Article

AI governance platform Aicura releases shadow AI discovery and runtime guardrail enforcement

Aicura's August 2026 release adds shadow AI discovery and runtime guardrail enforcement, alongside security testing, monitoring and agent governance.

By Scott Goldie · 27 August 2026

MELBOURNE, 27 August 2026 — Aicura’s August release adds shadow AI discovery and runtime guardrail enforcement, alongside security testing, monitoring and agent governance. Security incidents involving shadow AI more than doubled in a year to 43 per cent and averaged US$5.39 million per breach, according to IBM’s Cost of a Data Breach Report 2026. In separate IBM research from June 2026, 77 per cent of technology executives reported AI adoption running ahead of their governance capability.

Shadow AI is the AI an organisation runs without knowing it. Staff sign up for tools with a work email, agents get wired into workflows during a sprint, and vendors switch on AI features inside platforms that were procured for something else. None of it appears in any record, and none of it was assessed by anyone. Aicura surfaces it from the traces it leaves in the systems an organisation already runs, across identity, devices, cloud, code and expenses, and a person decides what goes into the organisation’s register of AI systems, the inventory of what runs, who owns it and what it is allowed to do.

The gap between adoption and governance is where the losses land. Of the organisations breached in IBM’s 2026 study, 68 per cent had no AI governance policy in place, and among those with AI-related breaches, 92 per cent lacked proper AI access controls. Governance is how an organisation knows what AI it runs, understands the risks each system carries, decides what each is allowed to do, enforces those decisions where the AI operates, and can show all of it. Aicura’s August release closes the distance between deciding and doing. The controls that come out of assessing a system become guardrails, compiled into signed bundles and enforced in the request path, and every intervention is recorded as it happens.

“Governance built for deterministic software assumes behaviour holds after signoff, but AI doesn’t behave the same way twice. Aicura carries a steel thread from discovered system to risks, controls and the guardrails enforcing them, so organisations can see the AI they actually run and hold it to the decisions they actually made,” said Scott Goldie, founder of Aicura.

Aicura is live now. Plans and features are published at aicura.com.au/pricing/.

About Aicura

Aicura Pty Ltd is an Australian company based in Melbourne. It makes Aicura, an AI governance platform built to find the AI in use, assess what it carries, enforce the decisions and prove all of it happened. Discover. Assess. Enforce. Prove.

Media enquiries

[email protected]

See the AI you actually run

Aicura's discovery reads the traces AI leaves in the systems you already run, across identity, devices, cloud, code and expenses, and you decide what goes into the register. Discovery is included from the free Register tier, so finding out costs nothing.