VYPR
advisoryPublished Aug 3, 2026· 1 source

Mimecast Launches Agent Risk Center to Govern Unsanctioned AI Tools

Mimecast introduces Agent Risk Center, a beta tool to discover, monitor, and govern AI agents, addressing the widespread use of unsanctioned AI tools in organizations.

Mimecast has unveiled Agent Risk Center, a beta capability designed to provide organizations with the means to discover, monitor, and govern the growing number of AI agents operating within their environments. This new offering is complemented by a redesigned Managed Threat Response service, which merges AI-assisted triage with human analyst-confirmed remediation for security alerts.

The proliferation of AI agents presents a significant challenge for security teams. Mimecast's analysis indicates that a staggering 98% of organizations already have unsanctioned AI tools in use. Projections suggest that by 2029, over a billion AI agents will perform an estimated 217 billion actions daily on behalf of employees, often with limited visibility for existing security tools. The Agent Risk Center aims to provide security and risk teams with a centralized platform to identify the users behind this activity and enforce governance, applying the same risk management principles used for human insiders to these AI agents.

"AI agents are being deployed faster than security teams can see them," stated Rob Juncker, Chief Technology & Product Officer at Mimecast. "Most organizations don’t know what agents are running in their environment, what data they’re touching, or who’s accountable when something goes wrong. Mimecast Agent Risk Center changes that — same risk model, same controls, extended to every agent acting on behalf of your people."

As enterprises increasingly integrate AI agents into workflows across email, collaboration platforms, and business processes, the attack surface expands, often with inadequate visibility into agent behavior, permissions, and data access. Mimecast's Agent Risk Center is positioned to offer a single point of control for security and risk teams to manage these AI agents. Key features include a unified dashboard for a real-time inventory of all AI tools and connections, an "AI Rulebook" for classifying agents and enforcing policies by department without new deployments, and response controls such as desktop app blocking, browser upload/paste restrictions, and in-context user nudges.

The Mimecast Agent Risk Center is currently in beta and available as a free, opt-in feature for active Incydr subscription customers. Early access is scheduled for September 2026, with general availability for these customers planned for January 2027. This phased rollout allows Mimecast to gather feedback and refine the product before wider release.

In parallel, Mimecast has introduced a revamped Managed Threat Response service. This 24/7 managed offering tackles the persistent problem of uninvestigated security alerts, a challenge highlighted by research indicating that 42% of alerts go uninvestigated. Mimecast's service addresses this gap by taking on 100% of reported email alerts, using AI for initial triage and then having Security Operations Center (SOC) analysts confirm and remediate threats. This includes actions like blocking malicious senders or domains, removing phishing campaigns tenant-wide, and updating detection logic based on confirmed outcomes.

Customers of the Managed Threat Response service benefit from a streamlined experience where confirmed threats are remediated without requiring them to manage new consoles, tune models, or hire additional analyst headcount. The continuous improvement of detection logic is driven by the identification of confirmed threats across Mimecast's extensive customer base of 42,000 organizations, creating a collective intelligence advantage.

These new offerings from Mimecast underscore the growing industry focus on managing the security implications of AI adoption. By providing tools to govern AI agents and enhance threat response capabilities, Mimecast aims to help organizations navigate the evolving threat landscape and mitigate risks associated with the rapid integration of artificial intelligence.

Synthesized by Vypr AI