OneTrust is rolling out CORIE, a governance layer built to enforce enterprise policies while AI agents operate, as the company revealed during TrustWeek 2026 that 87% of organizations now encourage agent use but only 47% have established clear governance, oversight and controls. The platform—Contextual Orchestration for Reasoning, Intelligence and Evidence—taps into an organization's existing privacy, consent, risk, data and AI governance programs to decide what agents can do, enforce those rules as they run, and log an auditable trail of every decision. The launch addresses a widening disconnect between how fast companies are adopting autonomous AI systems and how slowly they're putting safeguards in place.
OneTrust's 2026 AI-Ready Governance Report found that while nearly nine in ten respondents said their organizations promote agent use, fewer than half reported having governance structures to oversee those systems. The 40-percentage-point gap between adoption and control represents what the company frames as a critical vulnerability as AI agents gain the ability to act across company systems without real-time human supervision. The report underscores that enterprises are handing AI capabilities previously limited to engineering teams to every employee, creating a network of agents operating at a speed and scale that governance teams can't monitor through manual effort alone.
"AI is putting capabilities once reserved for engineering teams into the hands of every employee," said Blake Brannon, chief innovation officer at OneTrust. "The result is a growing network of agents acting across company systems at a speed and scale no governance team can oversee through human effort alone." According to DV Lamba, chief product and technology officer at OneTrust, governance teams already possess the context and expertise to guide AI use, but the challenge now involves applying that judgment to thousands of agent decisions each day. The company positions CORIE not as a pre- or post-deployment assessment but as an independent layer that enforces policies while agents work, applying rules at the tool-call level by permitting an action, blocking it, or escalating it for human review.
CORIE operates through three components: a Trust Graph that connects AI systems and models to enterprise data, vendors, and identities; a Reasoning Engine that applies policies and past governance decisions; and an Evidence Ledger that keeps an auditable record of actions. The platform sits between agents and enterprise systems through an AI Control Plane that evaluates actions at runtime, while a Governance Command Center gives teams a centralized view of risk posture, governance activity, and exceptions needing human intervention. OneTrust is also introducing an MCP Gateway in private preview, designed to bring governance context and workflows into AI applications including ChatGPT, Claude, Copilot, and Glean while cutting down on custom integrations. Additional platform capabilities—AI-driven assessments, continuous regulatory posture management, conversational consent, AI-driven Records of Processing Activities management, and automated risk and control recommendations—are slated for private preview this fall or winter, with risk and control recommendations expected to reach general availability in winter. For MSPs, solution providers and enterprise technology partners, the shift means governance controls increasingly need to be designed into AI architecture itself rather than treated as a separate compliance exercise after deployment, expanding the implementation conversation beyond model selection to include how individual agent actions are evaluated, recorded, and escalated. As autonomous systems move from pilots to production, the gap between adoption enthusiasm and oversight infrastructure will likely determine which organizations can scale AI without exposing themselves to runaway risk or compliance failures.

