Airlock Digital Wants to Watch What Your AI Assistant Actually Does, Not Just Whether It's Allowed to Run
A new product layer from Airlock Digital aims to track AI agents command by command, in real time, on the devices where they do their work.

Key points
- Airlock Digital announced a new product called Agentic AI Control & Governance at Black Hat USA 2026, targeting AI agents running on workplace computers.
- The Cloud Security Alliance reported in April 2026 that 82% of organisations had unknown AI agents running in their systems.
- 65% of those organisations experienced an AI-agent-related security incident in the 12 months prior to that April 2026 report.
- The product is expected to reach general availability for customers in Q3 2026.
- Airlock Digital, founded in Australia in 2013, sells software that controls which programs are allowed to run on a company's computers.
Most workplace security software asks one question: is this program allowed to run? Airlock Digital says that question is no longer enough.
The Australian security firm announced a new product layer called Agentic AI Control & Governance this week at Black Hat USA 2026 in Las Vegas. The target is AI agents, meaning software programs that act on a user's behalf, making decisions and taking actions on their own rather than waiting for a human to click a button. Think of a tool that can browse files, send emails, or book meetings without being told to do each step.
Why does this matter to ordinary workers?
If your workplace uses AI tools, there is a real chance some of those tools are running without your IT department's full knowledge. The Cloud Security Alliance, an industry body focused on computing security, found in April 2026 that 82% of organisations had unknown AI agents operating inside their systems. In the same period, 65% reported an AI-agent-related security incident.
That is the core problem Airlock Digital is trying to solve. Knowing a program exists on your network is one thing. Knowing what it is doing, file by file and command by command, is another.
How does the new product work?
Airlock Digital already sells application control software, which is a security tool that creates an approved list of programs and blocks everything not on it. The new product extends that idea to cover what an approved AI agent does after it starts running.
The product logs each command an AI agent attempts, checks it against a company's policy rules in real time, and tells the agent whether the action is permitted. Crucially, if an action is blocked, the system explains the boundary to the agent so it can try a different approach inside the rules, rather than simply failing and repeating the same blocked request.
A central dashboard records sessions, file interactions, token usage (the computing resource AI tools consume with each task), and cost.
| Feature area | What it does |
|---|---|
| Behaviour discovery | Logs AI agent commands and sessions automatically |
| Policy management | Central control with version history and admin permissions |
| Real-time evaluation | Checks each agent command against policy before it runs |
| Governance reporting | Searchable dashboard covering activity, risk, tokens, and cost |
| Availability | Customer general availability expected Q3 2026 |
"AI agents don't simply stop when an action is blocked; they evaluate alternatives and continue working toward their objective," said David Cottingham, co-founder and chief product officer at Airlock Digital.
What should employees and managers do now?
If your organisation uses AI productivity tools, ask your IT team whether those tools are inventoried and monitored. If the answer is unclear, that is itself useful information. You do not need to stop using the tools; you do need someone accountable for what they are doing on your systems. Policies governing what AI agents can touch, which files, which accounts, which external services, are worth writing down before an incident forces the conversation.



