Skip to content

Exabeam Delivers First Configurable Peer Benchmarking for CISO Decision-Making — Read the Release

Securing the Future of Work: Agent Behavior Analytics with Google Cloud

  • Sep 09, 2025
  • Steve Wilson
  • 2 minutes to read

Table of Contents

    Exabeam recently announced the first stage of our initiative for Agent Behavior Analytics, developed in partnership with Google Cloud. You can read the full press release here. This marks an important step in a new direction: while we’ve already invested in AI agents for cybersecurity through Exabeam Nova, we’re now extending that expertise into cybersecurity for the AI agents our customers are now building and deploying.

    The Business Problem: AI Agents as Insiders

    AI agents have officially joined the workforce. From packaged copilots to custom-built assistants, these systems are logging into applications, accessing sensitive data, and making decisions at scale. This rapid adoption introduces a new security challenge: AI agents as insiders. They’ve become digital employees — but unlike people, they don’t understand ethics, context, or consequence. That lack of judgment introduces a new type of insider risk.

    Traditional insider threats were already challenging. Now AI agents add entirely new categories:

    • Malfunctioning agents that behave unpredictably.
    • Misaligned agents that follow flawed prompts into compliance or privacy issues.
    • Hijacked or Jail Broken agents that can be weaponized against the business.

    Exabeam research shows 93% of organizations have either experienced or anticipate a rise in insider threats driven by AI, and 64% rank insiders — human and digital — above external attackers as their top concern. The risk is accelerating faster than most leadership teams expect.

    The Solution: Closing the Visibility Gap

    Most security tools weren’t built for AI-driven activity. SIEM and XDR lack the ability to baseline normal behavior and detect when an agent is drifting from its intended role or are being manipulated into misuse. This creates blind spots where AI agents can act outside their purpose without detection.

    This is where Exabeam is breaking new ground. Building on our proven behavioral analytics for human insiders, we’re extending our capabilities to cover AI agents. Through our partnership with Google Cloud, the New-Scale Security Operations Platform now ingests telemetry from Google Agentspace, Google Model Armor, and custom agents built with Vertex AI or Agent Builder. This enables us to baseline both human and AI activity together — surfacing anomalies in real time.

    Through Exabeam Nova, our multi-agent AI intelligence, analysts gain:

    • Visibility and risk scoring of both user and agent behavior
    • Real-time anomaly detection that distinguishes legitimate automation from risky behavior
    • Faster, more confident investigations and responses when things go wrong

    Building the Future of Agent Security

    This announcement is just the beginning. As AI agent technologies continue to grow, Exabeam is investing heavily in extending agent security to this new class of insider threat. In the coming months, you’ll see us:

    • Adding support to parse telemetry from other major agent frameworks in the market.
    • Extending our Common Information Model and user interface to capture the fine-grained relationships between users and their agents, as well as agent-to-agent interactions.
    • Advancing Exabeam Nova to interpret and explain increasingly complex AI behaviors.

    It’s an exciting time. The rise of AI agents is transforming how work gets done, and Exabeam is leading the way in ensuring those innovations are embraced securely, with the visibility and accountability enterprises need.

    Steve Wilson

    Steve Wilson

    Chief AI and Product Officer | Exabeam | Steve Wilson is Chief AI and Product Officer at Exabeam. Wilson leads product strategy, product management, product marketing, and research at Exabeam. He is a leader and innovator in AI, cybersecurity, and cloud computing, with over 20 years of experience leading high-performance teams to build mission-critical enterprise software and high-leverage platforms. Before joining Exabeam, he served as CPO at Contrast Security leading all aspects of product development, including strategy, product management, product marketing, product design, and engineering. Wilson has a proven track record of driving product transformation from on-premises legacy software to subscription-based SaaS business models including at Citrix, accounting for over $1 billion in ARR. He also has experience building software platforms at multi-billion dollar technology companies including Oracle and Sun Microsystems.

    More posts by Steve Wilson

    Learn More About Exabeam

    Learn about the Exabeam platform and expand your knowledge of information security with our collection of white papers, podcasts, webinars, and more.

    • Blog

      What’s New in LogRhythm SIEM October 2025

    • Blog

      What’s New with New-Scale in October 2025: Measurable, Automated, Everywhere Security Operations

    • Blog

      Catching the Quiet Threats: When Normal Isn’t Safe

    • Blog

      UEBA vs. XDR: Rethinking SIEM Augmentation in the AI Era

    • Blog

      How Exabeam Helps Organizations Adapt to Australia’s Privacy Reforms

    • White Paper

      Using MITRE ATT&CK® in Threat Hunting and Detection

    • Show More