
Proofpoint has launched an agentic security system that connects AI behavior, data access, and business policies to detect and respond to emerging risks. This new solution is designed to protect AI activity and enterprise data as a single, connected risk.
The Proofpoint Agentic Data and AI Security system, announced at Proofpoint Protect 2026, combines AI runtime security with data security. Organizations can now monitor what AI agents are trying to do, what data they access, and whether those actions fit company policies.
Also Read: Schneider Electric and NVIDIA Advance AI Data Center Infrastructure
The system gives AI agents access only to the data required for a specific task. It translates existing business policies into runtime controls and continuously identifies new risks across employees and autonomous AI agents.
Securing AI with an Agentic Security System
As companies give AI agents access to more enterprise systems and sensitive information, traditional security tools often see only part of the activity. AI security tools may track an agent's behavior without understanding data sensitivity.
Data security tools, meanwhile, can identify sensitive information without understanding the context of an AI agent's access. Proofpoint argues that connecting these signals provides a fuller picture of risk as AI moves from assisting employees to taking autonomous actions.
This shift expands the potential consequences of an AI compromise. AI agents can now interact with enterprise systems and execute transactions, creating financial, operational, and compliance risks.
Proofpoint's 2026 AI and Human Risk Landscape report found that 87% of organizations have deployed AI assistants beyond the pilot stage. However, 52% of organizations are not fully confident their current security controls would detect a compromised AI system.
Intelligence via the Proofpoint Knowledge Graph
At the center of the new system is the Proofpoint Knowledge Graph, which connects AI activity with data sensitivity, identity, access, and intent. Three autonomous agents operate from this shared context:
Go deeper on GCC & Africa tech — $9.99/month.
Deep dives and investor insights the free digest doesn't cover.
Detection Agent: Combines intent and access signals to identify actions representing meaningful risk.
Investigation Agent: Reconstructs activity across data and identity, helping security teams understand incidents without manual correlation.
Remediation Agent: Turns findings into action, including access remediation and DLP policy optimization, while maintaining human governance.
Enforcing Semantic Business Policies
Proofpoint is also introducing Semantic Business Policies to convert existing business rules into runtime controls. For example, a company could state that AI systems should not interact with gambling content.
The system interprets that requirement, identifies relevant systems, and automatically generates controls to enforce the policy. These policies can be combined with Intent-Based Access Control to evaluate an action against organizational rules.
Identifying Emerging Risks with Agentic Insights
Organizations must also deal with behaviors they did not anticipate when creating security policies. Proofpoint's Agentic Insights is designed to address that gap by using autonomous reasoning agents to analyze AI interactions and behavioral patterns.
When a risk is validated, the system recommends a new Semantic Business Policy to govern similar behavior in the future. This creates a cycle where newly discovered risks become enforceable controls.
This approach reflects a broader shift in AI security. Companies are now managing whether an AI system behaves in ways that conflict with business rules or creates operational vulnerabilities.
Capabilities within the Agentic Data and AI Security system, along with Semantic Business Policies and Agentic Insights, are expected to become available by the end of 2026.
Engagement



