In this post, we introduce Replica’s new native AI capabilities, enabling customers to innovate, investigate, and accelerate the most critical initiatives without compromise. Built from our deep global security origins and patented controls, Replica provides the secure operations platform for ALL high-risk digital work: both human and agentic.
Putting customer data into open-source AI models, conducting investigations to disrupt fraud, automatically combining and analyzing disparate threat data sets: exactly the kind of work banks want AI agents assisting, and exactly the kind of work no bank has dared automate inside its own network. That standoff is the reason Replica has built a safe space for agents to run at full capability: high-risk work that regulated institutions have never been able to automate now has somewhere to run.
A year ago, 11% of public companies assigned AI oversight to a named board committee. Today it’s close to 40%, and 62% of directors now put AI on the agenda directly, according to NACD’s 2025 board practices survey. [1]. Gartner expects the average Fortune 500 company to be running more than 150,000 AI agents by 2028. Only 13% of those companies believe they have the governance in place to manage them. [2]
Agents are multiplying faster than anyone’s learning to rein them in, and that’s exactly where most AI programs stall out.. or run into trouble.
Adoption That Outruns Governance
Almost every company has already moved toward AI adoption. SAP’s 2026 LeanIX survey puts agent deployment at 98%, either live or planned, but fewer than half of those companies can produce a full inventory of the agents they’re running. [3]
Kiteworks’ 2026 forecast puts three numbers on this type of control failure: 63% of organizations can’t enforce purpose limits on an agent, meaning there’s no way to say, “you can do this and nothing else” and really enforce it effectively. 60% can’t terminate a misbehaving agent once it’s running, and 55% can’t fence it off from the rest of the network to begin with. [4] Akeyless adds the picture of the aftermath: two-thirds of enterprises using agents suspect at least one has already reached data outside its intended scope, the average compromised agent goes fourteen hours before anyone notices, and only 7% of security teams trust their own controls to actually stop one once it’s caught. [5]
That’s the current operating condition for most IT and security teams running AI today, but it doesn’t have to be.
Review Boards Are Killing Product Launches
Gartner predicts more than 40% of agentic AI projects will be canceled by the end of 2027, and names inadequate risk controls as a leading cause, alongside cost and unclear value. [6] Replica’s own survey data lands on the same number from a different direction: 32% of the leaders we’ve talked to have delayed or canceled an AI deployment in the past year because there was no secure environment to run it in. [7]
Two different data sets are leading to the same critical finding. The technology works and has made a huge impact; the potential is enticing. The problem is nobody can answer the questions a BISO or review board asks before it will sign off on running it for real, on real data.
Copilots Without Containment
The investment in AI-SOC is a cyber headline staple these days, and most of that money is going toward copilots and assistants. These reason over and analyze enterprise telemetry from inside enterprise infrastructure, usually one prompt at a time. Guardrail vendors take a different angle but land in the same place: they constrain what an agent can say, not what it can reach.
Both approaches assume the agent lives on your network. For risky or sensitive work, dark-web investigation, breach data triage, malware analysis, covert collection, that assumption is the risk, not a detail to manage around it. We call it the Exception Economy, and now it’s extended to agentic machines: the same workaround instinct that used to live in a person clicking past a warning now lives in code that never gets tired and never waits for permission. An agent doesn’t need to mean harm to become the exception nobody approved.
Every board now asks (or should ask) the same three questions before it lets an agent anywhere near that kind of work:
- What can it touch? 63% of organizations can’t answer that with any confidence.
- Can we stop it? 60% can’t, once something’s running.
- Can we prove what it did? Most security teams are working from scattered logs that were never built to answer that question under pressure.
Replica answers all three of these concerns by changing where the agent runs, not by adding another layer of policy on top of the network. The agent operates inside an isolated environment, so there’s nothing beyond that environment for it to touch. Any run can be paused or killed from a single console, and any fallout stays within that environment wall. Every action is recorded and can be replayed, so proving what happened is a matter of pulling the session, not reconstructing it from fragments, or memory.
The Pitch, and the Proof
Replica’s new capabilities for AI let you innovate, investigate, and accelerate your most critical initiatives. We provide a secure operations platform for ALL high-risk digital work: both human and agentic.
- Range Without Risk Replica now runs Goose, an open-source, multi-model AI agent framework, wired directly into Replica’s own event system rather than bolted on as an add-on. An investigator types an objective in plain language, and an agent navigates to the relevant sources, runs the analysis, and returns a structured output with no configuration required. Models are reached through a private connection to AWS Bedrock that never travels the public internet, so switching between available models doesn’t cost visibility into what an agent is doing.
That same privacy holds outside of agents entirely. Set up a defined task against a frontier model, (Claude or OpenAI), from inside Replica itself, and it lands on a private, disposable copy of that model spun up on AWS Bedrock: used once, then shut down, never reaching the provider’s own servers, never folded into anyone’s training data. Replica’s environment keeps that use off the corporate network, and off a public model.
- Evidence in Minutes An agent can compare a new leak against known compromised records and hand back a formatted exposure report in minutes instead of days. Upload raw malware artifacts, binaries, memory dumps, network captures, and get a human-readable report on command-and-control infrastructure without pulling a specialist off other work for An investigator can also pull a summary of everything that happened inside an environment, browser activity, file edits, system actions, focused on exactly what they asked about and audit-ready without extra work. This eliminates manual work and other niche tooling.
- Speed With Control and Oversight Every agent’s status streams to the UI in real time, so a team can start a run, step away, and come back to check on it instead of babysitting a black box. One console handles launching, monitoring, pausing, and reviewing every agent, with logs and downloadable reports going back 30 days. A browser layer resolves CAPTCHAs and access barriers automatically, for both agents and analysts working manually, so investigations don’t stall behind them.
With this launch, your team can now watch exactly what an agent does, step by step, instead of taking it on faith for the sake of speed. Its world stays visible and bounded from the start. That’s what it means for an AI agent to never need an exception.
All of this within the existing Replica patented AI control architecture. Built to empower some of the most dangerous national security work, it naturally extended to control the entirety of what agents do and have access to – comprehensively from the base infrastructure all the way through networking, data and identity.
Ready to move forward, securely? Empower your team’s work, while eliminating security exceptions.