RXed AI News

AI to the bone.
@RXed_EU
Audited 2026-08-13 · RXed table v1.0

OneTrust

Visit onetrust.com
“The AI-Ready Governance Platform” — the vendor’s own words

14,000 customers, 300+ patents and the only AI governance vendor here that already had the enterprise installed base before the category existed. Runtime guardrail enforcement shipped in March 2026 and that is the real move. Read the release notes though: AI Policy Manager and guardrail enforcement were still public preview in the May 2026 release, and the median contract of $11,835 tells you nothing about what an AI governance deployment costs.

Best for: Large enterprises already running OneTrust for privacy, third-party risk or GRC, where AI governance is a module purchase rather than a new vendor and the registry can inherit an existing data map. Also multinationals that need EU AI Act, NIST AI RMF and ISO 42001 work backed by DataGuidance regulatory research across 300+ jurisdictions. Wrong fit for SMBs, for lean teams without dedicated GRC resource, and for anyone needing value inside weeks rather than a configuration project.
Scope15/20
Quality6/10
Where the quality sits
6Reactive
4Retrieval & Memory
7Orchestration
7Validation
6Models
Enterprise platformSecurity & ComplianceAutomation & AgentsProductivityPaid
Vendor
OneTrust, LLC · www.onetrust.com
Origin
US — Atlanta, Georgia
Pricing
Single module (e.g. Consent & Preferences) Quote only · AI Governance module Quote only · Multi-module enterprise Quote only
Users (official only)
More than 14,000 customers globally, including over half of the Fortune 500 (source, 2025-09-29)
Single module (e.g. Consent & Preferences)Quote only$10,000 minimum annual contract from Q2 2026; the low end of the Vendr range sits here
AI Governance moduleQuote onlypriced separately within the platform; discovery connectors for Bedrock, Databricks, Google Cloud and Azure Foundry are marked 'available with solution packaging only'
Multi-module enterpriseQuote onlyobserved $120,000-$500,000+/yr for 5,000+ employee organisations with multi-entity deployments

Modular pricing is the thing to model before signing. The headline median is a privacy-module number, not an AI governance number, and buyers consistently report that key capabilities sit behind additional paid modules. Several of the 2026 AI discovery connectors are gated behind solution packaging rather than included. Independent reviews put the recurring complaint at implementation effort rather than licence cost: most teams spend weeks in configuration before first value.

checked 2026-08-13 · vendor pricing page

Element scores

Reactive
Retrieval & Memory
Orchestration
Validation
Models
Primitives
Pr6
Prompts
Em5
Embeddings
Cx8
Context
Tr8
Tracing
Lg6
LLM
Compositions
Fc7
Function calling
Vx4
Vector store
Rg7
RAG
Gr8
Guardrails
Mm
Multimodal
Deployment
Ag7
Agents
Ft
Fine-tuning
Fw8
Frameworks & harnesses
Ev6
Evaluations
Sm
Small models
Emerging
Ma4
Multi-agent
Sy
Synthetic data
Pc7
Protocols
In5
Interpretability
Th
Thinking models
Tap or hover any element to see why it got that score.

Strengths

OneTrust arrived at AI governance with something no purpose-built competitor has: 14,000 customers, over half the Fortune 500, 300+ patents and a platform their compliance teams already live in. The March 2026 expansion is the substantive move, because it took the product from documenting AI to acting on it. Runtime guardrails filter prompts and outputs, block or allow actions by policy, mask and redact sensitive data, and force re-review whenever a model, agent, dataset or usage pattern materially changes. The registry design behind it is unusually honest for a vendor page: it states plainly that the registry is the record layer, workflows are the process layer, and runtime controls are the enforcement layer, and that you need all three. Change history is treated as a first-class problem, on the correct reasoning that a prompt update or a retrieval-source swap changes risk without changing the product name. The developer surface is the deepest in the category, with REST endpoints across every module, downloadable OpenAPI definitions, OAuth 2.0 and 200+ pre-built integrations, and automated AI discovery now reaches into Bedrock, SageMaker, Vertex, Azure Foundry and Databricks Unity Catalog. Gartner named OneTrust a Visionary in the inaugural Magic Quadrant for AI Governance Platforms in 2026, citing discovery and registry, dynamic risk scoring, workflows and approvals, and evidence and audit trail.

Honest dings

Start with the preview labels. AI Policy Manager, seeded AI policies and Guardrail Detection & Enforcement were all listed as public preview features in the 15/05/2026 release, and several of the cloud discovery connectors are marked available with solution packaging only. The March press release and the solutions page read as shipped; the release notes read as in progress, and the gap between those two documents is exactly what a buyer needs to close before signing. Second, the implementation cost is the real cost. Independent aggregation of G2, Capterra, Software Advice and Trustpilot scores OneTrust 6/10 on ease of use, 6/10 on support and 6/10 on pricing and value against 8/10 on features, with a steep learning curve, incomplete cross-module integration and limited reporting customisation as the recurring themes. Professional services run 20% to 40% of year-one subscription. Third, the modular model means the quoted median is close to meaningless for an AI governance buyer, and several key capabilities are separate line items. Fourth, on the AI itself: no model is selectable, no eval surface exists for OneTrust's own output, and the Guardian Agents page describes a Gartner framework rather than a named shipped product. The public MCP endpoint currently requires no authentication headers, which is fine for a documentation server and worth understanding before you point an agent at it.

Prices and details change — this passport is re-verified at least quarterly.
Sources (19) — every claim traceable

Every audit lists the research it rests on — transparency and traceability are the product. Tools evolve: each audit is a snapshot of its audit date, and re-audits supersede older versions (kept below for reference).

  • onetrust.com/solutions/ai-governance — Official solution page: three pillars (catalog and assess, monitor posture, programmatically enforce); runtime guardrails with prompt and output filtering, block or allow by policy, sensitive data masking and redaction, required evaluations before production promotion, re-review on material change; agent and MCP environment governance with enforced permissions and audit logs; EU AI Act, NIST and ISO 42001 templates (accessed 2026-08-13)
  • globenewswire.com/news-release/2026/03/09/3251861/0… — Official 09/03/2026 announcement at Gartner Data & Analytics Summit: AI agent detection and inventory, AI policy manager and policy library, AI guardrail enforcement; integrations named as Amazon Bedrock, Amazon SageMaker, Azure Foundry, Azure OpenAI, Databricks Unity Catalog and Google Vertex; DV Lamba quote on moving from point-in-time compliance to continuous runtime control (accessed 2026-08-13)
  • my.onetrust.com/s/article/UUID-0bcc6930-b07a-73e1-c… — Official Spring Release notes 15/05/2026 (202605.1.0): AI Agents Inventory; automated AI discovery for Bedrock, Databricks, Google Cloud and Azure Foundry marked 'Available with Solution Packaging Only'; AI Policy Manager & Seeded AI Policies and Guardrail Detection & Enforcement listed under New Public Preview Features; all environments upgraded to new AI Governance Services (accessed 2026-08-13)
  • onetrust.com/solutions/ai-governance/ai-discovery-a… — Official: registry as system of record versus workflow as process layer versus runtime as enforcement layer; lifecycle states from proposed through retired; record-level change history covering prompt updates, model swaps, retrieval-source changes and new agent actions triggering reassessment (accessed 2026-08-13)
  • onetrust.com/solutions/ai-governance/ai-policy-mana… — Official: policy statements, applicability conditions on risk level, geography, data sensitivity and deployment type, control requirements, exception records with compensating controls, approving authority and expiry; explicit statement that policy management defines what should be enforced while runtime controls execute it (accessed 2026-08-13)
  • developer.onetrust.com/onetrust/reference/mcp — Official developer docs: remote MCP endpoint at developer.onetrust.com/mcp for Cursor and Windsurf, giving API access, documentation search, real-time account data and code generation; states no authentication headers are currently required (accessed 2026-08-13)
  • developer.onetrust.com/onetrust/reference/onetrust-… — Official API reference: all endpoints RESTful over HTTPS, API key in HTTP header, OAuth 2.0 client credentials and API keys created in Global Settings, SCIM endpoints excepted, OpenAPI and Swagger definitions downloadable (accessed 2026-08-13)
  • onetrust.com/guardian-agents — Official: MCP governance risks (tool access proliferation without ownership record, delegation chains obscuring accountability, session-level risk invisible to model-level controls); positions OneTrust as the oversight layer for Gartner AI TRiSM Guardian Agents rather than naming a shipped agent product (accessed 2026-08-13)
  • onetrust.com/blog/onetrust-debuts-as-a-visionary-in… — Official 22/06/2026: Visionary placement in the inaugural Gartner Magic Quadrant for AI Governance Platforms; capabilities Gartner cited were AI Discovery and Registry, Dynamic Risk Scoring, Workflow and Approvals, Evidence Collection and Audit Trail, AI Usage Reporting and Data Usage Mapping (accessed 2026-08-13)
  • onetrust.com/about-us — Official: 2,000 employees, 13 global offices, trusted by over half the Fortune 500, founded 2016; CEO John Heyman with founder Kabir Barday on the board. Note the page publishes no customer count (accessed 2026-08-13)
  • prnewswire.com/news-releases/onetrust-accelerates-m… — Official press release 29/09/2025: more than 14,000 customers globally including over half the Fortune 500, half the world's 10 largest banks and airlines, seven of the 10 largest healthcare and retail companies; 74,000 sq ft Atlanta HQ, 13 global offices (accessed 2026-08-13)
  • prnewswire.com/news-releases/onetrust-debuts-on-for… — Official 15/09/2025: Fortune Future 50 debut at #46; names privacy and risk agents, Copilots, AI-driven workflows and automated policy enforcement as shipped capabilities; partners named as Adobe, Databricks, Microsoft and Snowflake (accessed 2026-08-13)
  • helpnetsecurity.com/2026/03/10/onetrust-expands-ai-… — Independent coverage 10/03/2026 of the runtime monitoring and guardrail enforcement expansion (accessed 2026-08-13)
  • siliconangle.com/2026/03/09/onetrust-expands-platfo… — Independent coverage 09/03/2026: continuous inspection of GenAI, traditional ML models and agents to validate guardrail configurations and detect violations in real time (accessed 2026-08-13)
  • sprinto.com/blog/onetrust-review — Independent review (competitor-authored, treat directionally), updated 21/07/2026, aggregating G2, Capterra, Software Advice, Trustpilot, Reddit, Vendr and Spendflo: overall 7.5/10, ease of use 6/10, support 6/10, pricing and value 6/10, features 8/10, integrations 8.5/10; 50+ pre-mapped frameworks, 300+ jurisdictions via DataGuidance, 200+ integrations, 14,000 customers, 300+ patents; cons listed as steep learning curve, escalating modular pricing, limited reporting customisation, incomplete cross-module integration, annual contracts only (accessed 2026-08-13)
  • consentstack.io/blog/onetrust-pricing — Independent procurement analysis: Vendr median $11,835/yr across 306 purchases, range $1,620 to $47,622, $10,000 minimum annual contract from Q2 2026; by size $10,000-$40,000 under 1,000 employees, $40,000-$120,000 for 1,000-5,000, $120,000-$500,000+ for 5,000+; implementation 20-40% of subscription in year one plus 5-10% training (accessed 2026-08-13)
  • en.wikipedia.org/wiki/OneTrust — Independent reference, last updated 30/06/2026: 14,000+ customers and 300+ patents as of 2025, March 2026 AI-Ready Governance brand positioning, Privacy Breach Response Agent built with Microsoft Security Copilot, Azure OpenAI integration, AI-based features added to DataGuidance regulatory research in 2024 (accessed 2026-08-13)
  • tracxn.com/d/companies/onetrust/__ze9yaIbvxYzoxTM_y… — Independent company record, 05/08/2026: $1.13B raised across 7 rounds, latest Series D $150M on 24/07/2023, valuation $4.5B, 2,487 employees as of 31/05/2026, Atlanta HQ, founded 2016 (accessed 2026-08-13)
  • forbes.com/companies/onetrust — Independent, stats as of March 2026: 14,000+ companies using the platform, $1.1B raised, $4.5B valuation, $500M annual recurring revenue, CEO Kabir Barday listed (accessed 2026-08-13)