Press Release

April 14, 2023 11:42 AM

Updated statement regarding LockBit claims

Mike Beck, Chief Information Security Officer, Darktrace

We have completed a thorough security investigation following yesterday’s tweets by LockBit claiming they had compromised Darktrace’s internal systems. We can confirm that there has been no compromise of our systems or any of our affiliate systems. Our service to our customers remains uninterrupted and is operating as normal and no further action is required.

Press Release

April 13, 2023 9:30 AM

Statement regarding LockBit claims

Earlier this morning we became aware of tweets from LockBit, the cyber-criminal gang, claiming that they had compromised Darktrace’s internal security systems and had accessed our data. Our security teams have run a full review of our internal systems and can see no evidence of compromise. None of the LockBit social media posts link to any compromised Darktrace data. We will continue to monitor the situation extremely closely, but based on our current investigations we are confident that our systems remain secure and all customer data is fully protected.


Press Release

Darktrace Extends Behavioral Security to Help Customers Safely Adopt Enterprise AI with General Availability of Darktrace / SECURE AI™

Cambridge, UK
September 22, 2026
  • AI adoption is moving faster than security teams can keep pace with, and generative AI use is now widespread: over 80% of Darktrace's customers now use generative AI services, and in August the average organization interacted with five different AI providers.
  • Early adopters of Darktrace / SECURE AI pointed to shadow AI detection, policy management, and prompt analysis as the use cases delivering immediate business value.
  • The general availability of Darktrace / SECURE AI includes integrations with Amazon Web Services (AWS), Anthropic, Microsoft and OpenAI, among others, to support prompt analysis and shadow AI detection across enterprise AI platforms.  

Darktrace, a global leader in behavioral security, today announced the general availability of Darktrace / SECURE AI™, giving enterprises the visibility, contextual understanding, governance and response capabilities needed to securely scale AI adoption. The solution is designed to deploy easily and rapidly, and enables organizations to discover AI use, understand how people and agents are behaving in real time, assess whether activity remains aligned with policy and intended purpose, and take action when risks emerge.

Enterprise AI adoption is now both widespread and fragmented. Over 80% of Darktrace’s customers now use generative AI services, and the average organization interacted with five different AI providers in August 2026 [1].  

Early adopter deployments showed how quickly AI activity moves beyond what security teams expect, across tools, users and business use cases.  

  • At one organization that had approved the use of a single AI assistant, Darktrace / SECURE AI discovered that a majority of employees were using unauthorized AI services, exposing a significant gap between policy and practice.
  • At another organization, Darktrace / SECURE AI uncovered unmanaged contractor use of multiple AI platforms, revealing a previously unknown risk vector. This prompted an immediate legal review and the implementation of formal AI governance controls.
  • Another organization identified nearly 90 AI agents operating within a low-code development environment with no formal approval process or oversight for agent creation, highlighting the rapid emergence of shadow AI across the enterprise.

As AI agents gain access to identities, data, applications and infrastructure, the challenge goes beyond uncovering AI use: security teams also need to know whether that behavior remains aligned with policy, intended purpose, and the normal operating pattern of the organization.

Darktrace was built for this shift. Its proprietary Adaptive AI™ learns what is normal for each organization and continuously evaluates behavior in that unique context, allowing security teams to detect emerging risk even when the activity has never been seen before. Darktrace / SECURE AI extends this behavioral approach to prompts, users, agents and AI systems, combining real-time visibility, policy governance and the ability to act when risk emerges so enterprises can move AI from experimentation to production securely and with confidence.  

“Darktrace / SECURE AI has given us a clearer view of AI activity across the organization, including the tools employees are using and the types of data appearing in prompts,” said Matthew Davis, Chief Information Security Officer at ESL Federal Credit Union. “That visibility helps us understand where use falls outside our approved services, guide employees toward the right tools and make more informed decisions about licensing and education as adoption grows.”

“As we worked to develop our AI usage policy, we realized we were making decisions without a clear understanding of how employees were actually using these tools,” said David Green, Senior Vice President of IT at Lamons. “Darktrace / SECURE AI showed us that AI was already helping people work more effectively across the business, and that insight changed our approach. We can now shape policy around real behavior, protecting company data while giving employees room to use AI productively. That has given us the confidence to keep moving quickly on AI.”

“Working with cybersecurity partners like Darktrace is critical to translating advances in AI into stronger, practical defenses. Together, we are supporting organizations as they adopt AI securely and giving defenders new ways to understand and respond to risk,” said McCall McIntyre, Head of Global Cyber Partnerships, OpenAI

Behavioral Defense for Enterprise AI Adoption

Darktrace / SECURE AI gives security teams a broad, integrated approach to the safe adoption of enterprise AI:

  • Shadow AI Management: Identifies unsanctioned AI activity through Darktrace telemetry and SASE integrations including Microsoft Entra Global Secure Access with the ability to block unsanctioned AI usage or quarantine affected devices. It helps customers distinguish unauthorized usage from approved usage, eliminate blind spots, and improve policy to reduce data exposure and risk.
  • AI Prompt Analysis: Provides real-time visibility into prompts, sessions and responses across supported platforms, including Amazon Bedrock, ChatGPT Enterprise, Claude, Microsoft Copilot, Copilot Studio, with Salesforce support coming soon. It detects activity including attempted jailbreaks, sensitive data exposure and potential indirect prompt injection, while ranking sessions by risk to help analysts prioritize investigation.
  • Policy Management: Provides a free-form policy upload capability, which enables security teams to define organization-specific controls, evaluate policy effectiveness, and continuously refine governance beyond standard frameworks. When uploading a policy, administrators can review the enterprise policy against regulatory and compliance frameworks to help users track alignment.  
  • AI Agent Identities and Actions: Identifies agents and human users associated with AI activity across supported environments, providing visibility into their permissions, roles, access and relationships. This helps organizations understand how agents are being used, what they are connected to and whether their activity remains aligned with their intended purpose.  
  • AI Agent Development Risk Management: Extends visibility into low-code and high-code development environments and platforms, including Amazon Bedrock and Microsoft Copilot Studio. Security teams can identify agent identities, excessive permissions, misconfigurations and anomalous development activity, connecting how agents are built with how they behave once deployed.

Darktrace / SECURE AI is part of the Darktrace Behavioral Defense Platform™. Rather than relying primarily on static rules, signatures, or known indicators, the platform learns what is normal for each organization and builds a real-time understanding of behavior across each enterprise. It provides unified visibility, continuous behavioral monitoring, and autonomous response across AI, people, and infrastructure, helping security teams detect suspicious activity and contain it before it causes harm.

"The security industry spent the last twenty years cataloging known threats. AI breaks that model," said Ed Jennings, President and CEO of Darktrace. "As AI systems become more adaptive and autonomous, security must understand behavior as it unfolds. Darktrace was built around a behavioral approach: you won’t always know what the next attack looks like, but you can tell when something starts behaving differently from what is normal for the organization. Darktrace / SECURE AI applies that same approach to AI, helping security teams manage risk without slowing adoption. That’s what it means to secure what AI can do.”

Advancing Behavioral Security Across the AI Landscape

Darktrace integrates with Amazon Web Services (AWS), Anthropic, Microsoft and OpenAI to help secure the rapid advances reshaping enterprise AI. Through integrations between Darktrace / SECURE AI and the frontier models, agent frameworks, and development environments customers are adopting, these collaborations extend behavioral security across agents, low-code and high-code development, prompts and enterprise AI use.

Amazon Web Service (AWS): Darktrace extends behavioral visibility across the development and runtime activity of agents built with Amazon Bedrock, helping mutual customers connect how agents are built with how they behave after deployment.

Anthropic: Darktrace extends prompt security coverage to Claude, helping mutual customers evaluate prompt and response activity in the context of each organization and identify behavior that may conflict with policy or intended use.   

Microsoft: Darktrace extends behavioral understanding across Microsoft Copilot users and agents, including low-code development in Microsoft Copilot Studio. This gives customers additional context on how AI and agents behave across the wider enterprise, whether their activity remains aligned with policy and intended purpose, and when emerging risk requires action.  

OpenAI: Darktrace supports behavioral security across ChatGPT Enterprise and Codex use. Through the Daybreak Defense Network, Darktrace is developing capabilities that combine OpenAI’s Daybreak models with its behavioral understanding to identify security incidents involving enterprise AI and enrich cyber incidents with business context, helping defenders understand which users, systems and business processes are affected and prioritize their response.

Availability

Darktrace / SECURE AI is available now to new and existing Darktrace customers and can be purchased as:  

  • A standalone product or as part of the Darktrace Behavioral Defense Platform;
  • Through the Amazon Web Services (AWS) Marketplace; or  
  • Through the Microsoft Marketplace.  

Additional Resources:

About Darktrace

Darktrace secures the modern enterprise by protecting AI, people, and infrastructure with behavioral security. Founded in 2013, Darktrace uses Adaptive AI to understand what is normal for an organization and detect known, unknown and novel threats and respond autonomously in real time. The Darktrace Behavioral Defense Platform delivers unified visibility, continuous behavioral monitoring, and autonomous response across the enterprise. Darktrace protects nearly 10,000 customers across major industries globally, helping organizations defend against AI-powered threats across AI and agents, email and collaboration tools, and hybrid networks, while enabling them to innovate with AI securely.  

References

[1] Based on aggregated Darktrace product telemetry across a fleet of ~8,200 observed deployments, measuring generative AI service usage across accounts monitored in August 2026. The 80%+ figure reflects the share of monitored accounts with any generative AI service usage during the same period.  

News coverage
News publication logo

Darktrace Extends Behavioral Security to Help Customers Safely Adopt Enterprise AI with General Availability of Darktrace / SECURE AI™

September 22, 2026

cv
Darktrace named a Challenger in first Gartner® Magic Quadrant™ for Email Security Platforms ·      Evaluated on Completeness of Vision and Ability to Execute Darktrace, a global leader in AI for cybersecurity,today announces that Darktrace / EMAIL™, has been recognized in thefirst ever Gartner Magic Quadrant™ for Email Security Platforms (ESP) as a Challenger. Chris Kozup, Chief Marketing Officer, Darktrace, said of therecognition: “We are extremely proud to have been recognized in the first MagicQuadrant for ESP.  We believe the factthat wehave seen such wide scale adoption is testament to the unique way in which wedevelop products to keep our customers safe from even the most sophisticated emailcompromises. We believe our placement reaffirms our dedication to deliveringexceptional customer service, and innovations that safeguard against the emailchallenges of today—and tomorrow.” Darktrace customers consistently acknowledge its exceptional customersupport, delivered by an award-winning[1]service team. Darktrace has the highest percentage of 5-star ratings with a 4.8rating on Gartner® Peer Insights™ out of 249 reviews as on[MW1]  19th December. We feel this unwavering commitment to customersatisfaction is evident in strong renewal rates and accelerated growth inDarktrace / EMAIL over the past few years, gaining almost 5,000 customers sinceits launch in 2019. Darktrace / EMAIL, one of the fastest-growing emailsecurity products on the market, is built on Darktrace’s unique Self-LearningAI, a multi-layered AI engine that leverages different types of AI includingNLP and behavioral analysis to detect threats, instead of traditional securitymeasures such as signatures and sandboxing. This approach enables Darktrace todetect and stop threats like business email compromise attacks and noveltechniques, including some 56% of which passed through customers’ other emailsecurity layers. This pioneering approach has enabled Darktrace to introduce industry-leadingcapabilities such as QR code analysis and automated incident investigations, alongsidedifferentiated functionality to help teams add new depth to their emailsecurity, including: Account     take over and Lateral mail account compromise protection.     Contributing yet another layer to the AI behavioural profile for each     user, security teams can now spot early symptoms of account compromise or     malicious insiders before a link or attachment payload is sent, and     exfiltration occur   Microsoft Teams security with advanced messaging analysis: Advancing beyond simple text analysis to     behavioral and natural language content analysis that tracks context     across both email and instant messaging to identify the approximately 38% of     phishing, sophisticated social engineering and novel insider threats other     solutions fail to capture ·      Drastically improveend user reporting with Cyber AI Analyst narratives: Real-time awareness training capabilities reduce falsepositives in phishing investigations by up to 60% by providing context specificanalysis of each received email to each employee as they interact with their mail.·       MailboxSecurity Assistant to increase security team operational efficiency: All forms ofsecondary investigations can now automatically perform advanced behavioralbrowser analysis and stop malicious links within webpages, reducing manualeffort of security analysts to detecting phishing links, and allowing them to remediateup to 70% more malicious phishing links than before.·       AI based,autonomous data loss prevention: to immediately protect organizations from misdirected emails,insider threats, and data loss—both classified and unclassified – using userbehavior and dynamic content analysis to determine sensitivity, removing administrativeoverhead from manual expressions and labeling.Marco Cavallo, IT Manager at Darktrace / EMAIL customer Arpa Industries comments:“During the POV, Darktrace / EMAIL showed how specific attacks weresurgically blocked. We realized that other tools wouldn’t have detected thesethreats.” Darktrace / EMAIL is part of Darktrace’s ActiveAI Security Platform™,offering network, cloud, endpoint, identity and operational technologyprotection from a single shared architecture, all built on Darktrace’s uniqueAI engine – providing a strong, integrated approach to threat prevention,detection and response across an organization’s entire digital footprint. Darktrace’s global presence supports a diverse and varied customer base,and adapts proactively to customer pain points of all kinds. Darktrace’sadaptability across all market segments, from SMBs to large enterprisessupports both first time email security buyers and mature email securitystacks. It is able to meet varied security needs with lower setuprequirements, includes capability for advanced depth in configuration and,particularly for mature organizations, can augment existing security providerswith additional protections.   Download the fullMagic Quadrant for Email Security Platforms here Resources:·      Read more onthe Darktrace Blog·      Read more abouthow business email compromise attacks are evolving on The Inference  Gartner disclaimersGartner, Magic Quadrant for EmailSecurity Platforms, Max Taggett, Nikul Patel, Franz Hinner, Deepak Mishra, 16December 2024 GARTNER is a registered trademarkand service mark of Gartner and Magic Quadrant and Peer Insights are aregistered trademark, of Gartner, Inc. and/or its affiliates in the U.S. andinternationally and are used herein with permission. All rights reserved.
Gartner Peer Insights content consists of the opinions of individual endusers based on their own experiences with the vendors listed on the platform,should not be construed as statements of fact, nor do they represent the viewsof Gartner or its affiliates. Gartner does not endorse any vendor, product orservice depicted in this content nor makes any warranties, expressed orimplied, with respect to this content, about its accuracy or completeness,including any warranties of merchantability or fitness for a particularpurpose. Gartner does not endorse any vendor,product or service depicted in its research publications and does not advisetechnology users to select only those vendors with the highest ratings or otherdesignation. Gartner research publications consist of the opinions of Gartner’sresearch organization and should not be construed as statements of fact.Gartner disclaims all warranties, expressed or implied, with respect to thisresearch, including any warranties of merchantability or fitness for aparticular purpose.  About DarktraceDarktrace is a global leader in AI for cybersecurity that keepsorganizations ahead of the changing threat landscape every day. Founded in2013, Darktrace provides the essential cybersecurity platform protectingorganizations from unknown threats using its proprietary AI that learns fromthe unique patterns of life for each customer in real-time. The DarktraceActiveAI Security Platform™ delivers a proactive approach to cyber resiliencewith pre-emptive visibility into security posture, real-time threat detection,and autonomous response – securing the business across cloud, email,identities, operational technology, endpoints, and network. Breakthroughinnovations from our R&D teams in Cambridge, UK, and The Hague, Netherlandshave resulted in over 200 patent applications filed. Darktrace’s platform andservices are supported by over 2,400 employees around the world who protectnearly 10,000 customers across all major industries globally. To learn more,visit http://www.darktrace.com.   ---- 
[1] Darktrace wins two Globeeawards for excellent customer service [PressRelease] [MW1]shouldthis be 'of'

About Darktrace

Download
Download

Credit: Darktrace

Darktrace / SECURE AI™ provides visibility into AI usage across the business, helping security teams discover and control Shadow AI by surfacing unsanctioned or unexpected AI activity where it appears, helping to distinguish misuse of legitimate tools and unapproved services, and applying policy to contain data exposure.

Share this article
More Darktrace news