Exaforce extends its AI security tool to monitor more than just Claude

While most of these efforts focused on AI agent discovery, a recent study showed that this is only part of the puzzle that enterprises need to solve. A March 2026 survey by the Cloud Security Alliance found 68% of organizations could not distinguish human activity from AI-agent activity, necessitating agent discovery. But even the agents they did know about were not necessarily under control: 74% of respondents said their AI agents received more access than necessary, and 52% said agents sometimes inherited access originally intended for humans.
That makes the AI-agent security problem more complicated, and it remains to be seen whether Exaforce’s bet on correlating existing security telemetry can provide enough control without dedicated agent identities, tightly scoped permissions and controls enforced at the point where an agent acts.
“Most current offerings remain observation and posture management, with very limited in-line blocking or remediation, and platform-native controls typically stop at their own cloud borders,” Litan said, adding that an effective solution would need to “discover sanctioned and unsanctioned agents across clouds and hosting environments, map the human and machine owner, tie activity to the right nonhuman identity when no global agent registry exists, and enforce policy once an agent leaves the platform that created it.”