SecurityBrief Asia - Technology news for CISOs & cybersecurity decision-makers
Asia
Bedrock Data launches AI agent data loss prevention

Bedrock Data launches AI agent data loss prevention

Sat, 1st Aug 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Bedrock Data has launched Agent DLP, a data loss prevention product for AI agents, alongside research suggesting those agents often start with far broader access to company data than human employees.

The product is part of Bedrock Data's ArgusAI platform and is designed to inspect data moving in and out of AI agents while they operate. It checks every request an agent sends to a software tool and every response it receives, then applies data access and regulatory policies in real time.

The launch addresses a growing concern for companies deploying AI assistants, copilots and autonomous software agents across internal systems. Many organisations have focused on model safety and employee use of generative AI tools, but Bedrock Data argues that a more immediate risk lies in the access rights inherited by machine identities such as service accounts and registered applications.

The study drew on anonymised telemetry spanning more than 70 petabytes of data, nearly 180,000 datastores and more than 540,000 identities across technology, finance and healthcare environments. It found that the median application or service account could reach 55 datastores, compared with 3 to 4 for the median employee.

It also found that 79% of those non-human identities could reach stored secrets such as API keys and tokens. Across all identity types, 81% of identities with access to any data could also access sensitive data, suggesting broad exposure is built into many enterprise systems rather than caused by isolated misconfigurations.

That matters because AI agents typically authenticate through those existing machine identities. In Bedrock Data's view, an agent can become a data risk as soon as it is deployed, without any new permissions, because it inherits the access already attached to the account behind it.

Runtime controls

Traditional data loss prevention tools have generally focused on human activity, such as moving files through email, endpoints or cloud applications. That model does not map neatly to agents, which interact through software tool calls and can retrieve or transmit information at machine speed.

Agent DLP is designed to sit at the agent gateway through native hooks for AWS AgentCore and LiteLLM. Rather than acting as a separate proxy or gateway, it inspects traffic inline as an agent interacts with tools.

The system can block, modify, redact or simply observe actions, depending on the policy applied. It also logs each decision with the target, action, data types involved and the verdict, creating an audit trail of what an agent did and what data it touched.

One example involved a customer support agent calling a tool to retrieve customer details. If the response contained an address, card number and Social Security number, the action would be blocked immediately. By contrast, a marketing agent query returning customer email addresses could be allowed in observe-only mode for monitoring.

Policy pressure

Bedrock Data linked the launch to growing regulatory scrutiny of AI governance. It pointed to rules and standards including the EU AI Act, state-level AI measures in Colourado and California, and ISO/IEC 42001, which require organisations to show what their systems did and why.

That framing reflects a wider shift in enterprise AI security from static policy-setting to operational enforcement. In practice, companies may already have classification rules, access policies and governance standards on paper, but the challenge is applying them consistently when agents interact directly with business systems and sensitive records.

A Gartner projection cited by Bedrock Data said that through 2026, at least 80% of unauthorised AI transactions would stem from internal policy violations rather than external attacks. The implication is that the main risk may lie less in hackers breaching AI systems than in organisations failing to control what their own automated agents are allowed to do.

Bruno Kurtic, Chief Executive Officer and Co-Founder of Bedrock Data, said the issue extends beyond technical teams into corporate strategy.

"A decade from now, the companies who win with AI will be the ones that put their most valuable data to work through agents. Their proprietary data is the one advantage competitors cannot buy or copy. Bedrock Data gives enterprises comprehensive data security posture at scale, and now real-time enforcement across everything agents do. Governance at runtime is what turns AI from a risk conversation into a growth strategy," said Bruno Kurtic, Chief Executive Officer and Co-Founder of Bedrock Data.

The company also included support from Boston Consulting Group, which said it uses Bedrock Data internally.

"Companies pulling ahead with AI are those who treat their data as a leadership priority, not a technical detail. Command of your own data and adoption of AI is what separates the winners from everyone still watching. That is a conversation for the CEO and the board, and it is the one I have most often right now," said Vladimir Lukic, Managing Director, Senior Partner and Global Leader of the Tech and Digital Advantage practice at Boston Consulting Group. "We use Bedrock Data at BCG to solve these problems for ourselves, so when we tell clients that command of their data comes first, we are speaking from experience."