メインコンテンツにスキップ
Abnormal Extends Behavioral AI to Identity and AI SecurityLearn more

Jul 28, 2026

AI Governance: Secure AI Transformation with Behavioral AI

Discover and govern AI Tools, Chats, and Agents with Behavioral AI.

AI tools and agents are spreading through organizations faster than any security team can review them. Employees are signing up for tools without IT approval, agents inherit access nobody reviewed, and sensitive company data is landing in AI chats employees assume are private. Companies leaning into AI transformation, empowering employees to work with AI tools and agents, are the ones now facing this exact problem.

Beginning August 3, Abnormal is launching AI Governance to help organizations see, score, and govern their AI tools, agents, and chats in their environment, using email, OAuth, identity, and SaaS signals to catch risk automatically and enforce policy before it becomes an incident.

AI Governance is another new product extending the Abnormal Behavioral Security Platform. For nearly a decade, Abnormal’s detection model has provided proven efficacy for email security. Now it's correlating signals from OAuth grants, AI chat content, and agent activity; a new category of signal extending protection using the same behavioral engine. That correlation is what helps catch what a static tool inventory or a written policy alone can miss: the moment a tool signs up, an agent oversteps, or sensitive data leaves through a chat.

Note: AI Governance will officially go GA at Black Hat USA 2026 on August 3, 2026. This blog serves as a preview of those capabilities.

Inside AI Governance

AI Governance extends the same behavioral AI that already protects the inboxes of 4500+ organizations to the AI layer, correlating email, OAuth, and SaaS signals with direct integrations into agent platforms and AI chat tools to establish a baseline of what's normal for that organization's AI usage.

That same baseline means AI activity gets evaluated in the context of how identities and data actually move, not as a list of approved and unapproved apps. No single sign-up or OAuth grant has to look risky on its own, but correlated against existing behavioral signals, a new AI tool or an over-permissioned agent gets the moment security needs to know about it. A tool inventory can tell you an AI tool showed up. AI Governance can tell you what it's connected to and what it can already do with the access it has.

Agents, Chats, and Shadow AI Spend

AI Security Product 1

Security teams often find out about an unapproved AI agent or tool only by chance, the same way one security leader described discovering an unreviewed integration that was supposed to go through approval: they happened to catch it, and know there are others they haven't. An employee adding an unvetted skill or integration to an otherwise sanctioned AI tool can quietly hand it access it was never meant to have, and nobody finds out until that access has already been used.

ABS308u 2 CR Cost Insights

AI Governance is built to close three blind spots at once: which AI agents are running, what sensitive data is showing up in AI chats, and how much shadow AI is costing you. It ties discovered agents to an owner, baselines its behavior across the model providers you use, flags sensitive data exposure in AI chat tools, and matches vendor invoices against what's actually running to surface spend on tools nobody's using.

AI Tool Discovery

AI Security Product 3

An unreviewed AI tool is effectively an outside vendor with access to company systems that nobody vetted, and it typically won't show up in the tools your security team already uses to monitor.

AI Governance discovers your sanctioned and unsanctioned AI tools using the same email and identity signals already used to protect your inbox, to help catch shadow AI before it becomes a breach. When someone signs up for a new tool or grants it OAuth access, whether that's a signup confirmation landing in the inbox or an OAuth consent event, AI Governance sees it and adds the tool to the directory, scored and classified automatically, before that access becomes the incident.

Automatic Remediation

AI Security Product 4

AI Governance enforces remediation the moment a new unsanctioned tool is discovered, no manual workflow required. It can be configured to automatically notify the person responsible for a flagged tool or grant and requests justification, with responses routed to the security team for review; security teams don't have to manually follow up with every user themselves.

Secure Your AI Ecosystem

Organizations are under pressure to move faster and do more with less, and AI makes that possible in ways that have never been experienced before. People across the business are spinning up agents and tools on their own, and security is the last to know, yet the first to feel it once something goes wrong. AI Governance puts security teams first, designed to continuously discover and automatically enforce policy as issues arise.

AI Governance gives organizations better visibility into the tools, agents, and software employees are using, insight into where data is exposed, and automated governance that keeps them ahead of their AI ecosystem instead of chasing it.

With AI Governance, organizations can say yes to AI adoption with confidence, instead of choosing between moving fast and staying secure.

To learn how AI Governance can help your organization securely adopt AI, connect with your Abnormal team or request inside access.

Request Inside Access

The above is intended to outline our general product direction. It is intended for information purposes only, and may not be incorporated into any contract. It is not a commitment to deliver any material, code, or functionality, and should not be relied upon in making purchasing decisions. The development, release, and timing of any features or functionality described for Abnormal AI’s products remains at the sole discretion of Abnormal AI and is subject to change.

Protect Against Evolving Email Threats

See how behavioral AI detects attacks that legacy defenses miss.