The thread
Four unrelated announcements this week share one assumption: AI systems are being deployed faster than the organisations using them can observe, contain or secure them. The response, across cybersecurity vendors, data platform vendors and even the AI labs themselves, is a new layer of control wrapped around models that were not built with that control in mind. That layer is where much of the enterprise AI business is now being fought.
Control as the product
Darktrace's general availability of SECURE AI, reported by SiliconANGLE, is the clearest statement of the thesis. The company is applying behavioural detection, the discipline it built for network traffic, to how employees and agents use AI tools. The detail that matters is scale: telemetry from roughly 8,200 customers feeds the system. That is not a point product bolted onto a console. It is an attempt to make AI usage legible to security teams that lost visibility the moment staff began pasting work into external models and wiring agents into internal systems.
Vast Data's DataEnclave, also reported by SiliconANGLE, attacks the same problem from the infrastructure side. It is a confidential computing environment inside the Vast DataEngine and AI Operating System, built on Nvidia confidential computing technology, designed to run advanced models against sensitive data without exposing either the data or the model's intellectual property. Where Darktrace watches behaviour, Vast constrains the environment. Both exist because the default deployment pattern, a model reading whatever it can reach, is no longer acceptable for regulated or competitive workloads.
The commercial logic is straightforward. If a bank cannot prove that a model never saw raw customer records, or that a proprietary model was not exfiltrated through its own inference path, the project stalls. Confidential computing and behavioural monitoring are the two practical answers available today, and vendors are now racing to make them standard rather than bespoke.
The agent is the weak point
The Meta story, reported by Ars Technica, shows what happens when that control layer is missing. Ars describes Muse, Meta's AI assistant, as extraordinarily privileged, and reports a serious zero-day in it, with a simple ClickFix attack cited as only one route to completely hijack the agent. The specifics are less important than the structure of the failure. An assistant with broad permissions across a user's accounts and data is, functionally, an insider with excellent credentials and no judgement. A single successful prompt or click can convert that privilege into full compromise.
This is the pattern the enterprise vendors are selling against. The agent is not a chatbot that occasionally says something wrong. It is a principal with rights, and the security industry has spent decades learning that privileged principals need monitoring, least privilege and containment. None of that was designed into the first generation of assistants. Muse is a consumer-facing product, but the same architecture is being copied into enterprise agents, which is precisely why Darktrace's telemetry and Vast's enclaves exist.



