Cyera Launches Agent Guardian to Secure the Autonomous Workforce
Agents are already inside enterprise systems operating without oversight. Cyera's newest products deliver critical
Press Release Disclaimer: This is a press release distributed through the XPR Media network. It has not been independently verified by our newsroom.

![]()
Non-human identities in Fortune 500 companies grew 480% in the last six months alone, and enterprises have no visibility into most of them. The moment an AI agent is deployed, it inherits elevated human permissions and moves at machine speed, touching data in seconds that would take a human a career to reach. This invisible layer of the new autonomous workforce is rapidly becoming the fastest-growing attack surface in enterprise security. Until now, there’s been no infrastructure purpose-built to govern what agents can see and do, leaving sensitive data, critical systems, and regulatory obligations increasingly at risk.
Today at Black Hat 2026, Cyera launched Agent Guardian, built to make every AI agent as visible and accountable as a human employee. Agent Guardian goes beyond the prompt and the response, monitoring every tool call, database query, and reasoning step in between. Alongside Agent Guardian, Cyera also introduced Cyera Endpoint, bringing AI guardrails directly to employee devices for local agents that operate outside corporate network controls, where they are increasingly doing their most sensitive work. Together, they extend the trust layer Cyera is building for the agentic enterprise, answering what an agent can reach and what it should be allowed to do with it.
“AI agents have become a new class of enterprise identity. But the fundamental shift isn’t that organizations have more identities; it’s that the gap between permission and execution has disappeared,” said Tamar Bar-Ilan, cofounder and CTO of Cyera. “Agent Guardian and Cyera Endpoint give organizations the visibility and runtime control to govern this new reality, enabling them to accelerate AI adoption without putting sensitive data at risk.”
Built to Secure the Agentic Enterprise, From the Device to the Cloud
Agent Guardian fills the critical gap between rapid agentic adoption and operational control, organizing the agent security journey around a continuous, systematic operational lifecycle:
- Discover—Account for every agent: Automatically inventories every AI application and agent running across endpoints, SaaS platforms, and cloud environments, including shadow agents and MCP servers security teams didn’t know existed, and maps exactly what data each one can reach.
- Govern—Set the rules: Defines what each agent is allowed to do, flags when it drifts from its intended purpose, and continuously audits for overprivileged access and risky configurations.
- Protect—Stop threats in real time: Operates inline within the execution path and uses AI-driven policy and content evaluations to intercept dangerous tool calls, block unauthorized data transfers, and quarantine compromised agents before execution.
- Validate—Prove the guardrails hold: Continuously red-teams defenses against prompt injection, jailbreaking, and privilege escalation, and generates audit-ready compliance reports to satisfy frameworks like the EU AI Act.
Whether enterprises are deploying agents built on AWS Bedrock, or managing developer agents running on employee devices or rolling out Microsoft 365 Copilot, Agent Guardian secures the entire agentic surface from one platform, giving security teams the visibility to see every agent, the precision to govern what it touches, and the runtime control to stop it before it causes harm.
AI Guardrails Where Agents Work
Agent Guardian enforces policy wherever AI interacts with enterprise data, including through platform APIs, AI gateways, browser extension, agent framework hooks, and remote scans of employee devices. That last control point has become increasingly important as developers adopt local agents such as Claude Code and Cursor, where activity never crosses a network boundary and traditional security tools have little or no visibility.
To add runtime protection to where local activity happens, Cyera today also introduced Cyera Endpoint, a lightweight endpoint control that brings Agent Guardian’s policies directly to the device. It provides live visibility into sanctioned and shadow local agent activity, classifies and protects sensitive files before they’re accessed or leave the machine, and blocks data from reaching unauthorized personal AI accounts, enabling consistent governance across cloud, SaaS, and endpoint environments.
Built for Every Agent, Across Every Platform
Cyera covers the full agentic surface, from desktop agents like Claude Code and Cursor to enterprise platforms like Microsoft Copilot Studio, Salesforce Agentforce, and Snowflake Cortex AI, to custom cloud deployments on AWS Bedrock, Microsoft Foundry, and Vertex AI.
“AI is only as trustworthy as the data behind it,” added Mayank Upadhyay, Chief Security & Trust Officer at Snowflake. “Working with Cyera lets Snowflake customers see every Cortex AI agent in use and understand exactly what data it can reach, so they can adopt agentic AI with the same confidence they place in their data.”
To see Agent Guardian and Cyera Endpoint in action, visit Cyera at Black Hat 2026, Booth #4152 or request a demo here.
About Cyera
Cyera is building the trust layer powering enterprise AI transformation. Enterprises like Paramount, Chipotle, and Valvoline use Cyera to control exactly what data their AI can reach—and govern what happens next. The platform secures data at rest, in motion, and in use, whether touched by humans or AI agents. Valued at $12 billion and backed by over $2.3 billion from Accel, Blackstone, Cyberstarts, Georgian, Lightspeed, and Sequoia. Protect your data. Secure AI.
View source version on businesswire.com: https://www.businesswire.com/news/home/20260803910817/en/
Media gallery

