The next chapter of the Mimecast Data Protection Platform starts now.
AI agents have become the ultimate insiders. Almost overnight, every employee has acquired a fleet of AI tools and agents acting on their behalf: Desktop assistants, GenAI LLMs, and MCP-connected agents that reach into GitHub, Salesforce, and production data at machine speed. Most of it is invisible to security. And insider risk continues to be expensive, with costs averaging $19.5 million annually for an organization.
If you’ve had insider incidents ask yourself the question we hear on nearly every call with prospective customers:
Can you see data exfiltration through AI agents, GenAI tools, endpoint, browser, and cloud, tied to the person behind it?
For years, a small, concentrated group of employees has driven most of human risk. Roughly 8% of people cause around 80% of incidents, and that reality has held steady for years. Those same people now operate at machine scale, with over a billion agents expected to perform hundreds of billions of actions a day by 2029. Just like insiders, their actions can be accidental, compromised, or malicious, and understanding the human behavior driving an agent is critical to being able to respond, at scale, to this growing risk surface.
The human-agent system is the real measure of risk
The unit of risk is not the agent in isolation. It is the human-agent system. Picture two employees whose agents pull the same large dataset from your CRM. Maya is a tenured finance leader with no suspicious exfiltration activity. David is a sales director who has been quietly moving files to personal accounts and devices. Same agent, same action, very different risk. From day one, ARC ties every agent to the human behind it. Mimecast’s risk scoring will separate those two agentic actions based on their behavioral profiles and flag the sales director’s activity.
One platform for humans, data, and AI
That is why we are expanding the Mimecast Data Protection Platform to protect your humans, your data, and your AI from one place. Incydr is the foundation, stopping insider data theft across endpoint, browser, and cloud, including shadow generative AI. With Agent Risk Center, we’re adding capabilities to govern the AI agents and workflows acting inside your environment. Together they make one platform, one risk model, and one set of adaptive controls that tighten as the human-agent risk to your data rises.
Today marks the first step. Agent Risk Center opens in Beta.
Agent Risk Center: See every agent & connection, then act
Agent Risk Center (ARC) enters Beta on July 31, 2026 as an opt-in program for Incydr customers or those looking to extend their data protection to AI (check out what to expect in an Incydr POV). It’s delivered through the Incydr endpoint agent and browser extension you already run, so there is nothing new to deploy. Turn it on and the inventory populates instantly.
Start with discovery. ARC catalogs every AI desktop application running across your organization and links each one to the people using it.
Agent Risk Center inventories the AI desktop apps running across the organization and ties each to the people using them. No policies required.
Discovery does not stop at applications. ARC surfaces the MCP connections quietly wiring agents into your systems, sanctioned and shadow alike. It pulls in copy/paste and uploads to GenAI tools as well, giving you the full AI picture across your organization and tied to every user.
The same inventory reveals the MCP servers connecting agents to systems like GitHub, Salesforce, and Slack.
Visibility only matters if you can focus it. The usage matrix breaks AI activity down by department, so you can prioritize where unsanctioned use concentrates instead of treating the whole organization the same. Our teams have consistently observed department-level trends for unsanctioned AI tools. On Monday the new tool one team member is using is adopted by half the department by the end of the week.
The usage matrix maps AI activity to departments, surfacing where risk concentrates first.
After visibility, you act. The AI Rulebook turns your acceptable use policy into a living, enforceable control. Classify each tool and connection as sanctioned or unsanctioned, scope that decision to the whole environment or a specific department, group, or individual, and block what should not be there. Add nudges in low-risk situations to drive behavior change and direct employees in the moment toward approved tools.
The AI Rulebook: classify a tool once, scope it to the right people, and enforce, with blocking and in-the-moment coaching built in.
Build a scalable data protection program for humans, data, and AI
Protecting humans, data, and AI should not require separate consoles, lengthy deployments, or loosely-integrated tools. The agentic risk surface will only expand as agents move toward billions of actions a day, and the programs that keep pace are the ones that ingest behavioral & organizational context already live across your human workforce.
Extending a program your team already runs is how you stay ahead of that curve without adding headcount: More than half of Incydr teams manage insider risk in under four hours a week and reach ROI in under six months, and that same efficiency now carries forward to the AI agents working alongside your people.
Most importantly though, Mimecast gives you one risk story for your CISO and board:
“Incydr helped us build a tight story around our insider threat program.” - Mario Durante, VP of Security, Snowflake.
If you’re an Incydr customer or would like to extend your data protection to AI, talk to your Mimecast account team or email incydr-product@mimecast.com to join the Beta program for Agent Risk Center.