Guozhen AIGlobal AI field notes and model intelligence

Realtime AI News

Bedrock Data launches Agent DLP to police data flowing through AI agents

Bedrock Data has launched Agent DLP, a data loss prevention product for AI agents that inspects every request and response an agent exchanges with software tools and applies access and regulatory policies in real time. The launch is backed by research showing machine identities used by agents typically hold far broader access to company data than human employees.

Published
Bedrock Data 推出 Agent DLP:为 AI 智能体装上实时数据防泄漏闸门
Image source: aws.amazon.com

Bedrock Data has launched Agent DLP, a data loss prevention product built for AI agents, alongside research suggesting those agents often start with far broader access to company data than human employees. The product is part of Bedrock Data's ArgusAI platform and is designed to inspect data moving in and out of AI agents while they operate.

Agent DLP checks every request an agent sends to a software tool and every response it receives, then applies data access and regulatory policies in real time. Rather than acting as a separate proxy or gateway, it inspects traffic inline through native hooks for AWS AgentCore and LiteLLM. Depending on the policy, it can block, modify, redact or simply observe actions, and it logs each decision with the target, action, data types involved and the verdict, creating an audit trail of what an agent did and what data it touched.

The research behind the launch drew on anonymised telemetry spanning more than 70 petabytes of data, nearly 180,000 datastores and more than 540,000 identities across technology, finance and healthcare environments. It found that the median application or service account could reach 55 datastores, compared with 3 to 4 for the median employee, and that 79% of non-human identities could reach stored secrets such as API keys and tokens.

Across all identity types, 81% of identities with access to any data could also access sensitive data, suggesting broad exposure is built into many enterprise systems rather than caused by isolated misconfigurations. Because AI agents typically authenticate through existing machine identities, an agent becomes a data risk as soon as it is deployed, without any new permissions, inheriting the access already attached to the account behind it.

Traditional data loss prevention tools have focused on human activity, such as moving files through email, endpoints or cloud applications, which does not map neatly to agents that interact through software tool calls at machine speed. Agent DLP sits at the agent gateway to close that gap. In one example, a customer support agent calling a tool to retrieve customer details would have the action blocked immediately if the response contained an address, card number and Social Security number, while a marketing agent query returning customer email addresses could be allowed in observe-only mode for monitoring.

Bedrock Data linked the launch to growing regulatory scrutiny of AI governance, citing rules and standards including the EU AI Act, state-level AI measures in Colorado and California, and ISO/IEC 42001, which require organisations to show what their systems did and why. It also cited a Gartner projection that through 2026, at least 80% of unauthorised AI transactions would stem from internal policy violations rather than external attacks, implying the main risk lies less in hackers breaching AI systems than in organisations failing to control what their own automated agents are allowed to do.

CEO and co-founder Bruno Kurtic framed the product as a strategic shift: a decade from now, the companies that win with AI will be the ones that put their most valuable data to work through agents, and governance at runtime is what turns AI from a risk conversation into a growth strategy. Boston Consulting Group also confirmed it uses Bedrock Data internally to solve these problems for itself.

Why it matters

Agent DLP extends data loss prevention from human users to machine identities, targeting the permission-inheritance risk that is easy to overlook when enterprises deploy AI agents, and aligning with auditability demands from the EU AI Act and similar regulations.

Bedrock DataAI AgentData Security
Back to realtime news

Nearby Updates

All