TLDRocket
Sign in

Ethyca launches Astralis to govern enterprise AI agents in real time

SiliconANGLE Duncan Riley

Ethyca launched Astralis, a system that watches AI agents in real time and blocks them from misusing company data. Compliance teams can't keep up with AI agents multiplying by the thousands, so software is stepping in.

Enterprises love deploying AI agents. They love auditing them a lot less. Ethyca, the privacy engineering firm behind clients like The New York Times and Ramp, thinks it has found the gap between those two facts and built a business around closing it. The company launched Astralis today, a platform designed to watch what AI agents do with corporate data as it happens, rather than checking in on them every quarter and hoping nothing broke in between.

The numbers behind the pitch are stark. Gartner expects the average Fortune 500 company to run more than 150,000 AI agents by 2028, up from under 15 last year. That is not a gradual climb, it's a cliff, and most legal and compliance teams are still staffed and structured for a world of periodic reviews and manual sign-offs. Ethyca argues this mismatch is exactly why so many AI projects get stuck in pilot purgatory: nobody can say with confidence why a given system touched a given dataset, and regulators are increasingly the ones asking.

Astralis attacks the problem from two angles. One piece, which Ethyca calls its Large Language Regulatory Model, automates privacy and AI impact assessments that used to eat 40 to 60 hours of staff time and now reportedly take 20 to 40 minutes. The other, a Purpose-Based Access Control engine, sits in front of data requests and checks that each one matches the reason it was originally approved for, rather than just checking whether someone technically has access. Together they're pitched as a live nervous system for data governance instead of a filing cabinet full of stale assessments.

Crucially, the whole thing runs inside a customer's own cloud, so the sensitive data being governed never has to leave the building to be governed. Ethyca says one large U.S. financial institution is already pushing 6,000 requests per second through the platform, translating into hundreds of millions of governed decisions a month. That's the kind of volume no team of human reviewers was ever going to handle, no matter how many people got hired.

CEO Cillian Kieran frames this bluntly: risk teams handling thousands of requests today will be handling millions soon, and automation is the only realistic answer. Julie Brill, a former FTC commissioner and Ethyca board member, makes the more strategic case, that companies which wire governance into their data infrastructure now will end up treating compliance as the foundation AI runs on, not the obstacle course it has to clear first. Given how fast the U.S. and EU keep rewriting AI rules underneath everyone's feet, that reframing might matter more than the product specs themselves.

My take

The agent-count math here is the real story, not the product demo. Once a company is running six figures worth of autonomous agents, manual compliance reviews stop being a process and start being theater, so betting on automated, real-time governance is less a bold move than an inevitable one. The bigger question nobody's asking yet is what happens when the governance layer itself becomes the thing regulators start scrutinizing, because a black box that polices other black boxes is still a black box.

Read more about this at: SiliconANGLE

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.