June 11, 2026 WitnessAI Release

WAI Docs Wed Aug 19 13:22:37 EDT 2026
List
Quick Start
Welcome
Supported Applications & LLMs
Release Notes
August 18, 2026 WitnessAI Release
August 4, 2026 WitnessAI Release
July 21, 2026 WitnessAI Release
July 14, 2026 WitnessAI Release
July 9, 2026 WitnessAI Release
June 30, 2026 WitnessAI Hotfix
June 23, 2026 WitnessAI Release
June 16, 2026 WitnessAI Release
June 11, 2026 WitnessAI Release
June 4, 2026 WitnessAI Hotfix
June 2, 2026 WitnessAI Update
May 19, 2026 WitnessAI Update
April 30, 2026 WitnessAI Update
April 28, 2026 WitnessAI Update
April 23, 2026 WitnessAI Update
April 16, 2026 WitnessAI Update
April 14, 2026 WitnessAI Update
April 9, 2026 WitnessAI Update
April 9, 2026 WitnessAI Update
April 7, 2026 WitnessAI Update
April 2, 2026 WitnessAI Update
March 31, 2026 WitnessAI Update
March 24, 2026 WitnessAI Update
March 19, 2026 WitnessAI Update
March 17, 2026 WitnessAI Update
March 12, 2026 WitnessAI Update
March 5, 2026 WitnessAI Update
February 26, 2026 WitnessAI Update
February 24, 2026 WitnessAI Update
February 10, 2026 WitnessAI Update
January 27, 2026 WitnessAI Update
January 20, 2026 WitnessAI Update
January 13, 2026 WitnessAI Update
December 18, 2025 WitnessAI Update
December 9, 2025 WitnessAI Update
November 25, 2025 WitnessAI Update
November 18, 2025 WitnessAI Update
November 11, 2025 WitnessAI Update
October 28, 2025 WitnessAI Update
October 23, 2025 WitnessAI Update
October 9, 2025 WitnessAI Update
October 2, 2025 WitnessAI Update
September 30, 2025: WitnessAI Update
September 23, 2025: WitnessAI Update
August 12, 2025: WitnessAI Update
July 31, 2025: WitnessAI Update
July 18, 2025: WitnessAI Update
April 11, 2025: WitnessAI Release v2.0
June 9, 2025: WitnessAI Update
June 23, 2025: WitnessAI Update
TOC Left Sidebar: not active
TOC Left Sidebar: ORIGINAL
User Guide
Policies - GuardRails
Witness Anywhere: Remote Device Security
Witness Attack
Administrator Guide
404

WitnessAI Release: June 11, 2026

💡
Note: New and updated features may not be immediately available on your dedicated deployment due to participation in limited availability releases, beta programs, or regional configurations.
If you don't see a feature you expect, please reach out to Customer Success. We're happy to help!
 

New Features

Agentic Tool Use Policy

Admins can now block or allow specific MCP servers and Tools for Agents. They can now use the new Agent Tool Use Policy to configure a Blocklist or Allowlist of MCP Servers or Tools. They can also block MCP servers and Tools from the new MCP Servers page in discovery, making it easy to take action on the new MCP servers discovered.

GitHub Copilot (VS Code)

Admins can now block or allow specific MCP tools and servers for GitHub Copilot agent sessions in VS Code, covering both the standard chat path and the Anthropic model path. Per-request latency metrics for tool block decisions are now visible in the monitoring dashboard, labelled by policy type, tool name, and tenant — making it straightforward to identify which tools are being evaluated and where delays occur.
New capabilities: Agentic Control

Claude Code

WitnessAI now fully supports the Claude Code Desktop, CLI and VS Code Extension. Prompts, responses, and agentic tool calls are captured and visible in the console. All AI policies — including content redaction, blocking, warnings and modified response content is correctly delivered to the user. The Witness Anywhere registration script for macOS and Windows automatically configures the Claude Code proxy settings — no manual setup required.
Supported capabilities: Prompt/Response Observability, Blocking, Warning, Redact, Route, Agentic Observability

OpenAI Codex (CLI, VS Code Extension, Desktop)

Full prompt and response capture, blocking, warning, and modification support is now in place across all three Codex surfaces. The Codex WebSocket conversation path now has history-rewrite protection, preventing prior-turn PII from being re-submitted to the model. The macOS Witness Anywhere registration script automatically configures the Codex environment file with the correct proxy settings.
New capabilities: Prompt/Response Observability, Blocking, Warning, Redact, Agentic Observability

Feature Updates

Claude Desktop & Claude Co-Work

Policy-modified response content is now correctly applied and delivered to users in Claude Desktop and Claude Co-Work. Previously, content redacted or rewritten by policy was silently discarded and the raw model output was forwarded instead.
New capabilities: Agentic Observability

Notion AI

Warning pop-ups now appear correctly when a policy is triggered in Notion AI, and full response content is now captured in the Conversations page. Previously, responses were only partially captured or not captured at all, and warnings were silently suppressed.
New capabilities: Warning (restored), Prompt/Response Observability

Google Docs & Google Sheets (Inline Mode)

Inline prompt submissions in Google Docs and Google Sheets are now captured and visible in the Conversations page. Previously, inline prompts were missing from the console while sidebar prompts appeared normally.
New capabilities: Prompt/Response Observability (inline mode)

Writer.com — Playbook Threads

WitnessAI governance now extends into Writer.com Playbook threads. Block, warn, and observe policies apply to prompts and responses within Playbook conversations — a workflow surface that was previously outside the inspection boundary.
New capabilities: Prompt/Response Observability, Blocking, Warning (Playbook workflow)

Custom Data Types — UI Improvements

The policy configuration experience for custom data types has been improved: the edit/delete popover now closes automatically after a deletion is confirmed, and example patterns in the custom data type creation flow no longer include anchoring characters that could cause unexpected matching behavior.

Per-Request Tracing for Proxy Traffic

End-to-end request tracing using a unique request identifier is now propagated across both HTTP/1.1 and HTTP/2 proxy paths. This allows operators to correlate a specific prompt’s full lifecycle — from the client through inspection — using a single identifier in observability tooling, significantly reducing time to diagnose issues.

Tool Block Metrics

Metrics are now emitted at each stage of the tool-blocking flow, both on the proxy side and in the console. This gives administrators visibility into where latency occurs when tool calls are evaluated and blocked, and enables per-request correlation between proxy-side logs and console-side records.

Claude Code CLI — Proxy Registration

The Witness Anywhere macOS and Windows registration scripts now automatically configure Claude Code CLI to use the proxy. The settings are written to the Claude configuration file as part of registration and can also be deployed via MDM (Jamf, Intune, or equivalent).
 

Performance, Reliability & API Updates

  • Binary file downloads (installers, update packages) are no longer buffered through the inspection pipeline, reducing memory usage when users download large binary files over a proxied connection.
  • Large streamed responses that appeared stalled now display correctly.
  • The device registration service now correctly logs vendor labels in the provisioning database, making troubleshooting registration errors faster.
  • A duplicate authentication header edge case that caused prompt extraction issues has been resolved.
  • The console data table library has been migrated to a lighter-weight implementation, reducing bundle size and improving page load performance across settings tables.
  • The app-catalog service no longer performs an immediate sync on startup, reducing unnecessary load during rolling restarts and deployments.
  • Hotfix deployment pipeline now supports hotfix branches, enabling faster out-of-band releases without requiring a full release cycle.
  • Stable conversation identifiers for Claude models in VS Code ensure that multi-session chat history groups correctly in the console even after reconnection.
 

Fixed Issues

  • Microsoft Copilot (iOS — Dictation) A compatibility issue with the Dictation feature in the Copilot Corporate iOS app has been resolved. Text entered via the dictation button now populates correctly and is captured by the proxy.
  • VS Code sometimes generated a duplicate response for the very first prompt in a session when a DLP warning guardrail was active.
  • Warning messages were occasionally not rendered in Visual Studio when policies were configured in Warn mode for GPT-5.3 Codex, GPT-5.4, and GPT-5.5 models via PAC Proxy.
  • The edit/delete popover for custom data types remained open after a deletion was confirmed, requiring an extra click to dismiss.
 

Known Issues

There are no known issues in this release.