Staff paste work into AI tools every day. Security rarely sees which ones — Darktrace Secure AI finds the AI tools your people use, reads prompts on five enterprise AI platforms and tracks AI agents as identities, all from Darktrace’s US or EMEA cloud.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Darktrace Secure AI — AI tools, prompts and agents. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Seeing which AI tools people and agents use, what goes into them, and stopping the risky parts.
What consolidation actually replaces, dimension by dimension.
| Dimension | AI blocked by URL list | Darktrace Secure AI |
|---|---|---|
| Knowing which AI is in use | Staff surveys and expense claims | Telemetry and SASE links list the tools |
| Unapproved AI services | A URL block list, months out of date | Blocked or quarantined from one console |
| Sensitive data in prompts | Found only after it has leaked | Flagged as sensitive-data exposure |
| Jailbreaks and hidden instructions | Invisible to existing tools | Detected in prompt analysis |
| AI agents | Service accounts nobody owns | Tracked as identities with their actions |
| What it is NOT | — | Self-hosted, India-hosted, or publicly priced |
The cheapest test: connect one AI platform in alert-only mode for a month and count the unapproved tools and risky prompts it finds.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Darktrace telemetry, plus SASE integrations such as Microsoft Entra Global Secure Access, shows which AI services staff reach, and can block or quarantine the unsanctioned ones.
Connections to Amazon Bedrock, ChatGPT Enterprise, Claude, Microsoft Copilot and Copilot Studio let it flag jailbreaks, sensitive-data exposure and indirect prompt injection.
AI agents are tracked as identities with a record of their actions, and agents still being built in Bedrock or Copilot Studio are assessed for development risk.
Darktrace runs it on multi-tenant regional Kubernetes in US and EMEA regions; your AI usage policy is uploaded as free-form text rather than built rule by rule.
Telemetry and SASE find the AI in use — prompt analysis and agent tracking run in Darktrace’s US or EMEA cloud.
Darktrace Secure AI watches the AI your people and agents already use — the tools, the prompts and the actions.
Darktrace telemetry surfaces AI services staff are reaching, sanctioned or not, so the inventory starts from traffic.
Through SASE integrations such as Microsoft Entra Global Secure Access, an unsanctioned AI tool can be blocked or quarantined.
Prompt analysis covers Amazon Bedrock, ChatGPT Enterprise, Claude, Microsoft Copilot and Copilot Studio; Salesforce is next.
Prompts written to talk a model out of its safeguards are flagged, so a jailbreak attempt reaches the security team.
Customer records, code or financial detail pasted into an AI conversation are picked out as sensitive-data exposure.
Text planted in a document or page that tries to steer the model once it is read is detected as indirect prompt injection.
Upload the AI acceptable-use policy in free-form text instead of translating every clause into separate rules.
Each AI agent is tracked as an identity, with the actions it takes kept in view for review and response.
Agents under construction in Amazon Bedrock and Copilot Studio are assessed for development risk before release.
A Lamons customer story, why AI security took over Infosec Europe, and a 2024 Darktrace explainer on what AI security means.
Lamons, one of the two customers quoted at launch, on securing the AI tools its people use.
A one-minute take on why AI security became the main topic at Infosec Europe.
Darktrace’s primer on the problem, recorded two years before SECURE AI shipped.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Most AI risk in a business is not a model it built but ChatGPT, Copilot or Claude in daily use. Shadow AI Management uses Darktrace telemetry and SASE integrations, Microsoft Entra Global Secure Access among them, to show which AI services are reached, and can block or quarantine the ones you have not approved.
A URL block says nothing about what an approved tool is fed. AI Prompt Analysis connects to Amazon Bedrock, ChatGPT Enterprise, Claude, Microsoft Copilot and Copilot Studio and flags jailbreak attempts, sensitive-data exposure and indirect prompt injection, the attack hidden in content a model is asked to read.
Agents act with their own permissions, so Darktrace records each as an identity with its actions, and assesses agents still being built in Bedrock or Copilot Studio for development risk. Darktrace places it in the Behavioral Defense Platform, whose Adaptive AI learns what is normal for one organisation.
It went GA on 22 September 2026, so public references are few: ESL Federal Credit Union and Lamons. It is hosted only in US and EMEA regions, with no self-hosted option documented. Prompt coverage is five platforms, Salesforce still to come. Darktrace publishes no price and documents no inline guardrail for apps you build elsewhere.
Inventory Copilot, ChatGPT Enterprise, Claude and Bedrock accounts, and your SASE path, before anything is connected.
Pick the US or EMEA region, and have legal confirm that prompt data processed outside India is acceptable to you.
Link a single AI platform, plus Entra Global Secure Access if you run it, and review shadow-AI findings without blocking.
Load your AI usage policy as written, then check jailbreak and data-exposure alerts against prompts you prepared.
Register agents from Bedrock or Copilot Studio, review what they do, and decide when block or quarantine goes live.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Within a week of connecting Entra Global Secure Access we had a list of AI sites nobody had approved, ranked by how often staff used them.”
“The prompt alerts on Copilot caught a team pasting a pricing sheet into a chat. We coached them rather than banning the tool.”
“Uploading our AI policy as a plain document saved weeks of rule writing, though we tuned the wording after the first alerts.”
“Hosting in the US or EMEA only was the sticking point; legal signed off for ChatGPT Enterprise but held back two other platforms.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the AI security market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
GA in September 2026; quote-only, US or EMEA hosting.
The grid nobody publishes — how much of staff AI use it sees vs how deeply it guards the AI apps and agents you build.
Shadow AI, prompts on five platforms, agent identities.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Palo Alto Prisma AIRS, F5 AI Guardrails, Akamai Firewall for AI, Netskope One AI Security and Trend Vision One AI Security — on coverage, agents, price, limits and India.
| Dimension | Darktrace Secure AI | Palo Alto Prisma AIRS | F5 AI Guardrails | Akamai Firewall for AI | Netskope One AI Security | Trend Vision One AI Security |
|---|---|---|---|---|---|---|
| What it is | Workforce and agent AI | Lifecycle AI platform | Runtime guardrail layer | LLM app firewall | Four-product AI suite | Scanner, guard, access |
| Deployment | Darktrace-run SaaS | Firewall or API call | Cloud, private, on-prem | Edge, API or proxy | Inline plus private AI | From Vision One |
| Workforce and shadow AI | Discover and block | Discovery first step | Not its focus | Not its focus | 1,800+ AI apps inline | AI Secure Access |
| Threats detected | Jailbreaks, leaks, IPI | Seven threat types | Injection to harm | OWASP LLM Top 10 | ATLAS and OWASP | 9 of OWASP’s 10 |
| Agents and MCP | Agent identities | Agent runtime checks | Agents in scope | Not described | Agentic Broker | MCP governance |
| Pricing model | Quote; no meter shown | Monthly token volume | Quote only | Quote after a demo | Quote only | Vision One credits |
| Published entry price | Not published | No public rate | Not published | Not published | Not published | Free trial offered |
| Included vs add-on | Own product spec | Strata stack included | Red Team separate | Standalone item | Four named products | Native to Vision One |
| Published limits | None published | 2 MB and 5 MB scans | None published | None published | None published | Rate limits offered |
| Integrations | Four AI partners | Strata Cloud Manager | Red Team loop | Akamai-centred | DLP, threat, NewEdge | CREM and controls |
| India data location | US or EMEA only | India region since 2025 | Self-host in India | Not documented | Mumbai management plane | Not stated |
| Support | Per contract | Not on product pages | In the offer | Per contract | Per contract | Per contract |
| Lock-in and exit | Darktrace console | Region-bound keys | F5 policy model | Edge assumes Akamai | Traffic via Netskope | Platform credits |
| Best fit | Copilot-heavy workforces | Palo Alto estates | On-site AI models | Public LLM apps | Netskope SSE users | Vision One customers |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
TechBag has no AI security guide yet, so Darktrace Secure AI sits outside the category guides. Browse all products to compare it with the rest of the catalogue. →
Drag the sliders (employees using AI tools; analyst-hour cost). Estimates model security and compliance time spent tracing which AI tools staff use and reviewing risky prompts, at an assumed 1.5 hours per AI user a year, with 70% of it removed by automated discovery and prompt analysis. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote-only: Darktrace publishes no SECURE AI price or usage metric, and its public AWS Marketplace offer is metered on network bandwidth and hosts, so it does not price this product. SECURE AI is contracted under its own product specification. TechBag inventories your AI platforms and agents first, then quotes in INR with GST.
Best for Copilot and ChatGPT Enterprise rollouts
Best for a broader rollout
Best for existing Darktrace customers
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Are your AI tools among Bedrock, ChatGPT Enterprise, Claude, Copilot and Copilot Studio? Salesforce is not covered yet.
Can prompt data be processed in a US or EMEA region? SECURE AI has no India region and no self-hosted form.
Do you run Entra Global Secure Access or another SASE that SECURE AI can use to block unapproved AI services?
Is your AI acceptable-use policy written down? It is uploaded as free-form text, so its wording drives the alerts.
Which agents are built in Bedrock or Copilot Studio, and who owns each one before it is tracked as an identity?
Will blocking and quarantine start in alert-only mode, and who signs off the move to enforcement?
Do you also need an inline guardrail for a customer-facing LLM app? That is a different job; compare it separately.
Does the quote state what is metered, the term and the hosting region? Ask for INR with GST and the contract specification.
List the AI platforms and agents you run first, or let a TechBag advisor scope a pilot on one AI platform before any blocking is switched on.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.