IBM has unveiled a pioneering software solution to unify AI security and governance, addressing the challenges of scaling agentic AI across enterprises. By integrating watsonx.governance and Guardium AI Security, this industry-first offering provides a comprehensive view of risk posture, enabling businesses to deploy AI agents responsibly and securely.
IBM introduces first software for unified AI governance and security.
Integrates watsonx.governance and Guardium AI Security for risk management.
Supports compliance with 12 frameworks, including EU AI Act, ISO 42001.
Detects AI use cases in cloud, code repositories, and embedded systems.
Automated red teaming identifies vulnerabilities in AI deployments.
Monitors agent lifecycle with metrics like relevance and faithfulness.
As agentic AI adoption accelerates, enterprises face risks from ungoverned autonomous systems. IBM’s new software bridges AI security and governance teams, offering a single platform to manage risks. The integration of watsonx.governance, an end-to-end governance tool, with Guardium AI Security, which secures AI models and data, ensures compliance and protection across decentralized AI ecosystems.
"AI agents are set to revolutionize enterprise productivity, but the very benefits of AI agents can also present a challenge," said Ritika Gunnar, General Manager, Data and AI, IBM. "When these autonomous systems aren't properly governed or secured, they can carry steep consequences."
Through a collaboration with AllTrue.ai, Guardium AI Security now detects AI use cases in cloud environments, code repositories, and embedded systems, triggering governance workflows automatically. New features include automated red teaming to uncover vulnerabilities and custom security policies to mitigate risks like code injection and data leakage. These capabilities are available now, with full integration into watsonx.governance rolling out by year-end.
"The future of AI depends on how well we secure it today. Embedding security from the start is essential to protecting data, supporting compliance obligations, and building lasting trust," said Suja Viswesan, Vice President, Security and Runtime Products, IBM.
Watsonx.governance enables comprehensive monitoring of AI agents from development to deployment. Evaluation nodes track metrics such as answer relevance, context relevance, and faithfulness, pinpointing performance issues. Planned features, expected by June 27, 2025, include agent onboarding risk assessments, audit trails, and an agentic tool catalogue to streamline governance.
The watsonx.governance Compliance Accelerators provide pre-loaded regulations and standards, including the EU AI Act, U.S. Federal Reserve’s SR 11-7, and ISO/IEC 42001. These tools help enterprises map obligations to their AI use cases, ensuring compliance with global frameworks. Available as an add-on, Compliance Accelerators simplify regulatory adherence.
"One of the biggest challenges for security teams is translating incidents and compliance violations into quantifiable business risk. The rapid adoption of AI and agentic AI amplifies this issue," said Jennifer Glenn, Research Director for the IDC Security and Trust Group.
IBM Consulting Cybersecurity Services offers new AI-focused services to support secure AI transformations. These include discovering AI deployments, implementing secure-by-design practices, and providing governance guidance for evolving regulations. With experience supporting clients like Nationwide Building Society, IBM helps enterprises scale AI responsibly.
This innovative software, combined with IBM’s watsonx AI solutions, empowers businesses to harness agentic AI’s potential while maintaining security and compliance, setting a new standard for responsible AI deployment.
IBM is a leading provider of global hybrid cloud and AI, and consulting expertise. We help clients in more than 175 countries capitalize on insights from their data, streamline business processes, reduce costs, and gain a competitive edge in their industries. Thousands of governments and corporate entities in critical infrastructure areas such as financial services, telecommunications and healthcare rely on IBM's hybrid cloud platform and Red Hat OpenShift to affect their digital transformations quickly, efficiently, and securely. IBM's breakthrough innovations in AI, quantum computing, industry-specific cloud solutions and consulting deliver open and flexible options to our clients. All of this is backed by IBM's long-standing commitment to trust, transparency, responsibility, inclusivity, and service.