There is increasing pressure inside organizations for broader adoption of AI tooling. Executives want more of their technical and non-technical staff to start bulding with agents. The belief is that greater adoption of AI will improve productivity and create cost reduction opportunities (in terms of IT spend). This pressure is largely falling on technical executives responsible for managing internal codebases.
The pressure to adopt AI is outpacing the hardening of governance layers to secure it. A new category is emerging calling “Shadow IT”. This is when internal tools are spun up to solve problems that live outside the normal governance of internal IT teams.
“Technical leaders are under more pressure than ever to keep climbing towards internal AI adoption and enablement, but are now increasingly responsible for outcomes they can’t see or control…These technical leaders know something in governance is broken, and 55% say they want centralized platform-level governance to fix it.” -ReTool
Startups are emerging to sell into this void. They are targeting InfoSec teams and technical leaders with some version of the following value proposition: 1) we’ll connect to your existing stack, 2) deploy secure sandboxes directly from the spaces people work (e.g. endpoints), and 3) help you monitor and govern AI usage.
Here are three example companies:
- Asymptote / Beacon: Sells “endpoint telemetry for AI agents” that plugs into the stack security teams already understand: gateways, EDR, SIEM, and detection pipelines. The core premise is that security is now at the “endpoint”, or the space where users are interacting with agents.
- Amika: Runs any coding agent in a VM (cloud computer) that you control. They set guardrails that help teams “ship more code without flooding your reviews”. They connect to the spaces where teams collaborate: GitHub, Linear, and Slack.
- HQ: Focused on “shared context”. Surfaces how the team is using agents and brings the best into a visible space where everyone can operate.
Each of these offers some version of telemetry and a cloud-hosted solution that monitors how the team is using AI.
The early buyer seems to be InfoSec Teams. These teams rely upon Security Information & Event Management (SIEM) solutions to monitor the organization. These solutions aggregate, normalize, and analyze log + event data from across an organizations IT infra in real-time.
Here are some buying conditions for an InfoSec team:
- Visible AI agent usage on sensitive endpoints. Especially ones that leadership is nervous about.
- The tool maps to an existing category and budget line: endpoint telemetry, SIEM ingestion, etc.
- Integration into existing system (existing SIEM or data lake). Workflows that don’t ask them to standup something new and orthogonal.
Companies
Sources
Retool Blog The State of AI Governance in 2026