Mimecast targets AI agent sprawl with new risk and threat tools
Mimecast, the London-founded email and human-risk security firm, used its Black Hat USA 2026 appearance to launch two platform additions aimed squarely at a problem that is accelerating across every sector: the proliferation of AI agents operating inside enterprise environments without adequate oversight.
The company unveiled the beta of its Agent Risk Center alongside a redesigned 24/7 Managed Threat Response service. Both products respond to a security posture that has been structurally weakened by the pace of AI adoption. Mimecast's own analysis finds that 98% of organisations already have unsanctioned AI tools active on their networks, a figure that squares with broader enterprise AI surveys from Gartner and others. The company projects that, by 2029, more than a billion agents will collectively execute some 217 billion daily actions on behalf of employees, the vast majority of them operating outside the line of sight of existing security tooling.
The visibility gap at the centre of agentic AI
The Agent Risk Center is designed to give security and risk teams a single, real-time inventory of every AI tool and connection in their environment, regardless of whether that tool was formally sanctioned by IT. Rob Juncker, Mimecast's Chief Technology and Product Officer, framed the challenge plainly: "Most organisations don't know what agents are running in their environment, what data they're touching, or who's accountable when something goes wrong."
The product extends Mimecast's existing insider-risk model to non-human actors, applying the same policy and governance controls the company already uses for human employees. A built-in AI Rulebook allows security teams to classify and enforce policy by department without additional deployment overhead, while response controls include desktop app blocking, browser upload and paste blocking, and in-context user nudges. The Agent Risk Center enters beta as a free opt-in for existing Incydr subscription customers, with early access targeted for September 2026 and general availability planned for January 2027.
The Managed Threat Response service addresses a separate but related problem: alert fatigue. Mimecast cites research suggesting that 42% of security alerts go entirely uninvestigated. Under the new service, every user-reported email is triaged by Mimecast's AI layer, with confirmed threats passed to human analysts in its Security Operations Centre for remediation. Critically, the detection logic improves continuously as confirmed threats are identified across Mimecast's 42,000-customer base, creating a feedback loop that compounds over time.
Convergence implications: security as the hidden cost of AI adoption
The Mimecast announcements sit within a wider structural shift that carries real cross-sector consequence. As AI agents become embedded in enterprise workflows spanning financial services, healthcare, logistics, and legal operations, the attack surface they create does not stay confined to any one industry. A misconfigured agent with access to a financial institution's trading data or a healthcare provider's patient records represents a systemic risk, not merely an IT department's problem.
For capital allocators, the agentic AI security space is emerging as one of the more durable sub-categories of enterprise cybersecurity spend. Legacy perimeter defence budgets are already being reallocated towards identity, behaviour, and now agent governance. Mimecast competes in this space alongside CrowdStrike, Palo Alto Networks, and a growing cluster of pure-play AI-security startups attracting venture backing. The managed-service wrapper Mimecast is deploying also reflects a broader industry recognition that the talent shortage in security operations is structural: automation paired with expert oversight is increasingly the only scalable model.
For boards and C-suites, the deeper implication is that AI adoption strategies and security strategies, long managed in separate organisational silos, are now inseparable. Every agent a company deploys to accelerate revenue generation simultaneously enlarges the footprint that adversaries can exploit. The Agent Risk Center's beta launch is a signal that the market for governing this expanded footprint is maturing from a niche concern into a mainstream enterprise requirement.