IT Brief Canada - Technology news for CIOs & IT decision-makers
Canada
KnowBe4 adds Claude oversight to Agent Risk Manager

KnowBe4 adds Claude oversight to Agent Risk Manager

Mon, 3rd Aug 2026 (Today)
Mark Tarre
MARK TARRE News Chief

KnowBe4 has added support for Anthropic's Claude to its Agent Risk Manager product, extending its AI agent oversight tools beyond existing support for Microsoft Copilot.

The update targets organisations using Claude-based agents in workplace systems and applications. It gives security teams visibility into agent activity and tools to identify threats as those systems take on more autonomous tasks.

Agent Risk Manager is designed to monitor and govern AI agents while they operate, without changing the underlying model. In Claude environments, it is intended to track conversations through Claude.ai and application programming interface connections.

The software can detect issues including prompt injection attempts, sensitive data and personally identifiable information leaks, privilege escalation, and unapproved tool access. It also includes a visual map of connected application programming interfaces and credentials, helping security teams identify systems that could pose greater risk if an AI agent is compromised.

KnowBe4 is positioning the product around a growing concern among security teams that AI agents are beginning to act inside business workflows without the same level of monitoring applied to employees or conventional software systems. The company cited findings from its 2026 Agentic Risk to Human Wins Report showing that 58% of cybersecurity leaders said AI agents are taking actions within organisational workflows, while 52% reported AI use that is unapproved or ungoverned.

Governance gap

The gap has become more pressing as organisations shift from using AI systems for assisted prompting to tools that can complete multi-step tasks, analyse data, and connect with third-party applications with limited human intervention. In that setting, security teams face the prospect of AI identities operating outside established controls for access, oversight, and audit.

The launch adds Anthropic's Claude to a growing list of AI environments where companies are trying to build practical security controls around emerging agent software. Corporate use of large language models has expanded from chat interfaces to embedded assistants and task automation systems, raising questions about how decisions are made, what data can be accessed, and how misuse can be detected in real time.

Matt Duren, SVP of AI and Data at KnowBe4, outlined the company's view of that shift.

"The industry spent decades securing the human element and are challenged to protect the newest members of the digital workforce, AI agents," Duren said.

He also pointed to the risks in more autonomous AI settings.

"It is incredibly important to protect what these agents are doing, especially when employees might be using features like skip permissions mode, which allows the LLM to make its own decisions autonomously with zero oversight. With KnowBe4's Agent Risk Manager for Claude, we focus on the actions, outputs, and tool usage of these agents, ensuring they do not become an unmonitored backdoor into sensitive company assets. We are on the bleeding edge of innovation, which will grow exponentially in the future," he said.

Broader push

Support for Claude follows KnowBe4's earlier native support for Microsoft Copilot, suggesting the company is trying to establish a governance layer across multiple AI agent environments. Rather than focusing only on model access, the product is framed around what an AI agent does after a user or workflow invokes it, including what systems it reaches, what information it handles, and whether its actions diverge from approved behaviour.

That reflects a wider debate in the cybersecurity market over where responsibility for AI safety and control should sit. Model developers have built safeguards into their own services, but buyers are increasingly looking for independent monitoring tools that can apply internal security policy across different suppliers and use cases.

KnowBe4 said Agent Risk Manager uses six detection engines to analyse risk events in real time. Setup is intended to be a one-time process that gives security teams insight into conversations taking place through Claude interfaces or application programming interfaces.

The addition of Claude support broadens KnowBe4's pitch to companies that want to treat AI agents as a new class of digital identity requiring direct oversight. The company says it is used by more than 70,000 organisations worldwide.