What it is
WitnessAI sits on the network between your staff and every AI model, app and agent they reach, reads what is being asked, and decides whether to allow it, warn, rewrite it, route it elsewhere or stop it. Founded in 2023 in Mountain View by CEO Rick Caccia, CTO Gil Spencer and Roger Thornton, it entered the category from the network security side rather than the agent-platform side. The deployment assumption is a proxy in the path, not a connector installed into Copilot Studio.
The platform is four named modules. Observe discovers the AI apps, agents and MCP servers in use and records the conversations — prompts, responses, agent actions. Control applies policy by department, role and risk, with six actions rather than an on/off switch: allow, warn, block, route the prompt to a different model, redact, or tokenize the sensitive fields before they leave. Protect, which WitnessAI markets as an AI firewall, inspects in both directions — prompt injection and jailbreak attempts inbound, leaking or harmful content outbound. Attack runs automated red-teaming against your own deployments.
Deployment takes four shapes: proxy chaining through SSE infrastructure you already run, Witness Anywhere for agentless visibility with no proxy integration, an API integration for runtime protection of models and agents, and an MCP integration for protocol-level control. There is no endpoint agent and no browser extension, which is the specific reason it sees Windows 11 Copilot and Office 365 traffic that a browser-extension tool misses. The platform runs single-tenant with customer-controlled encryption and carries SOC 2 Type II.
WitnessAI Agentic Security shipped in January 2026: agent activity monitoring, MCP server and tool access tracking, and human-to-agent attribution that traces an autonomous action back to the person whose credentials it ran under. It arrived alongside a $58M round announced 13 January 2026, led by Sound Ventures, with Fin Capital, Qualcomm Ventures, Samsung Ventures and Forgepoint Capital participating — about $85.5M total after a $27.5M Series A co-led by GV and Ballistic Ventures in May 2024. WitnessAI reports over 500% ARR growth and 5x headcount across the preceding twelve months. Both figures are company-disclosed and unaudited.
Why ops teams end up here
The trigger is rarely a breach. It is a question from legal or a customer’s security review that the ops leader cannot answer: which AI apps are our people using, and what have they pasted into them. Browser-based telemetry answers part of it. It does not answer the desktop copilot, the IDE assistant, or the contractor on an unmanaged machine hitting an API key directly.
WitnessAI’s argument for why a DLP rule cannot cover this: the payload is prose, not a file. A recruiter pasting a candidate’s full profile into a general-purpose chatbot to draft an outreach message is not exfiltrating a document, and a regex for credit-card patterns will not fire. The platform’s answer is intent-based classification — scoring the meaning and purpose of a prompt across a conversation rather than matching keywords, which is also what it claims catches multi-turn jailbreaks that single-prompt filters miss.
The agentic half is newer and matches what ops teams are now shipping. WitnessAI’s own July 2026 survey of 300 decision-makers at organizations of 1,000+ employees found 70% already using or piloting autonomous agents while 18% had all agents formally inventoried and approved. Treat that as a vendor-sponsored survey, not an independent benchmark — but the direction matches what the AI agent ops stack is built to fix.
Pricing reality
witness.ai routes to a demo booking with no published rates. AWS Marketplace lists three independent 12-month dimensions, each with a committed minimum and a $0.01-per-unit overage beyond the commitment:
- WitnessAI for Enterprise — $180 per user per year, 1,000-user minimum. $180,000/year at the floor.
- WitnessAI Agentic Visibility — $24 per agent per year, 2,500-agent minimum. $60,000/year at the floor.
- WitnessProtect Model Protection Guardrail — a flat $300,000/year.
All three is $540,000/year before negotiation. The per-seat rate is the number to anchor on: $180/user/year is $15 per user per month, which is exactly what Microsoft Agent 365 charges per user — so in a Microsoft-first tenant the comparison is coverage, not price.
Against Zenity the units diverge sharply. Zenity bills $130 per governed resource per month, or $1,560 per agent per year; WitnessAI’s agentic line is $2 per agent per month. That 65x gap is not a discount, it is a different purchase — Zenity’s number buys runtime enforcement that can terminate an agent mid-run, WitnessAI’s buys visibility into agent traffic, with enforcement sitting in the separate Protect dimension. Price the enforcement layer you actually need before comparing the headline rates.
Best for
The security-minded ops or IT leader at 1,000+ employees who owns the answer to “what are our people sending to AI, and under whose credentials,” across a workforce that is not all in one browser on one managed fleet. The scoped case where WitnessAI wins outright: a regulated enterprise — financial services, utilities, telco, airlines are the segments it names — that needs data residency, single-tenant isolation and an identity-linked audit trail covering desktop copilots, IDE assistants and homegrown agents at once, and that wants policy richer than block, such as routing a high-risk prompt to an internal model instead of refusing it.
Not for
Anyone under 1,000 knowledge workers. The Marketplace floor is $180,000/year regardless of whether you have 200 seats or 999, and at that size a written acceptable-use policy, an approved-tools list and the logging already inside ChatGPT Enterprise or Claude covers the audit question for a rounding error of the cost. It is also the wrong buy if the real problem is that a specific agent has too much write access to the CRM — that is a permissions review, not a network control, and a CRM agent access audit answers it in an afternoon. And it will not govern a model running inside a vendor’s SaaS product that your traffic never transits.
Versus the alternatives
- Netskope and Zscaler — the two incumbents most enterprises are already paying, both of which shipped AI governance into the SSE subscription they already sell you (Netskope One DLP with AI Guardrails; Zscaler’s AI Security Suite, expanded January 2026). Pick either when the AI question is a subset of a web and SaaS control problem you already route traffic for. Their ceiling is depth: coverage is bundled and broad, and policy granularity below allow/block is thinner. This is the comparison WitnessAI’s own marketing picks the most fights with, which tells you who it displaces in deals.
- SentinelOne — acquired Prompt Security on 5 August 2025 in a deal reported between $180M and $250M in cash and stock, closing 5 September 2025, and folded it into the Singularity platform. Pick it when you already run SentinelOne for endpoint and want AI controls on the same console and the same invoice.
- Zenity — the fastest-growing entrant on the agent side, at about $180M raised after a $125M Series C in August 2026. Pick Zenity when the thing to govern is what business-built agents do in Copilot Studio and Agentforce, with runtime enforcement at the tool-call step. Pick WitnessAI when the thing to govern is what people and agents send, at the network layer, across apps no platform console owns.
- Microsoft Agent 365 — the default in a Microsoft-only tenant at the same $15/user/month, enforced through Entra and Purview. Its ceiling is the tenant boundary.
If none fit — under 1,000 seats, one AI vendor, no auditor asking — the correct spend is zero. Name the approved tools, turn on the enterprise plan’s audit log, and revisit when the second unapproved app appears.
Watch-outs
- The $180,000 floor is a 1,000-user minimum, not a starting point you grow into. Marketplace commitments bill the minimum whether or not you use it. Guard: if you are under 1,000 knowledge workers, do not take the Marketplace path at all — require a private offer with the seat floor written into the order form, and price it against the SSE module you already own before you negotiate anything else.
- “Agent” is a billing unit with a 2,500-unit minimum, and almost nobody has 2,500 agents. Guard: get the counting rule in the contract before signing — does an MCP server count, a scheduled job, each conversation thread, each copy of the same agent? Ask for an example count from your own environment during the POV and a waiver of the floor if your real number is a tenth of it.
- Intent-based classification is the entire differentiator and there is no independent evaluation of it. Keyword matching is testable; intent scoring across a multi-turn conversation is not, and no third party has published a rate. Guard: make the proof-of-value adversarial on your own traffic — a multi-turn jailbreak, a PII exfiltration staged through an approved app — and require a measured false-positive count against a full week of real prompts before any policy is promoted from warn to block.
- The growth figures and the risk survey both come from WitnessAI. 500% ARR growth, 5x headcount and the 43% of enterprises reporting $2M+ in annual AI-incident costs are all vendor-published and unaudited. Guard: ask for three reference customers at your employee count, in your industry, running enforcement in block mode rather than monitor, for at least six months — and make the last of those three conditions explicit, because monitor-mode deployments are the easy reference to supply.