Bedrock Data Launches Agent DLP, Runtime Data Loss Prevention Built for AI Agents

ArgusAI Agent DLP sits inline at the agent gateway, inspects every tool call in both directions and enforces data access and regulatory policies in real time to deliver runtime control

SAN MATEO, Calif.--(BUSINESS WIRE)--Bedrock Data, the platform provider for DSPM, AI data security and governance, today announced Agent DLP™, a runtime data loss prevention capability for AI agents, available today as part of ArgusAI. Agent DLP extends Bedrock Data’s ArgusAI from posture, knowing what data every agent can access, to runtime control capable of governing what agents do with said data. It inspects agent traffic in both directions: every request an agent sends to a tool and every response it gets back enforcing enterprise data access and regulatory policies in real time as agents take actions. With Agent DLP, security teams no longer need to choose between an agent that is useful and one that is constrained: every operation is checked against the data it touches, the identity behind it, and the policy that applies, then allowed, modified, or blocked at the time of action. Every decision is logged with its target, action, data types and verdict, producing a continuous audit record of what every agent did.





“A decade from now, the companies who win with AI will be the ones that put their most valuable data to work through agents. Their proprietary data is the one advantage competitors cannot buy or copy. Bedrock Data gives enterprises comprehensive data security posture at scale, and now real-time enforcement across everything agents do. Governance at runtime is what turns AI from a risk conversation into a growth strategy,” said Bruno Kurtic, CEO and co-founder of Bedrock Data.

AI Agents Create Data Security Risks Existing Controls Can’t See
Enterprises are deploying agents faster than they can govern them. An agent can touch more sensitive data in minutes than an employee handles in a year, and existing security controls, built around human behavior, were never designed to evaluate an agent's every action.

Gartner projects that through 2026, at least 80% of unauthorized AI transactions will come from internal violations of enterprise policy rather than external attacks.¹ The exposure is the byproduct of agents, copilots, and assistants doing exactly the jobs they were given.

A new Bedrock Data study of enterprise data exposure, based on anonymized telemetry spanning more than 70 petabytes of data, nearly 180,000 datastores, and more than 540,000 identities across enterprise environments in technology, finance, and healthcare, shows why:

  • Enterprise data is complex. At least one in three bytes scanned carries a sensitive classification, and personal information is only a small part of that; most is financial, security, and confidential business data. Sensitivity is also unpredictable. Object storage averages under 4% PII, yet the study found a single bucket that was more than 99% PII. No one can assume what a datastore holds. It has to be classified.
  • The identities agents inherit have the widest access of all. In environments with registered OAuth apps and service accounts, the identity class agents authenticate as, the median app can reach 55 datastores, more than ten times the 3 to 4 reached by the median employee. Virtually every app that can reach data can reach sensitive data, and 79% can reach stored secrets such as API keys and tokens. In one environment studied, a single identity could reach more than 41,000 datastores and roughly 21 petabytes. An agent does not need to be granted anything new to become a data risk. It inherits this exposure on day one.
  • Broad access to sensitive data is structural, not accidental. Across all identity types, 81% of identities that can reach any data at all can reach sensitive data. This is not an anomaly waiting to be cleaned up. It is how modern work gets done, and it is why access reviews alone never finish the job.

Complex data plus inherited wide access is not a problem one control can solve. Pruning access narrows what an agent can reach, but a useful agent still needs real data to do real work. Runtime inspection governs the access that remains, checking every retrieval and blocking sensitive data at the moment it moves. The two controls work together: posture determines what an agent should reach, and runtime control governs what it does with that reach.

How Agent DLP Delivers Runtime AI Governance
ArgusAI already gives enterprises proactive posture, a single inventory of every agent across major platforms, a map of exactly which data stores each agent can access, natural-language data access policies, and detection of misconfigured or missing guardrails. Agent DLP closes the loop by enforcing those same policies at the moment data moves, so intent and enforcement never drift apart.

This is what regulators are now asking for. The EU AI Act, state-level AI rules in Colorado and California, and the ISO/IEC 42001 all require enterprises to demonstrate what their systems did and why. An agent that violates policy because no enforcement existed is still a violation. Intent without runtime enforcement doesn't satisfy that requirement.

“Companies pulling ahead with AI are those who treat their data as a leadership priority, not a technical detail. Command of your own data and adoption of AI is what separates the winners from everyone still watching. That is a conversation for the CEO and the board, and it is the one I have most often right now,” said Vladimir Lukic, Managing Director, Senior Partner and Global Leader of the Tech and Digital Advantage practice at the Boston Consulting Group. “We use Bedrock Data at BCG to solve these problems for ourselves, so when we tell clients that command of their data comes first, we are speaking from experience.”

Traditional DLP cannot meet this bar. It was built for people (e.g., employees moving files across email, endpoints and cloud apps) and has no view into an agent’s tool calls and retrievals and no way to keep pace with machine-speed data movement. Agent DLP applies the same discipline at the layer where agent data actually moves, checking every tool request and response against the enterprise’s own data classifications and access policies. Specifically, Agent DLP:

  • Sits inline at the agent gateway via native hooks for AWS AgentCore and LiteLLM, inspecting agent traffic without acting as a proxy or gateway itself.
  • Inspects traffic in both directions, what agents send to MCP tools and what those tools return, to mask, redact or block agent actions that violate governance policy before sensitive data exposure can occur.
  • Logs every decision. Each tool call is recorded with its target, action, data types involved, and verdict (blocked, modified, redacted, or observed), producing a continuous, audit-ready record of what every agent actually did.

In practice, a customer-support agent’s get_customer call returning an address, card number, and SSN is blocked on the spot. A marketing agent’s query returning customer emails is logged in observe mode. Routine lower-risk calls pass through untouched.

Availability
Agent DLP is available immediately. Deployment is via a Bedrock Data-provided stack that customers set inline at the agent gateway, with native hooks for AWS AgentCore and LiteLLM.

Bedrock Data on Runtime AI Governance at Black Hat USA 2026
Bedrock Data will present its approach to data-first agent governance at Black Hat USA 2026, August 1-6 in Las Vegas.

¹ Gartner, “Market Guide for AI Trust, Risk and Security Management,” by Avivah Litan, Max Goss, Sumit Agarwal, Jeremy DHoinne, Andrew Bales and Bart Willemsen, 18 February 2025.

Resources

About Bedrock Data
Bedrock Data is a data security and AI governance platform that serves as the enterprise’s Data Context System of Record. It autonomously discovers, classifies and contextualizes sensitive data across cloud, IaaS, PaaS, SaaS and AI environments at petabyte scale, in place, without moving data outside customer boundaries. The result is a continuously updated, authoritative picture of data sensitivity, access, lineage, and business context, distributed as truth across every tool in the enterprise stack. Powered by its patented Metadata Lake and Serverless Outpost architecture, its open, API-first design enables natural-language policy enforcement, AI governance and automated remediation at enterprise scale. Security, data, infrastructure and AI leaders in technology, finance, healthcare and biotech rely on Bedrock Data to secure their data and accelerate AI without increasing risk. Learn more at bedrockdata.ai.


Contacts

Media contact:
Bhava Communications
Pam Njissang
bedrockdata@bhavacom.com