Drata Ships AI Agent Governance. The MCP Proxy Still Can't Stop a Browser Tab.

Drata governs agent tool calls. The browser is still open.

By Containment.ai Research  ·  Published August 11, 2026  ·  Product status: Trust page →
One control plane, three moments of risk. The same deterministic discipline governs three boundaries: the human prompt (AI Chat Firewall, between an employee and the AI provider), the agent action (Agent Governance, between an agent and a tool or system), and the mission boundary (Mission Authorization Gateway, between an AI system and an edge, domain, or OT environment). All three run intercept, canonicalize, evaluate, enforce, audit.
FIG. A — ONE ENFORCEMENT LAYER, THREE MOMENTS OF RISKCONTAINMENT.AI

On August 4, 2026, Drata announced the Limited Availability of AI Agent Governance — a product designed to discover, monitor, govern, and prove traceability of the AI agents running inside an enterprise. The announcement named the architecture publicly for the first time: a device-level sensor that watches AI activity on managed endpoints, an MCP Proxy that evaluates each agent tool call against policy, and telemetry designed to create a tamper-evident evidence feed. The initial rollout covers Anthropic, with OpenAI, Google Vertex AI, and AWS Bedrock in active development.

For enterprise security teams, this is a meaningful capability. For defense primes and aerospace OEMs operating under CMMC and DoD AI policy, it is worth reading carefully — because what the architecture governs and what a cleared engineer actually does are not the same thing.

What the MCP Proxy Covers

Drata's three-layer architecture is designed around a specific threat model: AI agents that your organization builds, deploys, and operates — agents that make tool calls, access systems, and act on behalf of human principals inside a controlled environment. The MCP Proxy sits in that path, evaluates tool calls against policy, and creates an evidence record. That is a real and important control.

The device sensor complements it: it watches AI activity on managed endpoints, captures telemetry, and feeds a tamper-evident evidence log. If an agent inside your organization's boundary does something it shouldn't, Drata's architecture is designed to see it, flag it, and prove it happened.

This is agent governance at the workload layer. Drata is right that enterprises need it.

What It Doesn't Cover

The architecture has a boundary. It governs agents that your organization controls. It does not govern what a cleared engineer types into ChatGPT, Claude, or any other frontier model directly in a browser tab.

That distinction matters more in defense than in any other sector. A CMMC-scoped contractor has cleared employees with access to Controlled Unclassified Information (CUI). When one of those employees opens a browser and types a technical specification, a contract summary, or a draft proposal into a commercial AI interface, no agent inventory sees it. No MCP Proxy evaluates the request. No tamper-evident telemetry captures what left the boundary.

Agent governance and point-of-use enforcement are different problems, solved at different layers. The MCP Proxy is upstream of the browser. The browser is downstream of everything.

The Defense-Specific Gap

For most enterprise buyers, this distinction is academic today. Most data-loss-via-AI incidents involve agents, not humans manually typing sensitive content into commercial tools. Drata is solving the right problem for the majority of its 8,500+ customers.

For defense primes, the calculus is different. CMMC Level 2 and Level 3 obligations attach to CUI, not to the vector by which it moves. A cleared engineer typing a propulsion subsystem specification into Claude.ai is a boundary event regardless of whether an agent was involved. The auditable question is not "did an agent tool call execute against policy" — it is "did controlled technical data cross a boundary into a system outside the organization's certified environment."

That question requires enforcement at the point of use, not at the agent workload layer.

Two Layers, Not One

None of this is a criticism of Drata's design. Agent governance is a real category and Drata is building serious infrastructure for it. The mistake is assuming that buying the agent-governance layer covers the browser-boundary problem — because it doesn't, and for a defense prime, that gap has CMMC audit consequences.

The right architecture for a defense prime is two layers: an agent governance solution that monitors, inventories, and enforces policy on the agents your organization builds and operates; and a point-of-use enforcement layer that sits between the managed endpoint and any external AI surface — including frontier models accessed directly in a browser tab.

The Mission Authorization Gateway addresses the second layer: deterministic, non-bypassable enforcement at the boundary, with a signed decision receipt for every request, before data leaves the controlled environment. It does not replace agent governance. It covers what agent governance cannot see.

For the DoD prime security lead evaluating Drata's August 4 launch: the question is not whether to buy agent governance. The question is what you're buying in addition to it.


Drata's AI Agent Governance Limited Availability was announced August 4, 2026. Architecture details are from Drata's own announcement and Security Boulevard's coverage of the same event. The CMMC and DoD AI policy context is the reader's responsibility to verify against their specific program requirements — this post is not legal or compliance advice.

READY TO CLOSE THE GAP?
Deterministic AI governance for regulated and mission environments.
Request a 30-minute Boundary Review → Apply to the Design Partner Program → Keep controlled data out of public AI →