Ethyca’s Astralis Tries to Move AI Governance Into the Runtime
Ethyca's Astralis platform evaluates and enforces data policies at the point of access, enabling purpose-based AI governance with 150,000 policy decisions per second.
Ethyca launched Astralis on August 4, positioning it as an enterprise governance platform that evaluates and enforces data policies at the point of access.
The announcement matters because AI agents do not behave like conventional business applications. An agent can query a warehouse, retrieve customer information, call another model and initiate an action within seconds. As enterprise software moves from AI assistance to AI execution, governance controls increasingly need to operate at the same speed.
Governance processes built around spreadsheets, questionnaires and periodic reviews cannot intervene at that speed.
Astralis attempts to make policy enforcement part of the data infrastructure rather than a separate compliance workflow.
Key Takeaways
- Astralis applies policies when data is accessed, not only during pre-deployment reviews.
- Decisions can incorporate purpose, jurisdiction, consent, contracts and internal policies.
- The platform operates inside the customer’s infrastructure or privacy cloud.
- Ethyca claims it can enforce 150,000 policy decisions per second.
- Its strongest differentiation is purpose-based access control.
- Buyers still need independent evidence covering latency, deployment effort and false blocking.
What Happened
Astralis combines data discovery, continuous risk assessment, consent orchestration, regulatory mapping and runtime enforcement in one control layer.
Ethyca says the platform can approve, restrict or block an AI agent’s request according to why the data is being used, not merely whether the requesting identity has access. Every decision is logged to create an audit trail.
The company publishes performance indicators including policy enforcement at 150,000 decisions per second, governance of one petabyte of data per day and reductions in some data-access service levels from six weeks to five minutes. These remain vendor-reported figures. The 40–60-hour to 20–40-minute assessment claim and the reported deployment processing 6,000 requests per second do not appear in Ethyca’s main launch post, but they were repeated by Ethyca’s CEO in an interview and reported by SiliconANGLE and IT Brief as company-provided figures.
Why This Matters
Traditional access management answers, “Who can retrieve this dataset?” Agentic AI introduces a harder question: “Should this data be used for this purpose, in this jurisdiction, for this customer, at this moment?”
An employee may legitimately access customer records, for example, while an autonomous marketing agent acting through that employee’s credentials may not be permitted to use the same records for audience targeting. Purpose-based controls could help businesses distinguish between those cases.
For compliance, security and data leaders, the strategic value is potentially faster AI deployment. A governance system that can produce deterministic decisions and evidence could reduce the tendency to block entire data categories because manual review cannot keep up.
How It Works
Astralis is built on Ethyca’s Fides ontology, which provides a standardized language for classifying data and permitted uses.
When an agent requests information, Astralis evaluates the data category, intended use, applicable policies, consent status and other obligations. It can then allow the request, transform or de-identify the information, or block access.
Because it runs against data inside the customer’s environment, Ethyca says it does not need to become a processor of the regulated information being governed.
How It Compares
Most governance, risk and compliance platforms concentrate on inventories, risk registers, assessments and evidence collection. Data-security products typically focus on discovering sensitive information or controlling access by identity.
Astralis attempts to connect those layers through runtime, purpose-based enforcement. That places it closer to a policy decision engine than a conventional privacy-management application.
Abnormal AI’s new governance product approaches the issue from another direction: discovering AI tools, OAuth grants, agents and sensitive information in chats. Astralis is primarily about whether data use should be permitted; Abnormal is primarily about identifying and responding to risky AI behavior.
What Businesses Should Do
Buyers should test Astralis against two or three high-value workflows rather than attempting an enterprise-wide rollout immediately.
A useful pilot might involve a support agent accessing account data or a marketing agent creating an audience. Teams should measure decision latency, integration effort, policy accuracy, blocked legitimate requests and the quality of audit evidence.
Procurement teams should also require clarity on pricing, supported systems, policy-authoring responsibilities and what happens when Astralis cannot confidently classify an agent’s purpose.
Limitations
Most published performance evidence comes from Ethyca itself. Public information does not yet establish how the platform performs across highly customized data environments or how much human policy engineering is required.
Runtime governance may also become a critical point of failure. Recent incidents have demonstrated why continuous monitoring of autonomous agents is becoming an enterprise requirement. An incorrect policy could expose restricted data, while an overly cautious rule could interrupt legitimate operations at scale.


