{"id":7361,"date":"2026-08-01T08:02:42","date_gmt":"2026-08-01T12:02:42","guid":{"rendered":"https:\/\/workai.tv\/news\/2026\/08\/ai-agents\/morphisec-launches-ai-usage-control-to-govern-enterprise-ai-agents-and-identities\/"},"modified":"2026-08-01T08:02:42","modified_gmt":"2026-08-01T12:02:42","slug":"morphisec-launches-ai-usage-control-to-govern-enterprise-ai-agents-and-identities","status":"publish","type":"post","link":"https:\/\/workai.tv\/news\/2026\/08\/ai-agents\/morphisec-launches-ai-usage-control-to-govern-enterprise-ai-agents-and-identities\/","title":{"rendered":"Morphisec Launches AI Usage Control to Govern Enterprise AI Agents and Identities"},"content":{"rendered":"<h2>Share with your CISO<\/h2>\n<p>Morphisec is betting that the real AI governance gap isn&#8217;t network traffic, it&#8217;s the endpoint. The company has launched <a href=\"https:\/\/www.securityinfowatch.com\/cybersecurity\/news\/55394876\/morphisec-launches-ai-usage-control-to-govern-enterprise-ai-agents-and-identities\" target=\"_blank\" rel=\"noopener nofollow\">AI Usage Control<\/a>, a module that discovers and governs AI agents, machine identities, and shadow AI tools running directly on Windows, Linux, and macOS endpoints without requiring a separate agent or proxy. It maps actions to specific user identities in real time, enforces least-privilege policies before execution, and logs controls against the EU AI Act, NIST AI RMF, and SOC 2. Gartner projects 40 percent of enterprises will face AI-related compliance incidents by 2030.<\/p>\n<h2>What this means for your business<\/h2>\n<p>The question this product forces isn&#8217;t whether your organization uses AI agents, it&#8217;s whether you actually know which identities are driving them. Fifty-one percent of organizations already run agents in production, per LangChain research, and the attack surface that creates isn&#8217;t a future problem. An agent that can execute commands, move files, and chain tools together using standing privileges, meaning access rights that persist even when no human is watching, is a materially different risk than a SaaS app sitting behind an API gateway. CISOs with mature identity programs but no endpoint-level AI visibility are exposed on an axis their current tooling doesn&#8217;t cover.<\/p>\n<p>Morphisec&#8217;s core argument is that proxies and browser extensions miss the hard cases: local models, command-line agents, and Model Context Protocol servers, the emerging standard for connecting AI agents to external tools, that run entirely on the device. That claim is directionally correct. The proxy-centric governance model was designed for a world where enterprise software lived in browsers and called cloud APIs. Agents increasingly don&#8217;t. Where the argument strains is in Morphisec&#8217;s implicit promise that endpoint telemetry alone is sufficient governance. Knowing what an agent attempted doesn&#8217;t tell you whether the model producing those actions was tampered with upstream, which is a risk that lives outside the endpoint entirely.<\/p>\n<p>The company&#8217;s alignment with AIUC-1, described as a &#8220;SOC 2 for AI agents&#8221; and listed in the Cloud Security Alliance registry, matters more than it looks. Compliance frameworks create procurement leverage, and the moment a customer&#8217;s auditor starts asking for AIUC-1 controls, the vendor with a pre-mapped solution wins the renewal conversation by default. If AIUC-1 gains the traction SOC 2 did in SaaS procurement cycles, the CISO who ignored it during 2025 and 2026 will be retrofitting controls under deadline pressure in 2027. That&#8217;s the budget decision worth framing now, not after the framework hardens.<\/p>\n<h2>Concept deep-dive: Machine identity<\/h2>\n<p>A machine identity is the credential or token an AI agent uses to authenticate and act within enterprise systems, distinct from the human who deployed it. Think of it as a badge that the agent swipes autonomously, often with broad permissions set at deployment and never revisited. The governance problem is that traditional identity platforms authorize the session, not each individual action the agent takes inside it. AIUC-style controls attempt to enforce action-level accountability that session-based identity tools were never designed to provide.<\/p>\n<p><em>Based on reporting from <a href=\"https:\/\/www.securityinfowatch.com\/cybersecurity\/news\/55394876\/morphisec-launches-ai-usage-control-to-govern-enterprise-ai-agents-and-identities\" target=\"_blank\" rel=\"noopener nofollow\">Morphisec Launches AI Usage Control to Govern Enterprise AI Agents and Identities<\/a>, originally published 2026-07-31 10:14:00.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Share with your CISO Morphisec is betting that the real AI governance gap isn&#8217;t network traffic, it&#8217;s the endpoint. The company has launched AI Usage Control, a module that discovers and governs AI agents, machine identities, and shadow AI tools running directly on Windows, Linux, and macOS endpoints without requiring a separate agent or proxy. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":7362,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[142],"tags":[238],"tmauthors":[],"class_list":["post-7361","post","type-post","status-publish","format-standard","has-post-thumbnail","category-ai-agents","tag-ciso"],"_links":{"self":[{"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/posts\/7361","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/comments?post=7361"}],"version-history":[{"count":0,"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/posts\/7361\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/media\/7362"}],"wp:attachment":[{"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/media?parent=7361"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/categories?post=7361"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/tags?post=7361"},{"taxonomy":"tmauthors","embeddable":true,"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/tmauthors?post=7361"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}