← All articles

How an AI governance agent works

8 min read · Updated May 16, 2026

“Install an agent” sounds like a black box. This is a plain description of what actually happens between the moment someone types a prompt and the moment the AI provider receives it - what the agent sees, where redaction happens, and what that architecture does and doesn't cover.

What the agent does on the device

A small agent installs on the employee's laptop - macOS or Windows, pushed via MDM or run as a standalone installer. It watches outbound HTTPS traffic and recognises requests going to a known list of AI providers: ChatGPT, Claude, Gemini, Copilot, Cursor, Claude Code, and Codex via ChatGPT sign-in. Everything else - normal browsing, email, every other app - passes through untouched.

Because it works at the device level rather than inside one browser or one app, it covers the browser, the native desktop app, supported IDE assistants, and the command line, all from a single install. There is no browser extension to add per browser and no VPN client to configure.

Where redaction actually happens

This is the part worth being precise about. The agent's job is to intercept the request on the device - it does not itself decide what is sensitive. The request is forwarded, in flight, to NexusNest's redaction service (or to the customer's own deployment, for teams that run NexusNest in their own cloud or on-prem). Redaction happens there, before the request continues on to the AI provider. Only the redacted text goes on to the AI provider - once the redacted version is computed, the original is discarded.

Detection runs in two layers: a fast pattern layer for high-confidence strings (emails, card numbers, API keys, private keys) and a contextual layer for the harder cases - a customer name mentioned in passing, a paragraph that reads like an internal memo. Detected spans are replaced with placeholders before the request reaches the provider, and the AI answers from the surrounding structure - so the response still works.

Why the prompt box is different from anything else on a device

Most of what a company already has visibility into - email attachments, USB transfers, uploads to storage services - has a distinct shape on the network. A prompt to an AI tool doesn't: it's a normal HTTPS request, encrypted with TLS, indistinguishable on the wire from any other API call to the same domain. Nothing about the traffic itself says “this contains a customer record” unless something is actually built to open that specific request and read the prompt inside it.

That's the gap a governance agent is built to close - not by watching the network in general, but by understanding each AI tool's request format well enough to find the user-authored prompt text inside it, every time, regardless of which app or client sent it.

What a device-level agent covers that other approaches miss

  • Native desktop apps. The ChatGPT and Claude desktop apps, and IDEs like Cursor, don't run inside a browser - a browser-only approach never sees them.
  • The command line. Claude Code and similar CLI tools send requests straight from the terminal. A device-level agent catches this as ordinary outbound HTTPS; nothing browser-based can.
  • Off the corporate network. A coffee-shop wifi connection or a personal hotspot doesn't route through a corporate network proxy. An agent running on the laptop itself works the same regardless of which network it's on.
  • Signed-out and temporary chats. Several AI tools support a temporary or unauthenticated mode that doesn't tie to a corporate identity. A device-level agent covers this the same way it covers a signed-in session.

What it does not do

  • It redacts by default. Redacting and letting the request through keeps people using the tools they already know; a hard block just pushes the same work onto a personal device with zero visibility. Admins can choose to flag or block specific categories.
  • It does not read anything outside the AI-bound traffic it recognises. Normal browsing and other apps are not touched.
  • It does not keep a reverse mapping from a placeholder back to the original value - there is nothing to reconstruct.

How to evaluate one

When you're looking at a governance agent for your own company, ask directly: which surfaces does it cover today (browser, desktop app, IDE, CLI), where does redaction actually run, and can you see the audit trail it produces. A vendor that can answer all three specifically, rather than in generalities, has actually built the thing.

Stuck on the decision? The AI governance buyer's checklist walks through the twelve questions that surface the architecture answer directly.

Sources & further reading

Start with one team. Prove control before you scale AI.

Start with one team. See exactly how your company uses AI.

Start your trial