The news
OneTrust on September 29 introduced OneTrust CORIE, software that checks what AI agents try to do and can allow, block or flag each action for human review, the company said. It was unveiled at TrustWeek 2026, OneTrust's conference in Las Vegas.
CORIE stands for Contextual Orchestration for Reasoning, Intelligence, and Evidence. OneTrust describes it as a shared intelligence layer built into the OneTrust Platform, which companies use to run privacy, consent, risk and AI governance programs. OneTrust says thousands of companies use it, including over half of the Fortune 500. The company says CORIE turns written policies and past governance decisions into rules that agents apply on every request, learning from how teams decide and applying that judgment at scale.
Enforcement happens at the tool call, the moment an agent asks another system for data or an action. In OneTrust's example, when a marketing agent requests data it is not permitted to use, CORIE applies the policy before the AI model sees the data. The company said each decision is recorded with the agent's identity, the request, its purpose, the outcome and the policy that governed it.
OneTrust said CORIE keeps the system checking a decision separate from the agent making it, and that it works with OneTrust's own agents, customer-built agents and third-party agents. The release did not name specific agent platforms, and it did not give pricing or a general availability date.
Blake Brannon, OneTrust's chief innovation officer, said agents are now acting across company systems "at a speed and scale no governance team can oversee through human effort alone." The release cited an IDC projection of 1.15 billion active AI agents executing 217 billion actions per day by 2029.
The launch follows OneTrust's 2026 AI-Ready Governance Report, published on September 14. In that survey of 1,200 senior business decision-makers in eight countries, conducted by Sapio Research for OneTrust, 86% said their organization had at least one AI-related incident in the past year. Some 87% said their organizations encourage agent use, while 47% said they have clear governance, oversight and controls in place.
The numbers
- Surveyed organizations with at least one AI-related incident in the past year (OneTrust survey)
- 86%
- Had two or more incidents of AI taking unapproved actions
- 28%
- Encourage agent use vs. have clear governance and controls
- 87% vs. 47%
- Survey respondents
- 1,200 senior decision-makers in 8 countries
- IDC projection cited by OneTrust, by 2029
- 1.15 billion agents, 217 billion actions a day
Why CEOs should care
For general counsel, privacy chiefs and risk officers, CORIE is a sign that governance is shifting from policies on paper to controls that act while software runs. Before relying on it, ask which agent platforms your company actually uses are covered, since OneTrust named none. Ask what happens if the checking layer is slow or unavailable: does the agent stop, or does it proceed unchecked? And ask who inside your company writes and approves the rules CORIE will learn from.
CISOs should treat the audit trail as the main prize. A record of which agent asked for what, why, and which policy allowed or blocked it is the evidence regulators and incident responders will want. Ask whether those logs can flow into existing security monitoring tools, how long they are kept, and how CORIE's decisions fit with identity and access controls already in place, so agents do not face two sets of conflicting rules.
For CFOs and boards, OneTrust's own survey gives a budget signal: 98% of respondents said they plan to raise AI governance spending next year, by an average of 25%. That is vendor-sponsored research, so weigh it accordingly. A useful board question is simple: how many AI agents are acting in our systems, who approved each one, and could we show a regulator what any of them did last month?
The bigger picture
Compliance platforms are moving into territory once held by security and identity vendors. In March, SiliconANGLE reported that OneTrust added AI agent detection and inventory, an AI policy manager and real-time guardrail checks, a move its product chief described as shifting from point-in-time compliance to runtime control. CORIE takes that a step further by sitting in the path of each agent request.
The gap in OneTrust's survey, 87% encouraging agents but 47% with clear controls, is the market these vendors are chasing. In the same report, 28% said they had two or more incidents in which AI systems took unapproved actions, and 27% said they slowed or paused AI deployment after incidents.
What’s next
OneTrust scheduled an innovation keynote on September 30 at TrustWeek to present more platform capabilities. Buyers should watch for a general availability date, pricing, and named integrations with the agent platforms they already run, which will show whether CORIE can govern agents outside OneTrust's own products in practice.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error







