KnowBe4 announced the launch of Agent Risk Manager on April 14, 2026, a defense system designed to secure, monitor, and govern the behavior of autonomous artificial intelligence agents. The product addresses a critical security gap that has emerged as workflows shift from AI-assisted to agent-managed operations.
The Agent Risk Manager arrives as part of the KnowBe4 HRM+ platform, which helps organizations quantify and mitigate risks from both human and AI workforces. Greg Kras, chief product officer at KnowBe4, stated that while the industry has spent years securing human elements, AI agents now represent the newest members of the workforce. “Securing the prompt is only half the battle,” Kras said. “Our Agent Risk Manager focuses on the output and actions of these agents, ensuring that as they move through your network, they do not become the ultimate shadow IT or a backdoor for sophisticated prompt injection attacks.”
Key Features of Agent Risk Manager
The platform provides a real-time operational layer that governs how agents behave once deployed. Behavioral guardrails monitor agent actions in real time to prevent unauthorized data exfiltration or jailbroken autonomous execution. The system identifies access permissions and tools available to each agent through agentic identity governance.
Agent Risk Manager includes adversarial simulation capabilities that stress-test AI agents against the latest prompt injection and social engineering tactics used by attackers. The system draws on 15 years of behavior data to predict when an agent deviates from safe operating parameters, according to the company.
Operational Capabilities
The solution offers prompt injection detection using machine learning to identify jailbreaks, logic overrides, and indirect injections across user messages and tool outputs. Sensitive information detection uses more than 20 classifiers to scan for personally identifiable information and credentials, automatically redacting sensitive data before it reaches the audit log.
Unbounded consumption detection monitors for resource abuse and runaway agents to prevent excessive API calls, data queries, and compute costs. The agent inventory feature automatically catalogs agents and tools across multiple tenants without manual input, tracking tool definitions and activity timestamps. A compliance-ready audit log records all agent actions and detections, designed for rapid incident response and forensic review.
Integration and Deployment
Integration management provides centralized lifecycle management for multiple tenants with automatic connectivity and permissions validation. Guided onboarding delivers a streamlined setup process that achieves first-agent discovery in minutes without requiring professional services, according to KnowBe4.
The launch aligns with Identity Management Day, which this year carries the theme “Finding Identity: The Search for You, Me, and the Machines.” The theme underscores the need to secure not just human identities but also the agentic identities of AI systems. KnowBe4 stated that the Agent Risk Manager will be made available globally. The company serves more than 70,000 organizations worldwide and offers a comprehensive platform for human risk management that includes awareness training, integrated cloud email security, real-time coaching, crowdsourced anti-phishing, and AI defense agents.
“We are moving from a world of human risk to universal risk. Whether it is a human being tricked by a deepfake or an AI agent being manipulated by a malicious prompt, KnowBe4 is the only platform capable of defending both.”
Greg Kras, Chief Product Officer, KnowBe4





