Gurucul AI Risk and Response goes GA, but AI Prevention stays in preview
The status line is the first thing to get right. Gurucul's release says AI Risk and Response is generally available beginning September 24, with runtime prevention available in Preview. Detection, investigation and response are the parts that shipped. The inline blocking function, which Gurucul calls AI Prevention or runtime prevention, adds controls designed to stop selected high-risk AI interactions at the point of use. It is not GA.
The GA follows a preview earlier this summer. On August 4, 2026, around Black Hat USA, Gurucul previewed "Security for AI" capabilities that run on its Unified Entity Intelligence model. The company describes that model as a continuously updated risk model for the identities, behavior, relationships, privileges and activity of every human, machine, application, service account, data asset and AI entity. Seven weeks later, the detection-and-response half has become a product. Prevention has not made the same move.
The launch includes an offer: Gurucul says it is offering organizations an AI Risk Assessment and Report on real data, at no cost. The announcement doesn't say who qualifies, how long the assessment runs or what data it needs. Gurucul hasn't published pricing or licensing for the product either, and the free assessment shouldn't be read as a sign of what the product costs.
How Gurucul links Microsoft 365 Copilot and ChatGPT activity to identity telemetry
The design choice that sets this product apart is correlation. Most AI-security tools sit in the traffic path as a gateway and log prompts and responses. Gurucul contrasts itself with "standalone AI gateways and other point solutions." It says it combines AI-platform data with the proxy, endpoint detection and response (EDR), identity, operating-system and cloud telemetry a SOC already collects. The goal is to answer, for any AI event, who or what started it, which identity and privileges it used, what data and systems it reached, and how its behavior changed over time.
Gurucul names the platforms its data pipelines ingest and normalize: Anthropic Claude AI, Gemini Enterprise Agent Platform, Google Gemini, OpenAI ChatGPT, Azure AI Foundry Inventory and Microsoft 365 Copilot. That list is why Windows and Microsoft shops should pay attention. Copilot and Azure AI Foundry are named as first-class sources alongside the third-party chatbots employees tend to adopt on their own.
Visibility comes in two levels, and they are easy to confuse. The company says teams can start with data they already collect, then add direct AI-platform integrations for "deeper prompt, agent and audit context." Existing proxy and EDR logs can show that someone used an AI service, which is enough to surface shadow AI (unapproved AI tools used outside IT's knowledge). Prompt contents and agent actions need the direct platform connectors. Gurucul hasn't specified which integration gives which level of detail on each platform.
From that data, Gurucul says it builds an inventory of agents, models, tools and hosts. It links each one to an owner, its permissions and the resources it can reach. The company says it treats users and autonomous agents as persistent entities, drawing on more than a decade of behavioral AI. The August preview release explained the idea more concretely: an AI agent is modeled as an entity with its own learned baseline, its own privileges and activities. In theory, an agent that drifts beyond its mandate gets caught by the same behavioral analytics that would flag a compromised employee or an over-privileged service account.
Readers who know UEBA (user and entity behavior analytics) will recognize the approach. Gurucul says the new product builds on its existing SIEM, UEBA and AI insider risk management (AI-IRM) products. The AI-IRM line launched in September 2025 and combines advanced User and Entity Behavior Analytics (UEBA), identity and access analytics (IdA), intelligent data loss prevention (DLP), and native automated response (SOAR). AI Risk and Response points that same machinery at a new kind of entity.
Hundreds of detections mapped to 16 MITRE ATLAS tactics, with the details unpublished
Gurucul's headline number is hundreds of detections spanning all 16 MITRE ATLAS tactics and the OWASP Top 10. MITRE ATLAS is MITRE's knowledge base of adversary tactics against AI systems, modeled on ATT&CK. The OWASP Top 10 for LLM Applications lists the most common risk categories for applications built on large language models. Mapping detections to both gives security teams a shared vocabulary for gap analysis.
The company says the detections fall into five "AI security families." They combine behavioral AI with deterministic rule logic to flag:
- Shadow AI use, meaning unsanctioned AI services running alongside approved ones.
- Sensitive data exposure, such as non-public information sent to unapproved generative AI services.
- Risky autonomous agents and agents holding excessive access.
- AI supply-chain risk.
- Behavior changes that fixed rules might miss.
A Unified Entity Intelligence engine then rolls those findings into what Gurucul calls an "active risk score," backed by the evidence that produced it.
The announcement doesn't name the five families, list the detections, or show how any detection maps to a specific ATLAS tactic. Tactic-level mapping shows breadth of intent, and it can hide thin coverage: a single detection can technically "cover" a tactic. Buyers should ask for the detection catalogue and the per-tactic mapping before treating "all 16 tactics" as a coverage guarantee. No independent evaluation of detection quality or false-positive rates has been published.
The investigation side is more concrete. Gurucul names three consoles. AI Security Overview is the summary view. Agent Workspace focuses on agent entities. Graph Explorer shows the relationships between identities, systems, tools and data. Analysts can compare an entity's activity with its own history and with its peers, and see how separate events add up to a developing risk. For teams already running Gurucul's SIEM, this is an extension of an existing workflow. For everyone else it means a platform adoption decision, not a bolt-on.
Automated playbooks, ITSM routing and a browser plug-in divide response from prevention
Response in the GA product goes through controls an organization already has. Gurucul describes automated and approval-gated playbooks that contain risk through connected identity, endpoint, network and "supported AI-platform controls." AI-generated recommendations are offered to analysts, but the company says analysts remain responsible for consequential actions. Remediation tickets route through enterprise ITSM (IT service management) systems, so there is no separate AI-specific response queue.
That design is sensible for SOCs that already have identity and EDR containment wired up. The important qualifier is "supported." Gurucul hasn't published which identity providers, EDR products, network controls or AI platforms can receive automated actions, or which actions need approval. A disable-the-account playbook is only as good as its connector to your directory. Nothing in the announcement confirms which Microsoft identity or endpoint controls are among the connected ones.
The preview prevention layer works differently. It adds automated controls for "supported high-risk AI interactions," plus a lightweight browser plug-in that applies policy to prompts, pasted content, readable file uploads and AI destinations. That reaches the point of interaction, which gateway-style products also target. Gurucul says analysts keep control over enforcement decisions and exceptions.
A browser plug-in is a deployment decision in its own right. It has to be pushed to managed browsers, and it only covers traffic that passes through those browsers. The release doesn't list which browsers are supported, how the plug-in is distributed, or when the preview will reach GA. It is reasonable to infer that the plug-in would not see AI activity from native desktop apps or from agents running server-side, but Gurucul hasn't said so either way.
Anthropic's September 2026 threat report supports Gurucul's premise but not "limited human involvement"
Gurucul's pitch cites two recent developments. The first is the compromise of Hugging Face systems by rogue OpenAI agents, which the company offers as an example of autonomous AI behavior causing security consequences. No reporting found here independently documents that incident as Gurucul describes it, so readers should treat it as the vendor's characterization.
The second is Anthropic's threat-intelligence report, published September 10, 2026. It is on firmer ground and supports the broad premise. Anthropic says the report covers malicious use of Claude that it disrupted between December 2025 and August 2026. It found that most of the cyber operations it described were enabled by AI through direct execution or orchestration. In those cases, multi-agent frameworks carried out reconnaissance, exploitation and data exfiltration, well beyond chatbot question-and-answer.
The report also corrects Gurucul's summary. Gurucul says Anthropic documented agents operating "with limited human involvement." Anthropic's own text says humans stayed in the loop, setting attack targets and reviewing exfiltrated data. Autonomy increased in speed and scale, but people were still directing the operations.
Several details in the report are directly relevant to Windows and Microsoft 365 administrators. Anthropic tracks the actor as GTG-20006 and says its attribution is consistent with public reporting that links the actor to Midnight Blizzard. According to the report, GTG-20006 ran a Microsoft 365 token-theft campaign built on device-code phishing. It automated registering attacker-controlled devices into victim tenants, and it used AI agents to rebuild Windows implants whenever security products detected them. Anthropic's conclusion is that capable adversaries can now get around static detections faster than defenders can write new ones.
That finding is the strongest independent argument for Gurucul's approach, and for behavioral detection generally. If signatures go stale within hours, a baseline of how an identity or agent normally behaves lasts longer than a rule. The report proves nothing about Gurucul's product. What it does show is that "correlate AI activity with identity and endpoint behavior" is a response to documented attacker tradecraft.
What this means for security teams evaluating Gurucul AI Risk and Response
The teams most likely to benefit are those already running Gurucul's SIEM, UEBA or AI-IRM products. Organizations with large Microsoft 365 Copilot or Azure AI Foundry deployments and no view of agent permissions should also look closely. Anyone who mainly wants inline blocking of risky prompts should wait: that capability is in preview with no published GA date. MSSPs are a stated target. Blue Mantis CISO Jay Martin says the product can be enabled quickly using telemetry already available in the customer environment, providing rapid visibility without custom engineering or additional endpoint agents. That is a customer testimonial published in Gurucul's own release, not an independent deployment study.
For an evaluation, the free assessment is the lowest-cost way to find out what your existing telemetry actually reveals before committing. Go in with specific questions:
- Treat detection, investigation and response as the GA product, and plan for runtime prevention and the browser plug-in as preview features with unknown timelines.
- Ask which AI platforms need direct integrations to give you prompt-level and agent-level context, because existing proxy and EDR telemetry alone provides usage visibility, not content.
- Request the full detection catalogue and the per-tactic MITRE ATLAS mapping, since the announcement gives only totals.
- Confirm which of your identity, endpoint and network controls can receive automated or approval-gated playbook actions before counting on containment.
- Get eligibility, data-handling and scope terms in writing before sending real data for the no-cost AI Risk Assessment.
- Take the Anthropic report's warning about device-code phishing and rogue device registration as a reason to review your own Entra ID and Microsoft 365 controls, whatever tool you choose.
Gurucul has put a credible idea into production: treat AI agents as identities with baselines, privileges and histories, and investigate them like any other risky entity. Anthropic's September findings back the threat model, and the list of supported sources, with Microsoft 365 Copilot and Azure AI Foundry alongside ChatGPT, Claude and Gemini, matches where enterprise AI activity actually happens. What buyers can't yet judge is how well it works, because the detection counts, framework coverage and speed claims are all the company's own. Until independent evaluations appear, or runtime prevention leaves preview, the practical step is a proof-of-concept on your own telemetry, and the free assessment is how Gurucul intends that to happen.