SecurityBrief Canada - Technology news for CISOs & cybersecurity decision-makers
Canada
Ethyca launches Astralis to govern enterprise AI data

Ethyca launches Astralis to govern enterprise AI data

Wed, 5th Aug 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Ethyca has launched Astralis, an AI governance platform for enterprises designed to govern how AI models and agents use corporate data.

The launch comes as large companies face growing pressure to control how autonomous AI systems access sensitive information. Ethyca argues that many existing compliance and governance processes were built for conventional software and cannot keep pace with the scale of AI deployment now under way.

Astralis is aimed at organisations that want to use more of their existing data in AI systems without breaching privacy or regulatory rules. The platform combines automated regulatory assessments with real-time controls over data access, with the goal of determining not only who can use data but also the purpose for which it is used.

One part of the product, Ethyca's Large Language Regulatory Model, reduces privacy and AI assessment work from 40 to 60 hours of manual review to 20 to 40 minutes per assessment, the company said. A second component, described as a Purpose-Based Access Control engine, applies rules in real time as models and agents seek access to data.

The platform runs inside a customer's own cloud environment so sensitive information remains under that organisation's control, according to Ethyca. The company also said a major US financial institution is already using the system to process 6,000 requests per second, amounting to hundreds of millions of governed data decisions each month.

Governance strain

The product enters a market shaped by a rapid rise in the number of AI agents used inside large companies. Ethyca cited Gartner projections that the average global Fortune 500 enterprise will be running more than 150,000 AI agents by 2028, up from 15 in 2025.

That increase is creating a practical problem for legal, privacy and risk teams, which are expected to account for how AI systems use internal datasets. Regulators are increasingly asking companies to explain why an autonomous system accessed a particular pool of data, Ethyca said, yet many governance programmes cannot provide a clear answer.

Cillian Kieran, Founder and Chief Executive Officer of Ethyca, said the gap between AI deployment and compliance oversight is already affecting adoption. "Organisations are not ready for the AI onslaught. Risk teams managing thousands of requests today will soon face millions. This is holding up AI adoption," Kieran said.

He added: "The promise of enterprise AI won't be realized unless companies solve the governance problem underpinning it. Most haven't yet recognized the full scope of that challenge, and automation is the only answer. Astralis governs how every model and agent uses your data in real time, so you can put it all to work to get the most out of AI. It solves for risk, compliance, governance and much more."

Regulatory backdrop

The launch also reflects a broader shift in how companies are treating AI oversight. Rather than seeing compliance as a final review stage, more businesses are moving towards building policy controls directly into data infrastructure, particularly as rules in the US and Europe continue to evolve.

That is especially relevant for Chief Legal Officers and privacy teams, which must manage changing regulatory expectations while supporting internal demand for AI tools. Static approval processes may struggle in environments where agents can make repeated, automated requests for access to data at very high volumes.

Julie Brill, former FTC Commissioner, former Microsoft Chief Privacy Officer and an Ethyca board member, framed the issue as foundational to corporate AI strategy. "Compliance with data and AI regulation isn't the ceiling, it's the foundation," Brill said. "The organizations that will win the AI era are the ones that built governance into their data infrastructure, so compliance becomes the layer AI runs on rather than the thing slowing it down. Astralis makes that possible."

Ethyca is known for data governance and privacy software used by organisations including The New York Times, Condé Nast and Ramp. With Astralis, the company is extending that work into AI oversight as enterprises look for ways to use existing data more widely without losing control over access, purpose and regulatory accountability.

According to Ethyca, a major US financial institution currently uses Astralis to automate 6,000 requests per second.