Gartner® Emerging Tech Report on AI TRiSM: What We Believe It Means for Agentic AI and Data Security

GenAI Security
Blog

Key Takeaways

AI TRiSM is becoming an operational requirement, not a conceptual framework. Enterprises are moving past experimentation and into enforcement.
Agentic AI introduces a new class of risk. Autonomous systems change how data is accessed, combined, and shared.
Opsin is included in this emerging landscape, which we believe reflects a focus on preventing data exposure and exfiltration as AI agents move into production.
Data security is at the center of AI governance. Runtime visibility and control matter more than static policies.
Regulation is accelerating adoption. Frameworks like the EU AI Act and NIST AI RMF are pushing organizations to operationalize AI governance.

Our overview of Gartner’s “Emerging Tech: Top-Funded Startups in AI TRiSM: Agentic AI and Beyond” report and Opsin’s role in the agentic AI era.

What Is AI TRiSM and Why It Matters Now

AI TRiSM stands for AI Trust, Risk, and Security Management. It is Gartner’s framework for addressing the risks introduced by AI systems across their lifecycle.

That includes security, governance, privacy, and compliance. It also includes how AI behaves once it is deployed, not just how it is designed.

The timing matters. Enterprises are no longer testing AI in isolation. They are deploying copilots, autonomous agents, and AI-driven workflows that interact directly with sensitive data and business systems.

“The data intensity of GenAI is rapidly outpacing legacy security solutions, necessitating a new era of scalable architectural innovations in data privacy and access control.” As Gartner notes in the report: “the nondeterministic behaviors of AI make it necessary to evolve security testing approaches where established practices based on deterministic inputs and outputs are inadequate.”

What’s New to us in Gartner’s “Top-Funded Startups in AI TRiSM” Report

According to the report, Emerging Tech: Top-Funded Startups in AI TRiSM: Agentic AI and Beyond, “in this research, we examined 120 early-stage AI trust, risk and security management (TRiSM) startups that received venture capital (VC) funding during the period from October 2022 through September 2025. These early-stage (through Series B) startups collectively raised around $1,726 million in VC funding, from which we have identified several critical trends where investments are placed within AI TRiSM…… This involves comprehensive measures in AI security platforms, agentic AI security, information governance, AI governance and AI security testing.”

In our opinion, the most important shift in this report is Gartner’s focus on agentic AI. AI agents are no longer theoretical. They are being deployed to complete tasks, access data, and interact with tools with limited human oversight.

That shift changes the risk profile of AI adoption.

Key Findings: Agentic AI Changes the Risk Model

Gartner highlights several implications of agentic AI adoption:

  • “By 2030, machine customers are predicted to initiate 50% of all service requests, powered by agentic AI systems. This rapid rise introduces a new attack vector and complex governance challenges.”
  • “Initial concerns for organizations using generative AI (GenAI) have centered on data oversharing where AI models and applications might expose sensitive data or where data might be inappropriately input into external AI services.”

Unlike traditional applications, AI agents can chain actions together. They retrieve data, reason over it, and pass it downstream to other systems. That makes intent harder to define and mistakes harder to contain.

The result is a higher likelihood of data exposure and unintended exfiltration.

How Gartner Evaluates Emerging AI TRiSM Startups

This report is not a Magic Quadrant or Market Guide. It is focused on emerging technology in the space of securing and governing AI.

In our opinion, Gartner looks at where investment is flowing and which companies are addressing risks that did not exist a few years ago. The emphasis is on architectural fit for the future, not feature checklists.

To us, a consistent theme throughout the report is that fragmented, point-based solutions will struggle. We believe vendors that offer unified and AI-native approaches are better positioned to support enterprise-scale adoption.

Where Agentic AI and Data Security Converge

Agentic AI puts pressure on one question: how do you control data when systems act autonomously?

Traditional controls assume:

  • Human-driven access
  • Static roles
  • Predictable workflows

AI agents break those assumptions. They operate across tools, data sources, and steps. They can expose sensitive information through prompts, responses, or downstream actions without malicious intent.

Gartner repeatedly points to information governance and runtime monitoring as foundational capabilities for AI TRiSM. Without them, organizations lose visibility into how data is actually used.

Opsin’s Inclusion in Gartner’s AI TRiSM Landscape

Opsin is included in Gartner’s analysis of top-funded startups in AI TRiSM.

Our focus is narrow by design. We help organizations prevent data exposure and exfiltration as AI agents, copilots, and AI-powered workflows move into production.

We believe that focus aligns directly with the risks Gartner highlights. As enterprises scale agentic AI, they need practical ways to understand how data is accessed, shared, and controlled in real time.

Why Data Exposure and Exfiltration Are the Defining AI Risks

AI risk is often discussed in terms of bias or hallucinations. Those issues matter, but for enterprises, data loss is the most immediate concern.

AI systems can expose data in ways that are difficult to anticipate:

  • Sensitive data included in prompts or context windows
  • Agents combining information across domains
  • AI tools accessing more data than intended
  • Autonomous workflows triggering unintended actions

Once data leaves controlled boundaries, remediation is limited. The impact is regulatory, financial, and reputational.

That is why securing AI starts with protecting data at the moment it is used.

How We Believe Opsin Aligns With Gartner’s AI TRiSM Direction

Opsin’s approach reflects several principles we concluded in the report:

  • AI-aware information governance that understands context and intent
  • Runtime visibility into how AI systems access and share data
  • Controls designed for agents, not just users
  • Architecture that scales with AI adoption rather than slowing it down

By focusing on data protection in active AI interactions, Opsin enables organizations to move faster with agentic AI without increasing risk.

Conclusion

In our opinion, Gartner’s Emerging Tech: Top-Funded Startups in AI TRiSM: Agentic AI and Beyond report reflects a clear shift.

AI adoption is accelerating. Agentic systems are moving into production. Governance must move from policy to practice.

Data security sits at the center of this transition.

Opsin is building for that reality. We help organizations protect sensitive data as AI systems become more autonomous and more deeply embedded in the enterprise.

Gartner clients can access the full report here: Emerging Tech: Top-Funded Startups in AI TRiSM: Agentic AI and Beyond report through Gartner.

Gartner, Emerging Tech: Top-Funded Startups in AI TRiSM: Agentic AI and Beyond, 13 January 2026

Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.

GARTNER is a trademark of Gartner, Inc. and its affiliates.

Table of Contents

LinkedIn Bio >

FAQ

What is AI TRiSM?

AI TRiSM is Gartner’s framework. According to Gartner: “AI TRiSM is a maturing framework that focuses on managing and mitigating risks associated with AI implementations. This involves comprehensive measures in AI security platforms, agentic AI security, information governance, AI governance and AI security testing.”

Why is agentic AI a major focus in this report?

Because autonomous agents introduce new data and security risks that traditional controls cannot manage effectively.

Why was Opsin included?

We believe, Opsin addresses a core AI TRiSM challenge: preventing data exposure and exfiltration as AI systems become more autonomous.

How should enterprises use this report?

According to the research: “high-tech C-level executives must decide how to respond to the significant VC investments and acquisition trends within AI TRiSM as part of their security portfolio.”

About the Author
Oz Wasserman
Oz Wasserman is the Founder of Opsin, with over 15 years of cybersecurity experience focused on security engineering, data security, governance, and product development. He has held key roles at Abnormal Security, FireEye, and Reco.AI, and has a strong background in security engineering from his military service.
LinkedIn Bio >

Gartner® Emerging Tech Report on AI TRiSM: What We Believe It Means for Agentic AI and Data Security

Our overview of Gartner’s “Emerging Tech: Top-Funded Startups in AI TRiSM: Agentic AI and Beyond” report and Opsin’s role in the agentic AI era.

What Is AI TRiSM and Why It Matters Now

AI TRiSM stands for AI Trust, Risk, and Security Management. It is Gartner’s framework for addressing the risks introduced by AI systems across their lifecycle.

That includes security, governance, privacy, and compliance. It also includes how AI behaves once it is deployed, not just how it is designed.

The timing matters. Enterprises are no longer testing AI in isolation. They are deploying copilots, autonomous agents, and AI-driven workflows that interact directly with sensitive data and business systems.

“The data intensity of GenAI is rapidly outpacing legacy security solutions, necessitating a new era of scalable architectural innovations in data privacy and access control.” As Gartner notes in the report: “the nondeterministic behaviors of AI make it necessary to evolve security testing approaches where established practices based on deterministic inputs and outputs are inadequate.”

What’s New to us in Gartner’s “Top-Funded Startups in AI TRiSM” Report

According to the report, Emerging Tech: Top-Funded Startups in AI TRiSM: Agentic AI and Beyond, “in this research, we examined 120 early-stage AI trust, risk and security management (TRiSM) startups that received venture capital (VC) funding during the period from October 2022 through September 2025. These early-stage (through Series B) startups collectively raised around $1,726 million in VC funding, from which we have identified several critical trends where investments are placed within AI TRiSM…… This involves comprehensive measures in AI security platforms, agentic AI security, information governance, AI governance and AI security testing.”

In our opinion, the most important shift in this report is Gartner’s focus on agentic AI. AI agents are no longer theoretical. They are being deployed to complete tasks, access data, and interact with tools with limited human oversight.

That shift changes the risk profile of AI adoption.

Key Findings: Agentic AI Changes the Risk Model

Gartner highlights several implications of agentic AI adoption:

  • “By 2030, machine customers are predicted to initiate 50% of all service requests, powered by agentic AI systems. This rapid rise introduces a new attack vector and complex governance challenges.”
  • “Initial concerns for organizations using generative AI (GenAI) have centered on data oversharing where AI models and applications might expose sensitive data or where data might be inappropriately input into external AI services.”

Unlike traditional applications, AI agents can chain actions together. They retrieve data, reason over it, and pass it downstream to other systems. That makes intent harder to define and mistakes harder to contain.

The result is a higher likelihood of data exposure and unintended exfiltration.

How Gartner Evaluates Emerging AI TRiSM Startups

This report is not a Magic Quadrant or Market Guide. It is focused on emerging technology in the space of securing and governing AI.

In our opinion, Gartner looks at where investment is flowing and which companies are addressing risks that did not exist a few years ago. The emphasis is on architectural fit for the future, not feature checklists.

To us, a consistent theme throughout the report is that fragmented, point-based solutions will struggle. We believe vendors that offer unified and AI-native approaches are better positioned to support enterprise-scale adoption.

Where Agentic AI and Data Security Converge

Agentic AI puts pressure on one question: how do you control data when systems act autonomously?

Traditional controls assume:

  • Human-driven access
  • Static roles
  • Predictable workflows

AI agents break those assumptions. They operate across tools, data sources, and steps. They can expose sensitive information through prompts, responses, or downstream actions without malicious intent.

Gartner repeatedly points to information governance and runtime monitoring as foundational capabilities for AI TRiSM. Without them, organizations lose visibility into how data is actually used.

Opsin’s Inclusion in Gartner’s AI TRiSM Landscape

Opsin is included in Gartner’s analysis of top-funded startups in AI TRiSM.

Our focus is narrow by design. We help organizations prevent data exposure and exfiltration as AI agents, copilots, and AI-powered workflows move into production.

We believe that focus aligns directly with the risks Gartner highlights. As enterprises scale agentic AI, they need practical ways to understand how data is accessed, shared, and controlled in real time.

Why Data Exposure and Exfiltration Are the Defining AI Risks

AI risk is often discussed in terms of bias or hallucinations. Those issues matter, but for enterprises, data loss is the most immediate concern.

AI systems can expose data in ways that are difficult to anticipate:

  • Sensitive data included in prompts or context windows
  • Agents combining information across domains
  • AI tools accessing more data than intended
  • Autonomous workflows triggering unintended actions

Once data leaves controlled boundaries, remediation is limited. The impact is regulatory, financial, and reputational.

That is why securing AI starts with protecting data at the moment it is used.

How We Believe Opsin Aligns With Gartner’s AI TRiSM Direction

Opsin’s approach reflects several principles we concluded in the report:

  • AI-aware information governance that understands context and intent
  • Runtime visibility into how AI systems access and share data
  • Controls designed for agents, not just users
  • Architecture that scales with AI adoption rather than slowing it down

By focusing on data protection in active AI interactions, Opsin enables organizations to move faster with agentic AI without increasing risk.

Conclusion

In our opinion, Gartner’s Emerging Tech: Top-Funded Startups in AI TRiSM: Agentic AI and Beyond report reflects a clear shift.

AI adoption is accelerating. Agentic systems are moving into production. Governance must move from policy to practice.

Data security sits at the center of this transition.

Opsin is building for that reality. We help organizations protect sensitive data as AI systems become more autonomous and more deeply embedded in the enterprise.

Gartner clients can access the full report here: Emerging Tech: Top-Funded Startups in AI TRiSM: Agentic AI and Beyond report through Gartner.

Gartner, Emerging Tech: Top-Funded Startups in AI TRiSM: Agentic AI and Beyond, 13 January 2026

Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.

GARTNER is a trademark of Gartner, Inc. and its affiliates.

Get Your Copy
Your Name*
Job Title*
Business Email*
Your copy
is ready!
Please check for errors and try again.

Secure, govern, and scale AI

Inventory AI, secure data, and stop insider threats
Get a Demo →