AI You Can Actually Govern: What the OneTrust Summer Release Means For Your Team

See what the OneTrust Summer Release means for AI governance, privacy and data teams, and how new capabilities can help organisations manage AI with greater control.

In This Article:
Speak To Our Team

Have a question, or want to start your trust journey? Connect with one of our experts today

Every software release comes with a list of new features. The useful question is rarely “what is new”, it is “so what”. What actually changes for the team on Monday morning, and why does it matter enough to spend time on? We sat through the OneTrust Summer Release so you can skip to the part that matters: where the genuine operational value is, and how to capture it.

Here is our honest read. This release quietly moves OneTrust from governing risk on paper to governing it in the live environment. That is a bigger shift than any single feature, and it is worth understanding before you decide what to switch on first.

The big idea: governance that runs where your AI runs

Most organisations have already done the hard thinking. They have written AI policies, defined what good looks like, and agreed what is and is not acceptable. The gap has always been proving that those standards actually hold at runtime, across the different platforms where AI is really being built and deployed.

The headline of this release, Runtime Governance, closes that gap, and it is generally available now. OneTrust connects to the environments where you build and run AI, such as AWS Bedrock, Azure AI Foundry and Databricks, discovers the AI systems and agents running there, checks them against your policies, and validates that guardrails such as content filters, prompt-injection protection and sensitive-data controls are genuinely in place. Where a guardrail is missing, it can push the fix, either as code a developer copies in, or enforced natively in the cloud platform itself.

So what: in the live demo, an ungoverned agent leaked sensitive data in its response. It was flagged as a policy violation, and after a single click the same prompt came back with the sensitive data redacted. That is the distance between “we have a policy” and “the policy is working” closing in real time.

Why it matters for you: this is where AI risk actually lives. A policy in a document does not protect you if nobody can show it is enforced inside AWS or Databricks. Runtime Governance gives you continuous, exportable evidence for regulators, boards and auditors, and it turns the signals that matter, evaluation metrics, token usage, guardrail activity and PII exposure, into something your team can see and act on. It also shrinks two risks that keep security leaders awake: shadow AI, and ungoverned agents quietly doing things nobody approved.

Three more moves worth your attention

Knowing your models, without the manual research

If your teams assemble AI from frontier models, someone is currently spending real hours researching those models: chasing provider documentation, model cards and disclosures, then reconciling conflicting notes across separate reviews. Third-Party GenAI Intelligence replaces that with an always-current, sourced view of each model’s capabilities, limitations and known risks, attached straight to your inventory record. So what: your model reviews become consistent and fast, anchored in shared facts rather than one person’s research from three weeks ago.

Seeing the AI nobody told you about

Through a new native integration with Cloudflare, OneTrust can bring signals about the AI tools your employees are actually using into your governance workflow. So what: shadow AI stops being a blind spot. You get a real list of the AI applications in use across the business, you can see which ones were never sanctioned, and you can start the enforcement or assessment process with a few clicks. In the demo, a very widely used AI assistant appeared that the organisation had never formally approved. Most enterprises have exactly this, they just cannot see it yet.

The one that saves weeks: the Third-Party Risk Agent

If you run third-party risk, you know the real bottleneck is not your process, it is waiting on the vendor to respond, and hoping the response is complete and accurate. The new Third-Party Risk Agent, generally available now, removes most of that wait. Give it a vendor name and web domain and it creates the record, suggests a questionnaire, ingests any documents you provide such as a SOC 2, then crawls the vendor website and a broad range of public sources to fill the gaps. It produces a fully referenced risk report and answers the questionnaire itself, each answer carrying a source link and a confidence score.

So what: in the demo it assessed a vendor against a 208-question industry questionnaire and answered 186 of them, from a single SOC 2 plus deep research, without ever sending the questionnaire to the vendor. Work that routinely takes weeks, sometimes months, came back in roughly ten to fifteen minutes.

Why it matters for you: slow vendor assessments do not just frustrate the risk team, they hold up the business. New suppliers, product launches and growth initiatives all wait on this step. Compress it to minutes and you unblock revenue, not just compliance. One practical note: the report scopes to whatever questionnaire you choose, so the quality of the output depends on setting it up around your own risk tiers, which is exactly the kind of thing worth getting right at the start.

For the privacy and consent teams

Global Privacy Preference brings a seamless, compliant “do not sell” experience to OneTrust CMP. It connects a person’s local choice to a single global privacy preference, recognising both manual opt-outs and browser signals such as GPC, so the choice carries through to your tags, vendors and analytics rather than stopping at the banner. So what: the common failure, where an opt-out is honoured on the banner but never reaches the systems that actually activate data, gets closed, which lowers CCPA risk and gives you one source of truth for enforcement. Helpfully, it lives in CMP, so you do not need Privacy Rights Automation to use it.

The California DROP integration connects OneTrust directly to California’s new Delete Request and Opt-out Platform, the centralised deletion mechanism under the state’s Delete Act. Registered data brokers must pull and fulfil consumer deletion requests at least every 45 days. OneTrust pulls those requests, matches the hashed identifiers against your own secure database to find where you actually hold the data, and routes matches into your normal deletion workflow for automated, batched fulfilment. So what: a brand-new regulatory obligation becomes a configured, largely automated part of a process you already run, rather than a manual scramble every six weeks. If you could be classed as a data broker, this is the timely one.

Rounding out the release, Bulk Export for CMP finally lets business users export consent data with a few clicks rather than wrestling with APIs, Activity Log (previously Global Audit) gives administrators one real-time, searchable view of activity across every solution that can feed your SIEM, and the first phase of Attribute-Based Access Control (ABAC) brings record-level, least-privilege access so people get exactly the access they need, and no more.

So, what should you do with all this?

Our advice is simple. Do not try to switch everything on at once. Start where the value is closest and the effort is lowest, then build from there.

  • If you run third-party risk: try the Third-Party Risk Agent this week. It is available now, and the time saved is obvious from the first assessment.
  • If you build AI in the cloud: Runtime Governance is the strategic one. It is worth a proper look at how it maps to your existing policies.
  • If you are US-facing or a data broker: the California DROP integration is deadline-driven. Get ahead of it rather than behind it.
  • If you worry about shadow AI: the Cloudflare discovery integration is a fast way to finally see what is out there.

How The DPG can help

As a OneTrust partner, our job is to turn features into operational advantage. Switching a capability on is the easy part. The value comes from configuring it around your policies, your risk tiers and your systems, and embedding it into the way your teams actually work. Whether that is translating your AI policies into runtime rules, tuning the risk agent to your vendor tiers, mapping consent choices through to every downstream system, or standing up the DROP matching workflow, we can help you get from “switched on” to “delivering value”, quickly and safely.

Talk to us about a short working session on the release. We will help you decide what to enable first, and build the plan to operationalise it.

Note: some features described here are generally available now, while others are in public preview and need to be switched on via a support request in MyOneTrust or through your account team. All AI-powered capabilities require AI to be enabled in your environment.

Sources: OneTrust Summer Release webinar, 13 August 2026; CPPA data brokers / DROP.

iain borner the data privacy group - The Data Privacy Group

Contact the Author

Iain Borner
Co-Founder and CEO

As Co-founder and CEO of The Data Privacy Group, Iain Borner leads our mission to empower businesses with top-tier data protection services and foster Digital Trust across all customer touchpoints. With an extensive background in data privacy management, he is passionate about safeguarding businesses’ reputations, revenues and relationships in this digital age. It’s about steering organisations towards a future where Digital Trust is their most invaluable asset.