OneTrust
Type: company (privacy / AI-governance platform vendor) Sector: Privacy management, consent, third-party risk, AI governance software First seen: 2026-06-22 Last updated: 2026-09-18
Updated 2026-09-17 based on S-2026-09-14-onetrust-ai-ready-governance-report-2026 and S-2026-09-10-onetrust-trustweek-2026 (daily data-governance vendor-intelligence scan) — vendor research restates the runtime-enforcement thesis; product substantiation still absent. OneTrust’s second annual AI-Ready Governance Report (14 Sep; Sapio Research, n=1,200 senior decision-makers in eight countries incl. UK, FR, DE, ES) reports 87% encouraging agent use vs 47% with clear governance/oversight/controls, 28% with two-plus unapproved-agent-action incidents, 86% with at least one AI-related incident (vendor-defined basket) yet only 27% slowing deployment, 33% with shadow AI caused by slow approvals, and 98% raising AI-governance tech budgets (+25% avg). CIO Blake Brannon’s framing — “judgment has to live in the runtime itself, deciding and enforcing in the moment AI acts” — repeats the August Summer ‘26 positioning without naming a product, mechanism or availability, so the standing open question is unchanged. Also recorded: TrustWeek 2026 (28–30 Sep) with an innovation keynote on 30 Sep that promises “new capabilities” (the dated next check for that question); John Heyman confirmed as CEO in a primary dated release; Stephanie Glenn appointed Chief Revenue Officer (8 Sep; title-only capture). Low authority throughout (vendor-commissioned survey, event promotion); no regulator, regulation or FS deployment named — BBVA and Fiserv appear as speakers only. Updated 2026-08-18 based on S-2026-08-13-onetrust-summer-release-2026 (daily AI-governance vendor-intelligence scan; OneTrust webinar promotion page fetched in full) — OneTrust ran a Summer ‘26 Release webinar on 13 August 2026 whose marketing copy lists “govern AI with runtime monitoring, enforcement, and model oversight” among the capabilities demonstrated, alongside agentic-AI workflow automation and governance-insight/audit-activity visibility. If substantiated, this would be the first movement recorded in this vault of an established AI-governance platform pure-play into the runtime enforcement locus currently contested by security vendors (HiddenLayer, Obsidian Security, Zenity, Vorlon) and Credo AI’s Agent Governor — bearing directly on the standing “pure-plays quiet on shipped product” open question on AI Governance Platforms. ⚠️ Severe source caveat: the only evidence is a webinar registration page, not a release note, press release or product documentation. Availability status (GA / limited availability / preview) is unstated; no mechanism is given, so it is impossible to tell whether “enforcement” means pre-execution action interception or post-hoc alerting — a distinction this vault treats as decisive; no regulatory standard, customer, evidence artefact or retention model is named. Recorded as claimed direction of travel only, not as a shipped capability.
Created 2026-07-31 from S-2026-07-08-onetrust-eu-ai-act-timeline (daily vendor-intelligence scan). OneTrust previously appeared in the vault only via the 2026 Gartner MQ for AI Governance Platforms sources S-2026-06-22-gartner-mq-ai-governance-platforms; a second source now triggers this page per schema §2.3. Updated 2026-09-18 based on S-2026-09-18-weekly-vendor-synthesis (weekly vendor-synthesis): cross-week DG/DM read — the 2026 AI-Ready Governance Report restates OneTrust’s runtime-enforcement thesis with survey weight (87% encourage agent use vs 47% with clear governance; 86% incident rate) but again names no product, mechanism or availability status, so the standing ‘did runtime enforcement actually ship’ open question is unchanged for a second consecutive month; the 30 Sep TrustWeek innovation keynote remains the next dated check. The CRO appointment (Stephanie Glenn) is a minor vendor-lifecycle note, not a continuity risk. No contradiction.
Snapshot
OneTrust is a privacy/trust-management vendor (consent, privacy automation, third-party risk) that has expanded into AI governance — inventories, classification, workflow automation and evidence maintenance for regimes led by the EU AI Act. It matters to this wiki as one of the “regulatory-alignment” vendors: its platform and regulatory-intelligence content shape how EU/UK regulated firms interpret and operationalise AI Act readiness [S-2026-07-08-onetrust-eu-ai-act-timeline][S-2026-06-22-gartner-mq-ai-governance-platforms].
Positions / Claims they advance
- Named a Visionary in the inaugural 2026 Gartner Magic Quadrant for AI Governance Platforms; markets runtime observability (drift, hallucinations, anomalous behaviour) and integrations to Azure AI Foundry, AWS SageMaker/Bedrock, Databricks MLflow/Unity Catalog and Google Vertex — vendor marketing claims, not independently verified [S-2026-06-22-gartner-mq-ai-governance-platforms].
- Argues the EU AI Act amendment delays are not a pause: the deferrals (Annex III standalone high-risk to 2 Dec 2027; product-embedded to 2 Aug 2028) reflect missing standards/conformity infrastructure, and firms should use the runway to build “AI-ready governance” — AI inventories and classification, governance embedded in existing workflows (procurement, vendor onboarding, DPIAs), and continuous evidence collection [S-2026-07-08-onetrust-eu-ai-act-timeline].
- States providers are expected to implement transparency measures for AI-generated content by 2 December 2026 — a date that diverges from the vault’s primary-source record of Article 50 applying from 2 August 2026; see Tensions [S-2026-07-08-onetrust-eu-ai-act-timeline].
- Positions OneTrust AI Governance as centralising AI documentation, mapping AI systems/data flows, automating workflows, evaluating against frameworks and maintaining regulatory-readiness evidence — vendor marketing, unverified [S-2026-07-08-onetrust-eu-ai-act-timeline].
- Markets its Summer ‘26 Release (webinar 13 Aug 2026) as delivering AI governance with “runtime monitoring, enforcement, and model oversight”, plus agentic-AI workflow automation, governance insights and audit-activity visibility. This would represent a move from documentation/workflow tooling into runtime enforcement — but the claim rests entirely on a webinar promotion bullet with no mechanism, availability status, standard, customer or evidence artefact named ⚠️; it must not be treated as a shipped capability without release notes or product documentation [S-2026-08-13-onetrust-summer-release-2026].
- Argues, via its own 2026 research, that adoption is outrunning oversight and that the fix is runtime governance: 87% of surveyed organisations encourage AI-agent use but only 47% have “clear governance, oversight, and controls”; 28% had two or more incidents of AI systems or agents taking unapproved actions; 86% experienced at least one AI-related incident (sensitive-data/IP exposure, unapproved employee AI use, misinformation, data loss) while only 27% paused or slowed deployment; 33% saw shadow AI because approved tools were too slow to arrive; 80% spend more time on AI risk than a year ago (+26% hours) and 98% plan higher AI-governance technology budgets (+25% average) [vendor-commissioned survey — S-2026-09-14-onetrust-ai-ready-governance-report-2026]. The prescription — “Static rules worked … when a person made every decision. Now, judgment has to live in the runtime itself, deciding and enforcing in the moment AI acts” — is the August enforcement claim restated as research framing, with no product, availability status or mechanism named [S-2026-09-14-onetrust-ai-ready-governance-report-2026]. Practitioner read (inference, not in source): the incident basket maps onto GDPR Art. 32/33 (personal-data exposure and loss) and EU AI Act human-oversight events, and “approval friction breeds shadow AI” is a governance-design point for FCA SM&CR accountability and DORA control over unsanctioned ICT tooling — but the 86% figure is not comparable to any regulatory incident definition and no EU/UK or FS cut is published [inference — S-2026-09-14-onetrust-ai-ready-governance-report-2026].
- Positions TrustWeek 2026 (28–30 Sep, Las Vegas) as the venue for “the next wave of OneTrust platform innovation” — an innovation keynote on 30 Sep by CPTO DV Lamba and CIO Blake Brannon, plus a conversation with Anthropic’s Robert Bair on privacy and compliance “when agents do the work”; the AI-governance track is described as covering “agent governance and oversight, continuous monitoring and enforcement” [vendor event release — S-2026-09-10-onetrust-trustweek-2026].
Relationships
- relates-to → EU AI Act — core regulatory regime OneTrust’s AI-governance positioning targets [S-2026-07-08-onetrust-eu-ai-act-timeline].
- relates-to → AI Governance Platforms — placed as a Visionary in the category’s inaugural MQ [S-2026-06-22-gartner-mq-ai-governance-platforms].
- competes-with → BigID — overlapping privacy/sensitive-data governance and DSPM-adjacent positioning [inference].
- relates-to → AI Governance Maturity Gap — its 2026 AI-Ready Governance Report is a further adoption-outpaces-governance survey feeding that topic [S-2026-09-14-onetrust-ai-ready-governance-report-2026].
Tracked changes
- 2026-06-22 — Corroborated as a Visionary in the 2026 Gartner MQ for AI Governance Platforms [S-2026-06-22-gartner-mq-ai-governance-platforms].
- 2026-07-08 (logged 2026-07-31) — Published EU AI Act amended-timeline guidance urging “AI-ready governance” during the extended runway; site banner claims the MQ Visionary placement; footer notes a CEO appointment (John Heyman) — appointment date unverified [S-2026-07-08-onetrust-eu-ai-act-timeline].
- 2026-08-13 (logged 2026-08-18) — Summer ‘26 Release webinar; marketing copy claims AI governance with “runtime monitoring, enforcement, and model oversight” plus agentic-AI workflow automation and audit-activity visibility. Claimed direction only — no release note, mechanism, availability status or standard ⚠️. The John Heyman CEO appointment remains visible in the site footer and remains unverified [S-2026-08-13-onetrust-summer-release-2026].
- 2026-09-08 (logged 2026-09-17; title-only capture) — Stephanie Glenn appointed Chief Revenue Officer “to accelerate growth and scale” [S-2026-09-14-onetrust-ai-ready-governance-report-2026 — related-reading block; release not fetched].
- 2026-09-10 (logged 2026-09-17) — TrustWeek 2026 announced for 28–30 Sep, Las Vegas; innovation keynote 30 Sep to “unveil the next wave of OneTrust platform innovation”; John Heyman confirmed as CEO in a dated primary release (resolves the footer-only sighting); BBVA and Fiserv among session speakers [S-2026-09-10-onetrust-trustweek-2026].
- 2026-09-14 (logged 2026-09-17) — 2026 AI-Ready Governance Report released (Sapio Research, n=1,200, eight countries): 87%/47% agent-use vs governance; 86% incident rate; 27% slowed deployment; 33% shadow AI from approval friction; 98% raising governance-tech budgets. Runtime-enforcement thesis restated; no product named [S-2026-09-14-onetrust-ai-ready-governance-report-2026].
Tensions
On the transparency-obligation date for AI-generated content:
- Source A [S-2026-05-08-eu-ai-office-article-50-transparency] (high, primary) records Article 50 transparency obligations applying from 2 August 2026.
- Source B [S-2026-07-08-onetrust-eu-ai-act-timeline] (medium, vendor) states providers are “expected to implement transparency measures by December 2, 2026”.
- Where they actually disagree: possibly nowhere — OneTrust may be citing an amended or implementation-phase milestone from the AI Omnibus final text rather than Article 50’s applicability date; the blog gives no article citation.
- Status: unresolved — check the Omnibus final text / AI Office guidance for a 2 Dec 2026 transparency milestone in a future scan.
Open Questions
- No named EU/UK regulated-FS deployment of OneTrust AI Governance in any vault source — FS adoption evidence absent.
- What does the 2 December 2026 transparency date refer to? (See Tensions.)
- ✅ (partially answered 2026-09-17) Leadership: John Heyman is quoted as CEO in a dated primary release (10 Sep 2026) [S-2026-09-10-onetrust-trustweek-2026]; the appointment date itself remains unverified. New: Stephanie Glenn as CRO (8 Sep) — title-only capture, release not fetched.
- Did runtime monitoring/enforcement actually ship in the Summer ‘26 Release, at what availability status, and does “enforcement” mean pre-execution action interception or post-hoc alerting? Requires OneTrust release notes, product documentation or the on-demand recording. Until answered, OneTrust’s entry into the enforcement locus is claimed, not established [S-2026-08-13-onetrust-summer-release-2026]. Status 2026-09-17: still open — the 14 Sep research release repeats the thesis (“deciding and enforcing in the moment AI acts”) without naming a product [S-2026-09-14-onetrust-ai-ready-governance-report-2026]; next dated check: the TrustWeek innovation keynote on 30 Sep 2026 [S-2026-09-10-onetrust-trustweek-2026].
- What are the UK/EU-country and FS figures in the 2026 AI-Ready Governance Report (four EU/UK countries are in the sample, no cut published), and what is the fieldwork period and sector mix? Requires the gated report [S-2026-09-14-onetrust-ai-ready-governance-report-2026].
- If the capability is real, does it generate retained records usable as regulatory evidence, and against which framework? Nothing in the source addresses this [S-2026-08-13-onetrust-summer-release-2026].
Sources
- S-2026-06-22-gartner-mq-ai-governance-platforms
- S-2026-07-08-onetrust-eu-ai-act-timeline
- S-2026-08-13-onetrust-summer-release-2026 — Summer ‘26 Release webinar page claiming AI runtime monitoring/enforcement (low authority; marketing page, no product substantiation).
- S-2026-09-10-onetrust-trustweek-2026 — TrustWeek 2026 event release (10 Sep 2026; low authority; event promotion, CEO confirmation, 30 Sep innovation keynote).
- S-2026-09-14-onetrust-ai-ready-governance-report-2026 — 2026 AI-Ready Governance Report press release (14 Sep 2026; low authority; vendor-commissioned survey, gated report not read).
- S-2026-09-18-weekly-vendor-synthesis → S-2026-09-18-weekly-vendor-synthesis — weekly vendor-synthesis (own-writing): runtime-enforcement open-question continuity read.