Tenable and OpenAI launch AI component inspector for agent exchange
Tenable Holdings has announced a collaboration with OpenAI to build the CyberAgents Exchange AI Inspector, a security review process designed to scrutinise community-contributed AI agents, skills, MCP servers and multi-agent playbooks before they are deployed in enterprise environments. The product was unveiled at OpenAI's Intelligence at Work: Cyber Summit on 3 September and is expected to reach general availability later this month.
The Exchange Inspector combines automated assessment using OpenAI's GPT cyber models, skills inspection powered by Tenable One AI Exposure, and manual review by Tenable's security researchers. The collaboration grew from Tenable's participation in the OpenAI Daybreak Defense Network, a programme that connects cybersecurity vendors with frontier AI capabilities for defensive use cases.
The product and platform
The Exchange Inspector sits atop the CyberAgents Exchange, an open-source cybersecurity registry that Tenable launched in August 2026. The Exchange already holds more than 100 community-submitted components following a SWARM build event Tenable hosted at Black Hat USA. The registry is positioned by the company as the first cybersecurity-native marketplace of its kind for agentic AI artefacts.
Eric Doerr, chief product officer at Tenable, said the move was about building trust in the growing agent ecosystem. "By combining OpenAI GPT cyber models with Tenable's security expertise and researcher review, we're building a more rigorous way to inspect community-built AI components before they're used in enterprise environments," he said.
Tenable has not disclosed pricing for the Exchange Inspector, and the release does not name any enterprise customers who have committed to using the service. Benchmark data comparing the Inspector's detection rates against alternative review processes was not provided.
Market context
The arrival of Exchange Inspector reflects a broader anxiety across enterprise security teams: the explosion of agentic AI tooling has outpaced formal vetting processes. As organisations move from large-language-model chatbots toward autonomous agents capable of taking actions across IT environments, the attack surface expands to include the agents themselves, the skill libraries they call, and the orchestration layers connecting them.
Tenable competes in this space against Palo Alto Networks, CrowdStrike, Wiz and a growing number of AI-native security startups, several of which have announced agent-security features of their own in 2026. The CyberAgents Exchange's open-source, community-contribution model is a deliberate differentiator, lowering the barrier to contribution while the Inspector process provides a quality gate. Whether that model scales securely as the component library grows is a question practitioners are likely to press.
Regulatory read-across
The EU AI Act's obligations for general-purpose AI systems and high-risk AI applications are phasing in across 2026 and 2027, and enterprise procurement teams are already under pressure to demonstrate that AI components they deploy meet transparency and conformity requirements. A community-sourced registry with published inspection results could serve as evidence of due diligence, though Tenable has not stated whether its review process is designed to map to any specific regulatory framework or certification standard such as SOC 2 or ISO 42001. That clarity will matter as regulated-sector buyers, particularly in financial services and critical infrastructure, evaluate whether the Exchange can support their compliance obligations alongside operational security goals.