This is a broad release, and most of it is about precision. It sharpens who FireTail can attribute AI usage to, makes governance adaptive so it improves as your workforce uses AI, and adds harder access controls like restricting AI to corporate accounts.
This is a broad release, and most of it is about precision. It sharpens who FireTail can attribute AI usage to, makes governance adaptive so it improves as your workforce uses AI, and adds harder access controls like restricting AI to corporate accounts. The throughline is the one we keep coming back to: see what AI is running across your organization, govern how it gets used, and be ready to show your posture when someone asks.
Here is everything that shipped, grouped by the job it does.
Knowing that AI is in use is only half the picture. This release focuses discovery on who is behind it.
Workforce identity attribution. The endpoint agent now discovers AI provider account identities on devices and links them to the people behind them, including when someone signs in with more than one account. Instead of knowing that someone in the org used a given AI tool, you get the person, the device, and the accounts involved. That attribution is what makes the per-person governance later in this release possible.
Consistent ChatGPT detection. ChatGPT usage is now detected and logged whether the user is signed in or browsing anonymously, closing a gap where anonymous sessions could slip past.
Discovery in more places. In code, FireTail now detects AI usage in repositories built with crewAI and legacy LangChain versions, and repository analysis recognizes a wider range of usage patterns. In the cloud, another AI platform joins the catalogue of services FireTail discovers and monitors.
Also in discovery this release:
Cleaner logs, with more of what matters and less of what does not.
Blocked-domain action logging. The browser extension now logs blocked-domain actions specifically, so you get granular visibility into exactly when domain-blocking policies are enforced rather than inferring it from surrounding activity.
Show Image
Also in logging this release:
Governance is where this release put most of its weight, and the theme running through it is precision: rules that fit the person, the topic, and the way people actually prompt.
Adaptive topic guardrails. Topic guardrails now learn from real usage. When a prompt matches a topic, it is captured as a new example, so the guardrail sharpens over time, and sensitive content such as email addresses is masked before anything is stored. The result is a topic that FireTail surfaced from real activity, scored for risk, with the prompts that matched it in view.

Custom topics, with risk scores. You can define and manage custom topics for Prompt Intelligence, with automatic sub-topic generation and example embedding, so you control which conversation subjects are detected and governed. Each topic carries a risk score, so you can rank them and put governance attention where it matters most.

Restrict AI to corporate accounts. When you create or edit an AI Workforce Policy, you can now set the email domains allowed per platform. Requests from outside those domains are blocked, which gives you a clean way to keep people on corporate accounts and off personal ones. Availability varies by platform.

Enforcement that is harder to slip past. Blocking guardrails are now evaluated before informational ones, so an enforcement action is never skipped because an informational match came first. System topic policies are scheduled and enforced automatically alongside workforce log policies, so organizations on the workforce product get that enforcement without extra setup. And endpoint devices are notified in real time when topic data changes, so they always enforce against the latest definitions.
Also in governance this release:
Google SecOps integration (preview). You can now set up a Google SecOps (Chronicle) integration from the integrations page to forward FireTail findings into your Chronicle instance, so AI findings land in the SecOps workflow your team already runs. This one is available as a preview.

A round of deployment and platform work that makes the agent easier to run at scale and the console easier to move through.
On deployment, Windows now offers transparent, TUN-based traffic interception alongside the existing proxy mode, in-place Windows upgrades preserve your configuration, certificates, and device identity so only fresh installs need a token, and the agent installs and trusts its CA inside WSL2 automatically, so FireTail works there with no extra configuration. The macOS installer gained better support for MDM and RMM fleet deployments, and the agent now recovers cleanly from crashes on both Windows and macOS.
In the console, panels stack with a breadcrumb trail and full back and forward support so you keep your place, resource names are clickable throughout, dashboards take custom date ranges down to ten-minute granularity, and filtering gained name search, suggestions across resource types, and color-coded quota bars. Rounding it out: distributor access management for EU and US regions, faster application startup, stricter SCIM email uniqueness, clearer loading and empty states, and a set of stability fixes.
The fastest way to know what this finds is to point it at your own setup. Book a call and we will walk it with you.