Ent
by Ent
Reads user and AI-agent intent on the endpoint and intervenes before the risky action completes
Ent is an intent-aware workspace security platform that runs AI reasoning directly on the endpoint to evaluate what a user or an AI agent is actually trying to do, then applies policy through just-in-time interventions before the action completes. It sits alongside EDR rather than replacing it, and targets insider risk and AI-agent misuse.
Ent is an intent-aware workspace security platform that emerged from stealth on 16 June 2026 with a $100M seed round, one of the largest in cybersecurity history. It was founded by Elias Manousos and Brandon Dixon, who previously founded RiskIQ — acquired by Microsoft in 2021 — and then helped build Microsoft Security Copilot; the company is incorporated as Athena Formation Inc. The product is a lightweight endpoint agent for Windows, macOS and Linux, plus a browser extension, that runs AI reasoning locally rather than shipping telemetry away for post-hoc analysis. It observes behaviour across applications, browsers, workflows, data movement and local runtimes, evaluates whether human or AI-agent intent aligns with business objectives at the moment of use, applies customer-defined policy, and acts through configurable just-in-time interventions before an incident occurs. The premise is that conventional EDR and XDR are strong at catching malicious code after an action completes but weak on intent, insider risk and AI-augmented behaviour that looks entirely legitimate while it happens — so Ent positions itself as a new 'workspace security' layer between endpoint detection and the broader push to govern how employees and agents use enterprise systems, working alongside existing EDR, SIEM, SOAR and IAM rather than displacing them. Stated capabilities span insider-risk detection, AI usage governance, data loss prevention, last-mile threat prevention and incident investigation with behavioural context. It can be hosted by Ent or run inside the customer's own cloud for data sovereignty, is generally available, and is reported to be running inside Global 2000 organisations in hospitality, financial services and defence.
A CISO or insider-risk lead at a Global 2000 enterprise where employees and AI agents now have broad access to sensitive systems, and where the existing EDR stack catches malware but cannot answer whether a legitimate-looking action was actually aligned with the business.
Risky actions are interrupted at the moment of decision on the device, rather than investigated after the data has already left.
At a Glance
- Category
- Governance & Security
- Pricing
- Contact for pricing
- Target Market
- CISOs, CIOs, Security Operations Leads, Insider Risk Teams, Compliance Officers
- Deployment
- Hybrid, Self-hosted, Cloud-first
- Customers
- Reported to be running inside Global 2000 organisations across hospitality, financial services and defence; no customers named publicly
Key Features
- ✓On-device AI reasoning
Runs the model locally on the endpoint for low-latency, privacy-preserving evaluation, rather than shipping telemetry to a cloud for after-the-fact analysis.
- ✓Intent evaluation at the moment of use
Assesses whether a user or agent action aligns with business objectives while it is happening, which is the gap conventional post-breach detection leaves open.
- ✓Just-in-time interventions
Applies customer-defined policy through configurable interruptions before an action completes, turning detection into prevention at the decision point.
- ✓AI-agent behaviour governance
Treats autonomous agents as first-class subjects alongside humans, giving security teams a control point over what agents do on managed devices.
- ✓Cross-platform endpoint and browser coverage
Runs on Windows, macOS and Linux with a dedicated browser extension, covering the browser where most AI tool usage and data movement now happens.
- ✓Customer-hosted deployment option
Can run inside the customer's own cloud environment for complete data sovereignty, or be hosted by Ent, which matters for regulated and defence buyers.
- ✓Behavioural context for investigation
Retains the reasoning behind flagged actions so incident investigation starts with intent rather than reconstructing it from raw event logs.
Capabilities
Use Cases
- •Insider data exfiltration prevention
Interrupt a departing employee bulk-copying customer records at the moment of the copy, rather than finding it in an audit weeks later.
- •Governing employee AI tool usage
Detect and block sensitive data being pasted into unsanctioned AI assistants without banning the tools outright across the organisation.
- •Constraining autonomous agents on endpoints
Apply policy to what AI agents running on managed devices are permitted to read, move or execute on the user's behalf.
- •Last-mile threat prevention
Stop socially engineered but technically legitimate actions that malware-focused EDR cannot classify as malicious in the first place.
- •Intent-aware incident investigation
Review flagged events with the behavioural context already attached, shortening the reconstruction phase that dominates most insider investigations.
Ideal For
Best For
- ✓Insider-risk programmes where the threatening activity is authorised users doing authorised things for the wrong reason
- ✓Enterprises governing employee and agent use of AI tools, where the exposure is data pasted into a model rather than malware executed
- ✓Regulated environments that need reasoning to run on-device and hosting inside their own cloud for data sovereignty
- ✓Security teams that want a prevention layer alongside existing EDR, SIEM, SOAR and IAM rather than another rip-and-replace
- ✓Organisations deploying autonomous agents on employee endpoints and needing a control point for what those agents actually do
Not Ideal For
- ✗Buyers who need independent validation before purchase — no G2, Capterra or TrustRadius listing exists, Hacker News returns zero results, and no third-party efficacy testing against real-world attacks has been published
- ✗Teams looking to consolidate agents rather than add one: Ent is explicitly an additional layer alongside EDR/XDR, so it adds a second agent to endpoints that usually already carry several
- ✗Organisations that need published pricing or a self-serve evaluation path, since no pricing of any kind is disclosed and the vendor site publishes almost no product detail
- ✗Anyone seeking a full EDR replacement — the company positions the product as complementary, not as a consolidation play
- ✗Risk-averse buyers who require a multi-year track record, given the product only reached general availability in June 2026
Deployment
Market & Ratings
Reported to be running inside Global 2000 organisations across hospitality, financial services and defence; no customers named publicly
Market Analysis
Pros
- ✓Addresses a genuine and widening gap — EDR is built for malicious code, while insider risk and AI-agent misuse look legitimate right up until the damage is done
- ✓On-device reasoning enables intervention at the decision point instead of alerting after the fact, which is the difference between detection and prevention
- ✓Customer-cloud hosting with full data sovereignty is a serious option for regulated, defence and financial buyers
- ✓Founders have an exit track record in exactly this domain, and In-Q-Tel's participation signals government and defence interest
- ✓Complements rather than replaces the incumbent stack, which removes the biggest objection to adopting a new endpoint vendor
Cons
- ✗There is effectively no independent evidence to evaluate: no G2, Capterra or TrustRadius listing, zero Hacker News discussion, no named customers, no case studies and no third-party efficacy testing against real attacks
- ✗The vendor's own website publishes almost nothing beyond a tagline, so every technical detail here comes from launch press rather than documentation a buyer could review
- ✗It adds another agent to endpoints that typically already carry EDR, DLP and management agents, and the performance cost of running local model inference on every user device is undisclosed
- ✗Intent inference is inherently probabilistic — a false positive interrupts legitimate work in real time, which is a far more disruptive failure mode than a noisy alert queue
- ✗No published pricing, no trial and no self-serve path means evaluation requires a full enterprise sales engagement
- ✗The product reached general availability only in June 2026, so all deployments are early and none of the scale claims are independently verifiable
Pricing
Enterprise
Contact for pricing
- ✓Endpoint agent for Windows, macOS and Linux plus browser extension
- ✓On-device intent reasoning and just-in-time interventions
- ✓Insider risk, AI usage governance and data loss prevention
- ✓Hosted by Ent or deployed in the customer's own cloud
- ✓Works alongside existing EDR, SIEM, SOAR and IAM
Nothing about pricing is public — no rate card, no tiers, no per-endpoint or per-seat figure, no free trial and no self-serve path, and neither the launch press release nor the independent coverage disclosed a commercial model. Deals are direct enterprise sales into Global 2000 accounts, and the company said the $100M seed is funding go-to-market hiring, which suggests a sales-led motion rather than product-led adoption. Expect endpoint security norms — per-endpoint annual subscription with volume tiers — but that is an expectation, not a published fact. The choice between Ent-hosted and customer-cloud deployment is likely to be a pricing variable for regulated buyers.
Security & Compliance
Sources
This page was written from 5 sources, 4 on domains other than ent.ai.
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
DeepKeep
AI security platform covering red teaming, an AI firewall, agent attack-surface scanning and runtime controls for coding agents
Armadin
Autonomous offensive security: AI agent swarms that chain your weak spots into proven attack paths before an attacker does
WitnessAI
Network-layer AI security and governance for employee AI use, models, apps and agents
Ascerta
Enterprise AI management: measure the ROI, cost and adoption of every AI initiative, agent and coding tool