Thursday, September 17, 2026
Advertisement
HomeEnterprise AIExpel Launches MDR for AI, Opens Early Access for Anthropic Claude Integration

Expel Launches MDR for AI, Opens Early Access for Anthropic Claude Integration

0
(0)

Most security tools that watch how employees use AI can tell you that someone used it. They can’t tell you why. Expel, a managed detection and response (MDR) provider, is trying to close that gap with a new product line called MDR for AI — and its first concrete step is a Claude integration that reads prompt content itself, not just the activity logs around it.

Expel announced the launch at Black Hat USA on August 4, 2026, and confirmed it as shipped in its regular product recap published September 1, 2026. Three things went live at once: an early-access integration with Anthropic’s Claude, a detection library mapped to the MITRE ATLAS framework for AI threats, and a set of AI-focused threat-hunting techniques for existing hunting customers.

What Expel Announced

Expel’s pitch is that AI security has an ownership problem inside most companies — everyone agrees it’s a risk, but nobody agrees who’s responsible for watching it. Rather than building a separate program from scratch, Expel is extending the MDR service it already sells, pointing the same analysts and the same platform at a newer kind of risk.

Advertisement

The company frames this as coverage across three fronts: attacks launched using AI, risky AI use by employees, and exposure inside the AI systems a company builds itself. Whether that adds up to the “full AI attack surface,” as Expel describes it, is the company’s own characterization — a claim of market completeness that trade press has not independently audited.

What’s actually shipped, according to Expel’s own posts, breaks down cleanly:

CapabilityStatus
MDR for AI (overall program)Live
Anthropic Claude integrationEarly access
MITRE ATLAS-mapped detectionsLive
AI-focused threat huntsLive (hunting customers only)

Timeline:

  • August 4, 2026 — Announced at Black Hat USA
  • September 1, 2026 — Confirmed shipped in Expel’s monthly product recap

That distinction matters. Only one of the three pieces — the Claude integration — is still gated behind an access request. The other two are already running for existing customers, and neither depends on whether a company uses Claude at all.

The Anthropic Claude Integration, In Detail

The centerpiece of the launch is Expel’s integration with Anthropic’s Claude. According to Expel, it pulls Claude Enterprise Compliance signals — usage activity and prompt content — directly into its detection pipeline, with detections spanning what the company calls the control plane and the content plane. Independent reporting from MSSP Alert adds a third data category: Expel pulls usage activity, prompt content, and tool use from the Claude Compliance API into its detection pipeline, giving analysts more context around how the tool is being used and what users or systems are trying to do.

That second word — content — is the notable part. Expel says most AI monitoring tools today log activity — who logged in, when, from where, what admin settings changed — but stop there. Its operators, the company says, go a step further and read the prompt content itself, looking for signs of intent rather than just a record that a conversation happened.

Access isn’t self-serve yet. Early access is open now for Claude.ai, and companies interested have to ask their Expel customer success manager to submit a request — a detail that signals a controlled early rollout rather than a broad general release. Expel has not published a timeline for when, or whether, the integration will move beyond early access.

Several operational details are simply not public. Expel hasn’t disclosed how prompt content is secured, retained, or restricted once it enters the detection pipeline — a reasonable question for any company handling potentially sensitive employee prompts. Nor is it clear whether the integration covers Claude usage through the API or Claude Platform, since Expel’s own language specifies Claude.ai.

Why Prompt-Content Analysis Matters

Expel’s own framing is direct: most coverage stops at activity logs, which tell you what happened but not why. Our operators work the prompt content itself, so we surface intent instead of just activity.

It’s a meaningful distinction in principle. As a general illustration of the distinction: an activity log alone might only show that a session took place, without indicating what happened during it, while reviewing the prompt content itself could reveal whether the conversation involved routine work or something that raises concern, such as an attempt to extract sensitive data or work around a policy. But this is Expel’s own characterization of what its analysts do with the data; no independent technical review of the detections themselves, or how effectively they distinguish intent from noise, was found in reporting on the launch.

MITRE ATLAS Mapping and Detection Coverage

The second piece of the launch doesn’t touch Claude at all. Expel has labeled its detection library everywhere AI is a factor and mapped it to MITRE ATLAS — the Adversarial Threat Landscape for Artificial Intelligence Systems, a framework built specifically to catalog how attackers target AI and machine learning systems, distinct from the more general MITRE ATT&CK framework used for traditional IT threats.

Expel says its coverage today spans 13 of the 16 tactics in the ATLAS framework, a figure the company repeated on the record to MSSP Alert. That fraction is at least internally consistent: MITRE ATLAS’s current published framework version does define 16 total tactics, so Expel’s claim isn’t an arbitrary number. What Expel hasn’t disclosed is which three tactics remain unmapped, or what a customer should expect to be missing as a result.

Crucially, this mapping runs across a customer’s existing telemetry — endpoint, identity, cloud, SaaS, and network data Expel already collects through more than 160 integrations. It doesn’t require the Claude integration to function. As Expel’s Sarah Crone put it to MSSP Alert, the ATLAS-mapped coverage and the AI-focused hunting work “aren’t Claude-dependent. They run across whatever’s already in a customer’s environment.”

Human-Led, Not Autonomous

Underlying all three capabilities is a specific operating philosophy Expel has been vocal about: humans, not autonomous AI agents, make the calls.

“You can’t out-automate an attacker who’s using the same AI you are,” Expel co-founder and Chief Strategy Officer Justin Bajko said in the company’s announcement. “The models change weekly. What doesn’t change is the judgment call in the middle of an incident, because that’s still a human thing.”

That extends specifically to how Claude data is handled. “Expel’s operators investigate every signal themselves,” Crone told MSSP Alert. “AI speeds them up, but it doesn’t make the call. That includes the Claude integration above: our people work the prompt content directly instead of handing it to an agent.”

Alex Glass, Expel’s vice president of global channel sales and alliances, framed it as a market-wide question: “The question is not whether AI belongs in the SOC. It does. The question is whether removing human judgment is the right decision for customers today, and we do not believe it is.” These are statements of company philosophy and positioning, not independently verified claims about how consistently that philosophy is applied in practice.

What’s Not Yet Live

It’s worth being precise about the current limits of the launch. At the time of announcement, Claude was Expel’s only live AI-native model integration — there is no equivalent integration yet for other large language model providers. Expel has said more are coming: “Claude’s the first of several,” Crone told MSSP Alert, describing plans for additional AI-native integrations covering prompt injection and telemetry generated by AI agents, spanning both model providers and AI-specific endpoint protection tools, with rollout continuing “through this year and moving forward.” None of that is available today.

There’s also no multi-tenant or MSSP-focused version of the product. “MDR for AI is built for enterprise environments today,” Crone said. “Multi-tenant and partner-led delivery for MSSPs isn’t a current focus, but they’re factored into the roadmap as demand develops.” Managed service providers hoping to resell this capability to their own customers will need to wait.

Limitations and Open Questions

Several relevant details simply aren’t public yet, and it’s worth naming them rather than guessing:

  • Timeline to general availability for the Claude integration is not disclosed.
  • Data handling for prompt content — how it’s secured, how long it’s retained, who can access it — has not been described by Expel.
  • Independent technical validation of the detections themselves, beyond Expel’s and one interviewed spokesperson’s account, was not found.
  • Anthropic has not been found publicly confirming this specific integration. Anthropic did launch a broad Claude Compliance API program for enterprise security and compliance partners in May 2026, which appears to be the underlying technical channel Expel is using, but Expel does not appear in the partner lists reported around that original launch — suggesting it was added afterward. That’s a reasonable inference, not a confirmed fact.

None of this means the launch isn’t real — Expel’s own posts and independent trade coverage agree on the substance of what shipped. It means the offering is early, single-vendor, and still short on the operational detail that security buyers typically want before committing.

Conclusion

Expel’s MDR for AI is a genuine product launch, not vaporware: three capabilities went live in August 2026, and Expel confirmed them again in its September recap. The most technically interesting piece — reading Claude prompt content for intent rather than just logging activity — is also the most limited, restricted to early access and gated behind a request to Expel’s sales team.

The ATLAS-mapped detections and AI-focused hunts are further along and don’t depend on any one AI vendor, which may end up being the more durable part of this launch as Expel’s roadmap unfolds. What happens next is worth watching: whether the Claude integration reaches general availability, whether Expel adds integrations with other model providers as promised, and whether the company discloses more about how it handles the prompt content it’s now collecting.

Frequently Asked Questions

Is Expel’s Anthropic Claude integration generally available? No. As of the August 2026 launch, it’s in early access. Interested companies must request access through their Expel customer success manager. Expel has not published a general-availability date.

What data does Expel’s Claude integration actually pull in? Claude Enterprise Compliance signals, which Expel and independent reporting describe as usage activity, prompt content, and tool use. Expel says this feeds detections across both what it calls the “control plane” and the “content plane.”

Does Expel’s MITRE ATLAS mapping require the Claude integration? No. Expel has said explicitly that its ATLAS-mapped detection coverage and AI-focused threat hunts run across telemetry it already collects from a customer’s existing environment, independent of whether that customer uses Claude.

How do I get access to Expel’s Claude integration? Through Expel’s customer success team — it’s not self-serve. Interested customers are directed to ask their CSM to submit a request.

Is Claude the only AI platform Expel’s MDR for AI supports? At launch, yes — Claude is described as Expel’s first AI-native integration, with more model providers and AI security platforms planned for later in 2026 and beyond. Those additions are roadmap items, not currently available.

Does Expel use AI agents to review the prompt content it collects? According to Expel, no. The company says human analysts review prompt content directly rather than handing that work to an autonomous agent, as part of a broader “human-led, AI-accelerated” approach it applies across its MDR service.

Is this available to MSSPs or only direct enterprise customers? Currently only enterprise customers. Expel has said multi-tenant or partner-led delivery for managed service providers isn’t a current focus, though it’s on the roadmap as demand develops.

Was this article helpful?

Rate this article from 1 to 5 stars.

Average rating: 0 / 5. Reader ratings: 0

No ratings yet. Be the first to rate this article.

Thank you for your feedback

Help us improve this article.

What information was missing or could be improved?

RELATED ARTICLES
Advertisement

Most Popular