security
May 15, 2026
By Teun
KnowBe4 expands agent risk management for AI and humans
KnowBe4 said it is extending its agent risk management tools to cover both human workers and AI agents. Vice president of AI and data Matt Duren said the company is adding visibility, explainability and tailored training as enterprises deploy more non-human digital workers.
KnowBe4 is expanding its security platform to manage risk across both employees and AI agents, as businesses bring more non-human digital workers into everyday workflows. Matt Duren, vice president of AI and data at KnowBe4, said the pace of deployment has outstripped governance and created a new security problem for enterprises.
Duren made the remarks in an interview with theCUBE’s Scott Hebner at KB4-CON 2026, during a broadcast produced by SiliconANGLE Media’s livestreaming studio. He said security teams can no longer focus only on human users and phishing emails, because AI agents are now being used across industries and job roles.
“The things that we’re able to do with modern AI are so, so impactful, so much more intelligent,” Duren said. “Most leaders have found that they don’t have a choice [between human and digital workers]. AI is getting used by everyone in every industry and every job role.”
KnowBe4’s response is centered on what it calls agent risk management. The company said that approach is meant to help security teams see which AI agents are active in an organization, what those agents can access, how people interact with them and how they affect business operations.
That work is being folded into two products. One is AIDA Orchestration, which KnowBe4 launched in the first quarter of 2026 as the eighth agent in its Artificial Intelligence Defense Agents suite. The company said the feature autonomously creates, schedules and personalizes phishing simulations and security awareness training at the individual-user level.
KnowBe4 said AIDA Orchestration uses more than 1.4 billion processed risk events to tailor those interventions. The other product, Agent Risk Manager, is currently in tech preview and is designed to give security teams visibility into AI agents running across the organization.
Under both products is KnowBe4’s SmartRisk score. The company said the score now uses 316 indicators that include human behavior and, increasingly, AI agent activity. Duren said KnowBe4 redesigned the scoring system to make it more explainable, so security teams can see why a score is changing.
“The previous risk score … was something that really didn’t have very much explainability because we were using custom trained AI models that we produced ourselves,” Duren said. “We’ve updated that. We’ve given lots of complex algorithmic type of approaches to the score now that, on our side, heavily involve AI and agents as well.”
Duren said KnowBe4 is using a hybrid model approach rather than relying on a single foundation model. He said the company picks the right model for each task based on cost, accuracy and latency, while managing what he described as a fleet of roughly 10 to 20 distinct systems.
The company’s focus on explainability comes as many security leaders remain hesitant to deploy AI more broadly. Duren said more than half of chief information security officers are holding back rollouts because they cannot verify what agents are doing or why.
“That’s a pause and, in a lot of ways, it’s a dangerous pause,” Duren said. “The companies that have figured that out, they’re able to move at a speed that we’ve never seen before. Agents move at machine speed - even small risks that are introduced there can really be exploited quickly.”