Glean Tackles Shadow Agents and Enterprise AI Governance
Shadow Agents Raise the Stakes for Enterprise AI
Alan Shimel speaks with Sunil Agrawal, chief security officer at Glean, during Techstrong TV’s Black Hat 2026 coverage. The discussion focuses on enterprise AI governance and the new risks created by agentic AI. Agrawal explains that Glean began as enterprise search, evolved into a ChatGPT-style assistant for internal knowledge and is now focused on helping companies build secure AI agents.
That shift changes the security conversation. Shadow AI was already a challenge for many organizations. Now, Agrawal says enterprises also need to think about shadow agents. Employees may build or run agents without enough oversight. Those agents can access data, invoke tools and take actions faster than traditional governance models can track.
Approved AI Platforms Can Reduce Risk
Agrawal argues that enterprise AI governance starts with giving employees a better approved option. If workers can use a secure internal platform that delivers strong AI results, they have less reason to send proprietary data to public tools. Glean’s approach is to combine enterprise search, retrieval-augmented generation and model flexibility inside a governed platform.
That matters because employees often upload sensitive documents, source code or business data when they ask AI systems for help. In an enterprise AI governance model, that data should remain under company control. Agrawal says Glean helps by using indexed enterprise knowledge, approved model relationships and controls that prevent customer data from being used to train outside models.
The Agentic Harness Needs Security Controls
The conversation also breaks down the idea of an agentic harness. Agrawal compares the LLM to the brain of an agent. The harness gives that brain tools, memory, skills and access to enterprise context. Those pieces make AI more useful, but they also expand the risk surface.
For security teams, the goal is not to block AI adoption. It is to make approved agentic AI safer and easier to use than unmanaged alternatives. That means setting policies around who can build agents, what data they can reach, what tools they can invoke and which actions need human approval.
Security Must Keep Pace With AI Scale
Agrawal also notes that attackers are using AI to shrink the time between vulnerability discovery and exploitation. Defenders need to operate at machine speed and AI scale. That requires visibility, governance and approved platforms that can support productivity without losing control.
For Techstrong TV viewers, the message is practical. Enterprise AI governance is no longer only about chatbots. It now includes agent behavior, tool use, data access and auditability. Glean is positioning its platform as a way to help organizations adopt AI agents while reducing the risks of shadow AI and shadow agents.