Airlock Digital adds agentic AI governance to endpoint security

Airlock Digital is extending its application control platform with session-level visibility and real-time policy enforcement for AI agents on endpoints.

Airlock Digital adds agentic AI governance to endpoint security

Airlock Digital has unveiled Agentic AI Control and Governance, a set of capabilities that extend its existing application control platform to cover the behaviour of AI agents once they are running on enterprise endpoints. The company announced the product at Black Hat USA 2026 in Las Vegas on 4 August, with customer general availability targeted for Q3 2026.

The distinction the company draws is between two policy layers. Traditional application control governs whether a piece of software is trusted to execute at all. Once an AI agent clears that gate and begins running, a second set of questions arises: what commands can it issue, what files can it touch, and how should it respond when a requested action falls outside policy? Airlock's new capabilities are designed to answer those questions at the session and command level, rather than simply blocking or allowing execution.

The product

Agentic AI Control and Governance covers four main areas: automated discovery of AI applications and agents; centralised, version-controlled policy management for both traditional applications and AI agents; real-time evaluation of agent commands against policy with decisions communicated back to supported agents; and a unified dashboard for monitoring sessions, commands, file interactions, token usage and cost.

That last point is notable. Rather than simply terminating an agent when it attempts a disallowed action, the platform signals the policy decision back to the agent, allowing it to adapt its behaviour within permitted bounds. David Cottingham, co-founder and chief product officer, explained the rationale: "AI agents don't simply stop when an action is blocked; they evaluate alternatives and continue working toward their objective. Rather than repeatedly blocking an agent, organisations can communicate clear operational boundaries, allowing trusted agents to adapt their behaviour while remaining within policy."

The company cited a Cloud Security Alliance survey from April 2026 reporting that 82% of organisations had unknown AI agents running in their environments, and that 65% had experienced an AI agent-related security incident in the prior 12 months. Those figures lend urgency to a product category that has emerged quickly alongside the rapid enterprise adoption of agentic frameworks.

Market context

Airlock Digital, founded in Australia in 2013, has historically positioned itself around application allowlisting and OS hardening, with a customer base spanning financial services, healthcare, energy and government. The pivot to agentic AI governance places it in a nascent but increasingly crowded space. A number of well-funded cybersecurity startups are pursuing AI agent security from different angles, including network-traffic analysis, identity and access management extensions, and LLM-specific firewall products. Incumbent endpoint detection and response vendors are also adding AI-specific telemetry to their platforms.

What differentiates Airlock's approach, at least in its own framing, is the application control foundation: policy enforcement happens at the endpoint where the agent executes, rather than at the network perimeter or within a cloud-native application's own guardrails. Whether that endpoint-centric model proves more durable than perimeter or API-layer alternatives will depend heavily on how agentic AI deployment patterns evolve across enterprise architectures.

Regulatory read-across

Governance over autonomous AI systems is a live regulatory concern. The EU AI Act's obligations for general-purpose AI systems and high-risk AI applications are phasing in through 2026 and 2027, and enterprise buyers in regulated sectors will need audit trails and policy controls that satisfy both internal compliance teams and external regulators. NIS2, which applies to operators of essential services across EU member states, similarly demands demonstrable controls over software executing on critical infrastructure. A centralised dashboard with searchable session logs and version-controlled policy changes is positioned by Airlock to address exactly those audit and demonstration requirements.

Chief executive Kevin Dunne said the company's customers are less focused on AI adoption than on the governance gap that follows it. General availability in Q3 2026 will be the first test of whether the platform's policy-communication model holds up across the range of commercial agentic frameworks enterprises are deploying.