Employees can activate an agent and delegate their identity. Agents working autonomously can also use their own identity without a human delegating permissions.
Introducing Rippling AI Governance: Get your AI house in order

In this article
Today, we're introducing Rippling AI Governance, a suite of products that helps companies scale AI usage without losing track of spend, access, or accountability. It connects AI activity to the workforce context already in Rippling, so companies can move from reacting to AI sprawl after it happens to governing AI at the moment it's used.
Built on Rippling's employee graph, AI Governance gives IT leaders one place to understand AI usage and spend, control access to models and tools, and manage agents throughout their lifecycle, with policies that map to each employee's team and role.
AI adoption has outrun AI governance
Companies are under pressure to scale AI, but the systems to govern it haven't kept up. Leaders face three problems:
They can't see or control AI usage and spend. Data is scattered across vendor consoles, invoices, API logs, spreadsheets, and unmanaged accounts. Finance sees the spend after the fact, while IT has to explain what changed without a reliable view of the people, teams, models, and workflows driving it.
They can't reliably secure what employees and agents can access or do. Model access, tool permissions, and data security policies live across separate systems. Controls are often manual, vendor-specific, or applied only after access has spread.
They can't reliably identify and manage agents. Agents often run through shared keys, generic service accounts, or repurposed employee credentials. That makes it difficult to determine who is responsible, what an agent can access, what it has done, and what should happen when its owner changes roles or leaves.
That leaves companies with two bad options: move quickly and accept rising costs and security risks, or lock AI down and miss out on productivity gains.
Govern AI usage, spend, access, and agents from one platform
For leaders tasked with efficiently scaling AI across their organisation, Rippling AI Governance is a set of software tools that allows companies to measure and control AI usage. This is a suite of products that, taken together, give admins a comprehensive set of controls for managing the use of AI within their organisation. Rippling routes employees' LLM traffic, governs tool access, surfaces unsanctioned AI usage, and manages agent identity, all through the organisational context that makes policies enforceable. Our promise is to help companies scale AI adoption without losing control of spend, access, or auditability.

What we're launching
MCP Gateway
AI agents become useful when they can act on information, not simply answer questions. An AI agent decides how to complete a task. Model Context Protocol, or MCP, connects it to the tools, data, and systems it needs to do so. An MCP Gateway controls which of those connections and actions are allowed.
As employees connect AI tools to more business systems, every unmanaged connection creates another path to sensitive data that IT can't reliably see, control, or audit. IT may not know what is connected, who is using it, or what actions they can take once connected.
Rippling MCP Gateway gives IT a controlled entry point for supported MCP connections. The model is familiar: IAM governs which SaaS apps employees can access. MCP Gateway governs which company systems employees and agents can reach through AI, and what they can do once connected. Before a tool call runs, Rippling checks who is making the request and whether the relevant policy allows it. The call is then recorded for review.
That control goes deeper than deciding whether a connection can exist. An engineer may have broad access to GitHub, but an AI agent working on their behalf shouldn't automatically receive the same permissions. The agent might be allowed to read approved repositories and open pull requests, while being blocked from deleting branches, changing repository settings, modifying secrets, force-pushing code, or accessing security-sensitive repositories outside the engineer's team. MCP Gateway governs what an agent can do through a connection, not simply whether it can connect.
Because Rippling already knows each employee's role, team, and employment status, access updates automatically when employees join, change roles or teams, or leave the company. A standalone gateway has to import and maintain that context from external identity systems. Rippling starts with it.
With Rippling MCP Gateway, companies can connect AI to more of the business without losing control of who can access each system or what they can do within it.

Rippling MCP Gateway applies the same identity based access controls companies already use for SaaS apps to MCP connections. Permissions update automatically when employees join, change roles, or leave.
AI Gateway*
AI spend is becoming one of the hardest software costs for companies to manage. Employees and agents can call OpenAI, Anthropic, Google, and other providers directly, often across multiple tools and subscriptions. Finance sees the bill after the fact. IT sees only part of the access picture. And leaders struggle to answer the basic questions: who is using which models, which teams are driving spend, and where should usage be limited or optimised?
Rippling AI Gateway gives companies one governed path for LLM traffic. It sits between employees, apps, agents, and model providers, so admins can control access to models, set budgets, enforce spend limits, and log usage with the employee and organisation context already in Rippling.
That matters because AI governance is not just about saying yes or no to AI. It is making sure the right people have the right level of access, at the right cost. A security engineering team may need frontier models for complex work, while other teams can be steered towards faster, lower-cost models for everyday tasks. With AI Gateway, companies can route the right traffic to lower-cost models, set hard budget caps, and block usage when limits are reached.
The result is governance and spend management in the same system. Companies get visibility into model usage and cost by user, team, department, provider, and model, auditability for every request, and controls that apply at the moment AI is used, not weeks later when the invoice arrives.

Rippling AI Gateway enforces model access and budgets as requests happen, while recording usage and spend for auditability.
Agent Identity Management
Agents are becoming a new class of worker. They can hold credentials, access apps, call tools, and take action across the business. But without a clear identity and owner, an agent can quickly become a security and audit risk: no one knows exactly what it can access, what it has done, or how to revoke it.
With Rippling Agent Identity Management, companies can create and manage agent records alongside employees and service accounts. Admins can assign owners, set permissions, and provision agents into third-party apps using the same access controls they already use in Rippling.
That means every agent can be known, owned, permissioned, auditable, and revocable from one system. Agent Identity Management gives companies the foundation to put agents to work safely, without letting them become invisible, shared, or unmanaged accounts.

An agent can act through permissions delegated by an employee or through its own managed identity. In either case, admins can see who owns it, what it can access, how much it spends, and what it does.
Shadow AI Detection*
Shadow IT has always been a problem for IT teams. Employees find a tool that helps them move faster, start using it before it has been reviewed, and suddenly the company has software with no clear owner, policy, or audit trail. Shadow AI raises the stakes. An unapproved AI tool may not just store data; it may read files, connect to apps, process sensitive information, call tools, or keep running as an agent.
Rippling Shadow AI Detection helps companies find AI usage they did not provision. It gives admins visibility into unapproved AI apps, third-party OAuth connections, browser extensions, coding assistants, local agents, and MCP servers, then connects that activity back to the employee, device, app, and organisation context in Rippling.
From there, admins can decide what should happen next. They can approve a tool, restrict it, notify employees to move to an approved alternative, revoke risky access, or bring usage into a managed path through Rippling AI Gateway or MCP Gateway. The goal is not to slow AI adoption down. It is to make the approved path easier, safer, and more visible than the unmanaged one.
This completes the AI governance story. MCP Gateway governs how AI connects to business tools. AI Gateway governs model usage and spend. Agent Identity Management makes non-human actors known and accountable. Shadow AI Detection finds the activity happening outside those approved paths, so companies can scale AI without losing sight of what is actually being used.

Each ingestion flow lands in raw records before normalisation and review.
Get started today
AI adoption isn't slowing down. The companies that scale it well won't be the ones that move fastest or impose blanket restrictions. They'll be the ones that build governance into the same infrastructure that already runs their business. That's what Rippling AI Governance is: visibility and control over AI, built on the employee graph that already powers everything else.
MCP Gateway and Agent Identity Management are live today. See them in action.
*Join the waitlist for AI Gateway and Shadow AI Detection.
Disclaimer
Rippling and its affiliates do not provide tax, accounting or legal advice. This material has been prepared for informational purposes only, and is not intended to provide or be relied on for tax, accounting or legal advice. You should consult your own tax, accounting and legal advisors before engaging in any related activities or transactions.
Author

Sinead Reilly
Sr GTM Manager, EMEA
Explore more

From unchecked AI spend to complete control: How Rippling built AI Spend Console
AI Spend Console gives CFOs and CTOs a clear view of AI spend, connects it to business outcomes, and governs the use of approved LLMs.

Inside the Making of Rippling AI
As AI adoption accelerates across HR, organisations face growing pressure to balance efficiency with privacy, compliance and accountability. This behind-the-scenes look at Rippling AI explores how it was built to operate within strict governance frameworks, leverage real-time workforce data and deliver trusted insights for HR, payroll and compliance teams—without compromising security or human oversight.

The 4 UK HR trends that actually matter in 2026
Day-one rights, shadow AI, tech sprawl, and hybrid work are reshaping UK HR. Here’s what teams need to prepare for and how they can capitalise in 2026.

Two-Thirds of European HR Teams Are Using AI — Are They Doing It Responsibly?
67% of European HR departments now use AI daily — but adoption and governance aren't keeping pace. Only 36% of HR leaders say they could confidently defend their AI decisions to a regulator. This post breaks down where the confidence gap is coming from, what's slowing teams down, and what responsible AI use in HR actually looks like in practice.

How the German KI-MIG Law Redefines HR and Finance Data Integrity
Germany's KI-MIG Act is bringing the EU AI Act's high-risk AI rules into sharp enforcement focus — and most HR and finance teams aren't ready. From shadow AI and audit failures to what deterministic governance actually looks like in practice, here's what the new law means for your workforce data.

How our European team uses Rippling IT
Manual IT provisioning means crossed wires, missed access, and a first day that starts with troubleshooting instead of onboarding. This post breaks down how Rippling handles provisioning differently — from contract signature to day one setup, role-based access that updates automatically, and compliance logs that are always audit-ready.

Rippling AI: Built to Do the Work, Not Just Talk About It
Rippling AI delivers precise, auditable answers using live company data—and takes real action across HR, IT, and Finance. Built for accuracy, security, and compliance, it goes beyond chatbots to power workflows businesses can trust.

5 Trends That Stole the Show at CIPD's HR in Ireland Awards 2026
The CIPD’s HR in Ireland Awards come but once a year, offering a lens into best-in-class HR thinking and the latest trends taking root across industries.
See Rippling in action
Increase savings, automate busywork and make better decisions by managing HR, IT and Finance in one place.