Cybersecurity company Tenable has partnered with OpenAI to launch the CyberAgents Exchange AI Inspector, a new security review process designed to help enterprise security teams evaluate AI agents, MCP servers, skills, and multi-agent playbooks before they go live in production environments.
The announcement, made September 3, 2026, comes as enterprise teams are deploying AI agents faster than their security processes can keep up. The average organisation now manages dozens of AI agents, many built by individual teams without central review or security oversight.
What the Exchange Inspector Does
The Exchange Inspector combines three layers of scrutiny:
- Frontier AI assessment using OpenAI’s GPT cyber models to analyse components for potential vulnerabilities and misuse risks
- Skills inspection powered by Tenable One’s AI Exposure analysis to identify exposure gaps in how agents access systems and data
- Expert review by Tenable security researchers who validate findings and flag anything the automated layers miss
The tool is built into the CyberAgents Exchange, an open-source, cybersecurity-native registry that Tenable launched in August 2026. The Exchange is essentially a vetted marketplace for AI components: agents, skills, MCP servers, and multi-agent playbooks that enterprise teams can evaluate, adopt, and build on. Following a SWARM build event at Black Hat USA, the registry now holds more than 100 community-submitted AI components.
The collaboration grew from Tenable’s participation in the OpenAI Daybreak Defense Network, a program that gives vetted cybersecurity organisations access to OpenAI’s most advanced cyber-capable models for defensive purposes.
Exchange Inspector is expected to reach general availability in September 2026.
Why This Matters Now
The timing reflects a real pressure point in enterprise AI adoption. Agentic AI tools are no longer experimental. Teams across finance, legal, operations, and IT are actively deploying agents that can browse the web, write code, query databases, and execute workflows with minimal human oversight. But the security processes for evaluating those agents have not kept pace.
MCP (Model Context Protocol) servers have become a particular focus for security teams. MCP servers act as bridges that connect AI agents to internal tools, data sources, and external APIs. A compromised or poorly configured MCP server can give an agent unintended access to sensitive systems. The Exchange Inspector specifically covers MCP servers as a review category, which addresses one of the more pressing governance gaps businesses face today.
For teams that have adopted platforms like Claude, GPT-based tooling, or multi-agent orchestration systems, having a way to independently verify the security posture of third-party components is no longer optional. It is a governance requirement.
What This Means for Business
If your organisation is building or buying AI agents, three things are worth taking from this announcement.
Third-party AI components carry third-party risk. Community-built agents and MCP servers can introduce vulnerabilities that bypass your existing security controls. Before you connect an agent to internal systems, you need to understand what that agent can access and whether it behaves as advertised.
The tooling is catching up to the risk. The fact that OpenAI is lending its most capable cyber models to help inspect AI components is a signal that the industry is starting to treat AI agent security as a first-class concern, not a future problem to solve later.
Security review needs to be part of your AI governance process. Most organisations have change management and vendor review processes for traditional software. Those same controls need to extend to AI agents. The CyberAgents Exchange Inspector is one practical example of what that looks like in a world where agents are pulling data, executing tasks, and talking to external APIs on your behalf.
Enterprise DNA’s Omni Ops service helps businesses implement AI agent workflows with appropriate governance guardrails from the start, so teams can move quickly without exposing themselves to unnecessary risk. If you are planning an agentic deployment and want to work through the security and operational governance side of it, book a discovery call to talk through your specific setup.
Source
GlobeNewswire
Free Resource
Going deeper with Claude?
Get the free 32-page implementation guide for ANZ teams.
Your guide is ready
Check your downloads folder. If it did not open automatically, use the button below.
Download the GuideWant this working inside your business?
See what's possible