OneTrust is launching CORIE, a new AI governance layer designed to enforce enterprise policies as AI agents operate, as the company expands its platform to address governance challenges created by increasingly autonomous AI systems.
Announced as part of TrustWeek 2026, CORIE—short for Contextual Orchestration for Reasoning, Intelligence and Evidence—draws on an organization’s existing privacy, consent, risk, data and AI governance programs to determine what agents are permitted to do, enforce those policies at runtime and create an auditable record of their decisions.
The launch comes as enterprises face a widening gap between AI adoption and governance. OneTrust’s 2026 AI-Ready Governance Report found that 87% of respondents said their organizations encourage agent use, while just 47% reported having clear governance, oversight and controls in place.
OneTrust CORIE brings runtime governance into agent workflows
Rather than treating governance primarily as an assessment conducted before or after deployment, OneTrust is positioning CORIE as an independent layer that can enforce policies while agents are working.
CORIE can turn existing governance decisions into rules applied to individual requests and enforce them at the tool-call level by permitting an action, blocking it, or escalating it for human review. The system also records information including the agent, request, purpose, outcome, and governing policy.
“AI is putting capabilities once reserved for engineering teams into the hands of every employee,” said Blake Brannon, chief innovation officer at OneTrust. “The result is a growing network of agents acting across company systems at a speed and scale no governance team can oversee through human effort alone.”
OneTrust is extending that architecture through its broader platform, which combines CORIE with an AI Control Plane and Governance Command Center. CORIE itself includes:
- Trust Graph that maps AI systems and models to enterprise data, vendors, and identities
- Reasoning Engine for applying policies and previous governance decisions
- Evidence Ledger for maintaining an auditable record of actions
The AI Control Plane sits between agents and enterprise systems to evaluate actions at runtime, while the Governance Command Center provides teams with a centralized view of risk posture, governance activity, and exceptions requiring human intervention.
MCP Gateway extends governance to enterprise AI tools
OneTrust is also introducing a headless experience through an MCP Gateway, which is in private preview. The gateway is designed to bring governance context and workflows into AI applications including ChatGPT, Claude, Copilot, and Glean while reducing the need for custom integrations.
“As organizations put AI to work, their governance teams already have the context and expertise to guide them,” said DV Lamba, chief product and technology officer at OneTrust. “The challenge now is applying that judgment to thousands of agent decisions a day.”
Additional platform capabilities include AI-driven assessments, continuous regulatory posture management, conversational consent, AI-driven Records of Processing Activities management and automated risk and control recommendations. Most are slated for private preview this fall or winter, while risk and control recommendations are expected to become generally available in winter.
AI governance becomes part of the channel implementation stack
For MSPs, solution providers and enterprise technology partners, OneTrust’s announcements reflect a broader shift in how governance fits into AI projects: controls increasingly have to be designed into the architecture itself rather than treated as a separate compliance exercise after deployment.
As customers move AI agents from pilots into production, partners will need to consider how policy enforcement, auditability, consent and human approval requirements fit into the systems they design, integrate and manage. That expands the implementation conversation beyond model selection and infrastructure to include how individual agent actions are evaluated, recorded and, when necessary, escalated for human review.
Channel Insider has tracked that evolution over the past several months as technology providers and partners build governance and security offerings around enterprise AI adoption. OneTrust’s latest platform additions suggest those capabilities are moving closer to the operational layer, where governance decisions can influence what an AI agent is actually allowed to do.




