavioral detection approach to enterprise AI use. The company describes that approach as learning the activity patterns of each customer’s environment and identifying deviations from expected behavior. Its general-availability announcement names integrations with AWS, Anthropic, Microsoft and OpenAI for prompt analysis and detection of shadow AI: services being used outside the organization’s approved arrangements.

According to SiliconANGLE, Darktrace first announced SECURE AI in February. It is now available to new and existing customers as a standalone product or within the Darktrace Behavioral Defense Platform, with purchasing routes through AWS Marketplace and Microsoft Marketplace. Darktrace’s Microsoft Marketplace listing also carries a “Get it now” option and describes the product’s Microsoft integrations.

The availability change gives buyers a product to evaluate against their own environments. The public descriptions establish its intended coverage and capabilities, but provide no independent measurements of detection accuracy, false-positive rates or investigation time saved. Those remain evaluation questions, particularly for a product whose central promise is recognizing activity that falls outside normal business behavior.

Darktrace’s positioning is broader than an inventory of approved AI applications. Its Marketplace description connects employee prompts, agent development, permissions and production activity. The practical proposition is that security teams should be able to follow an AI-related risk across those stages, instead of treating an agent’s configuration and its subsequent behavior as unrelated findings.

Copilot and Copilot Studio coverage addresses different administrative jobs​

Darktrace’s Microsoft Marketplace listing describes prompt and session visibility across Microsoft Copilot, alongside visibility into agents created through Microsoft Copilot Studio. These capabilities address two distinct administrative tasks: understanding how people use an assistant, and understanding what an organization’s agents can access and do.

For employee interactions, SiliconANGLE reports that SECURE AI scans sessions in ChatGPT Enterprise, Claude, Microsoft Copilot and Amazon Bedrock in real time for jailbreak attempts, sensitive-data exposure and signs of indirect prompt injection. Sessions receive risk rankings to help analysts prioritize investigation. Darktrace’s Marketplace description supports the broader capability to analyze prompts, sessions and responses for prompt-based attacks and data exposure.

The distinction between detecting a service and inspecting its interactions is important when evaluating coverage. Discovery can establish that an AI service is in use; prompt and session analysis promises more detailed evidence about the activity taking place. A buyer should establish which of those capabilities applies to each service in its deployment. The Copilot name in a product description does not establish identical inspection across every Copilot workload, subscription or tenant configuration.

Copilot Studio introduces a different set of objects to examine. Darktrace says SECURE AI maps AI assets, permissions and connections, identifies excessive permissions and misconfigurations during development, and connects that information with behavior after deployment. SiliconANGLE also reports that the product maps agents to the human users behind them and records what each agent is permitted to reach.

That connection offers a useful way to organize an investigation. An alert about unusual agent behavior becomes more actionable when the analyst can also identify the responsible user, the agent’s connections and its permitted access. It links an observed event to the person or team able to review the agent’s design. The Marketplace listing describes this as coverage from development to runtime, including low-code development and cloud-hosted AI architectures.

Darktrace’s customer examples show three separate governance gaps​

The demand argument comes from Darktrace’s own customer telemetry. SiliconANGLE reports that, across approximately 8,200 deployments, more than 80% of monitored customer accounts used generative-AI services in August 2026. The average organization used five AI providers that month. These figures describe Darktrace’s monitored customer population, not a representative measurement of every enterprise.

Darktrace supplied three early-customer examples that illustrate different administrative problems. At one organization, a single AI assistant had been approved, but most employees were using unauthorized services. At another, nearly 90 agents had been created in a low-code environment without an approval process. At a third, contractors’ unmanaged use of multiple AI platforms triggered an immediate legal review. SiliconANGLE reports all three as company-provided examples.

Their value is in separating problems that can otherwise disappear under the broad label of “AI risk”:

  • Unauthorized assistant use creates a gap between the approved application list and employees’ actual activity.
  • Agent creation without an approval process leaves administrators needing to establish ownership, permissions and connections.
  • Contractor use introduces a governance issue that may require legal review as well as a technical investigation.

These examples support an evaluation focused on concrete administrative outcomes. Discovering an unknown service, identifying an agent’s owner and producing evidence for a policy review are distinct jobs. An organization may need one more urgently than the others.

The low-code example also has a firm attribution boundary: SiliconANGLE does not identify the development platform involved. It should not be read as a reported Copilot Studio incident simply because SECURE AI supports Copilot Studio. The relevant connection is the administrative task—finding agents created outside an approval process—not an allegation about a particular Microsoft deployment.

Microsoft integrations connect visibility to existing security operations​

Darktrace’s Microsoft Marketplace listing positions SECURE AI as complementary to Microsoft’s identity, governance, compliance and agent-management capabilities. It says behavioral risk signals can appear within Microsoft Agent 365 alongside Microsoft-native signals. For security teams, that potentially makes a finding available in an existing agent-management workflow instead of leaving it confined to a separate monitoring console.

The same listing says Microsoft Sentinel can ingest Darktrace AI Analyst incidents and model-breach alerts. For Azure workloads, it describes broader Darktrace integrations covering infrastructure, platform services and control-plane activity. Those connections matter because an AI investigation may require context beyond the prompt or agent that first attracted attention.

The documented relationship is an additional behavioral layer around existing controls. Microsoft’s identity and governance systems establish permissions and operating rules; Darktrace says its monitoring evaluates activity against the organization’s expected behavior. The listing does not establish that every underlying Microsoft control is replaced or that every alert automatically results in enforcement.

SiliconANGLE reports a more specific enforcement path through secure access service edge integrations, including Microsoft Entra Global Secure Access. It says administrators can block unsanctioned services or quarantine a device. This is a reported integration capability, not a documented universal workflow: the available detail does not specify the configuration, permissions or connected components required for each action.

That boundary belongs in deployment planning. Service blocking and device quarantine have different operational consequences, and buyers need to establish which system executes each action and who authorizes it. A finding delivered to an analyst, a recommended response and an executed containment action are separate outcomes; the product evaluation should identify which is available for each supported integration.

SiliconANGLE also reports that companies can upload AI policies in free-form text and have the software check them against regulatory and compliance frameworks. Darktrace’s Marketplace listing separately describes mapping organizational policies to observed prompt and user activity. These functions can support policy review, but the described checks should not be treated as a compliance certification.

OpenAI Daybreak is partnership context, not a blanket shipping commitment​

Darktrace is a member of OpenAI’s Daybreak Defense Network. OpenAI’s partner page describes the program as combining its cyber capabilities with partners’ products, telemetry and workflows, with safeguards and human review built into governed defensive uses.

For Darktrace specifically, OpenAI describes pairing behavioral understanding with its models to add business context to incidents and help defenders prioritize AI-system risk. SiliconANGLE reports that Darktrace is developing capabilities intended to show which people and systems an AI-related incident has touched.

That work is relevant to SECURE AI’s investigation ambitions, but it has a different availability status from the product launch. SECURE AI is generally available; the partnership description is not a feature-by-feature commitment that every proposed Daybreak capability ships in it today. Buyers should evaluate the capabilities included in their offer separately from ongoing partnership development.

The distinction keeps the purchasing question concrete. Prompt visibility, agent mapping, Microsoft integrations and supported response actions can be assessed as product capabilities. Future investigation enhancements should enter a buying decision only with an explicit delivery and entitlement commitment.

Evaluate SECURE AI against the AI activity you actually need to govern​

Organizations with multiple AI providers or growing Copilot Studio deployments have a concrete reason to evaluate SECURE AI: they may need a consolidated view of use, ownership, permissions and behavior. A narrowly scoped deployment with established visibility has a different decision to make—whether the additional behavioral findings justify another security product and its operating requirements.

The material implementation gap is how inspection is enabled for the organization’s particular workloads and what happens to the information collected. The available descriptions do not specify the required collection method for each integration or the handling and retention of prompt and response content. Those details affect both achievable coverage and the privacy review necessary before deployment.

A useful procurement review should therefore turn the announced capabilities into explicit commitments:

  • Establish which Copilot workloads, Copilot Studio environments and third-party AI services receive discovery, prompt inspection, agent mapping or runtime monitoring.
  • Confirm the integration prerequisites and data-handling terms, including what prompt or response content is processed, where it is processed and how long it is retained.
  • Identify which findings reach Microsoft Sentinel or Microsoft Agent 365 and what evidence an analyst receives with them.
  • Separate alerting from enforcement, documenting which connected system can block a service or quarantine a device and which approvals those actions require.
  • Obtain pricing and licensing terms for the required scope, and keep generally available features separate from Daybreak-related development commitments.

Darktrace’s launch gives enterprise teams a specific cross-provider monitoring option to assess alongside their Microsoft controls. Its strongest practical promise is the connection between AI use, agent ownership, permitted access and observed behavior. For administrators, the next decision is to establish that connection in their own supported workloads—and confirm that the resulting evidence reaches the people and controls able to act on it.