Proofpoint combines AI and data security in new agentic system

Proofpoint has announced a new security system designed to give organisations a single view of AI activity and data access.

According to the cybersecurity firm, the Proofpoint Agentic Data and AI Security system has been designed so that enterprises can give AI agents access to only data they need based on intent.

“You cannot secure AI without securing the data it acts on, and you cannot secure data without understanding how AI is using it,” Proofpoint data security and governance group executive VP and general manager Mayank Choudhary said.

“Intent and access are two sides of the same coin. Securing them separately leaves critical context behind. Bringing AI run-time protections and AI data governance together gives organisations that context, and the ability to act on risk at the speed AI now moves.”

Autonomous Agents

The system is built on Proofpoint’s Knowledge Graph, which connects AI activity with information about data sensitivity, identity, access, behaviour and intent. Proofpoint added it also features three new autonomous agents: a detection agent, investigation agent and remediation agent.

The detection agent is designed to identify potentially risky combinations of AI intent and data access, while the investigation agent can automatically reconstruct activity across data, identity and behaviour to speed up investigations. The remediation agent can then take actions including access remediation and data loss prevention policy, with human oversight remaining part of the process.

Semantic Business Policies and Agentic Insights

Proofpoint said it is also introducing Semantic Business Policies to help turn existing business rules into controls that can be applied to AI controls. 

The company is also adding Agentic Insights, which uses autonomous reasoning agents to analyse AI interactions, tool usage, policy decisions and behavioural patterns to identify risks that may not have been explicitly defined in existing policies. When a risk is identified and validated, the system can recommend a Semantic Business Policy to govern similar activity.

“Business intent needs to become part of the security control itself, with the ability to identify new risks and adapt as AI behaviour evolves,” Proofpoint chief strategy officer Ryan Kalember said.

The company said the new capabilities are expected to be available by the end of 2026.

More from our security section

About The Author

Aimee Chanthadavong
Aimee Chanthadavong

Aimee Chanthadavong has been a journalist, editor and content producer for more than a decade. During that time she's covered enterprise technology for premium websites such as ZDNet and InnovationAus as well as food and travel for Broadsheet and SBS.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.