Morphisec Launches AI Usage Control to Govern Enterprise AI Agents and Identities
Morphisec has announced the general availability of AI Usage Control, or AIUC, a module designed to discover and govern AI tools, autonomous agents, and machine identities operating across enterprise endpoints.
The company said AIUC extends its in-memory prevention technology to AI governance and runs on Windows, Linux, and macOS through the existing Morphisec Protector agent, eliminating the need for a separate agent, proxy, or cloud relay.
The launch comes as organizations continue expanding the use of AI agents. Morphisec cited LangChain research showing that 51 percent of organizations already run AI agents in production, while Gartner projects that more than 40 percent of enterprises will face security or compliance incidents related to unauthorized shadow AI by 2030.
According to Morphisec, the risks extend beyond unmanaged AI tools to unmanaged identities operating approved tools, as well as compromised agents, data leakage, and compliance exposure involving privacy and data sovereignty requirements. The company argued that AI agents present a distinct challenge because they can execute commands, move files, and chain tools together using standing privileges.
Morphisec said many current AI governance products rely on traffic interception through proxies, browser extensions, or API gateways, which may not capture local AI models, command-line agents, or Model Context Protocol servers running directly on a device. The company also said traditional endpoint detection and response tools focus on malicious code rather than authorized agents performing seemingly legitimate actions, while identity platforms typically authorize sessions rather than individual runtime actions.
Chief Executive Officer Ron Reinfeld said Morphisec focuses on monitoring AI agents directly rather than observing network traffic. He said the platform identifies which identity is driving which agent, what tools the agent has been granted, and what actions it attempts to perform, allowing governance in real time for both sanctioned and shadow AI.
AIUC includes AI discovery capabilities that inventory AI tools, accounts, agents, browser extensions, large language model services, and MCP connectors, including shadow AI and the identities associated with them. The module also provides identity-aware governance by mapping AI actions to users, identities, and devices so organizations can enforce role-based tool access and detect sanctioned tools operating under unsanctioned identities.
The platform adds controls for tools, skills, and permissions, allowing organizations to govern the specific capabilities an agent may use rather than only the agent itself. Morphisec said it can also stop AI-driven data exfiltration from endpoints based on the type of tool being used and the destination of the data, without inspecting the content itself.
For compliance, AIUC provides inventories and enforcement logs mapped to the EU AI Act, NIST AI RMF, ISO 42001, and SOC 2. The module also includes runtime guardrails intended to enforce least-privilege policies and block risky AI actions, such as attempts to access credentials, before they execute.
Morphisec said its platform aligns with AIUC-1, a standard launched in 2025 and described as a "SOC 2 for AI agents," which is listed in the Cloud Security Alliance STAR registry. The company said it maps its controls to all six pillars of the AIUC-1 framework.
AIUC is available immediately as a standalone module and as part of the company’s Anti-Ransomware Assurance Complete bundle, which includes Morphisec’s Ransomware-Free Guarantee. The company plans to demonstrate the product at Black Hat USA 2026 in Las Vegas from August 1 through August 6.
