Decoding the world of cybersecurity

Proofpoint joins AI and data controls

Proofpoint has announced a system intended to connect AI behaviour, data access, identity, and business intent, with key capabilities expected to become available by the end of 2026.

Proofpoint joins AI and data controls
Summary
  • Proofpoint’s Agentic Data and AI Security system is designed to analyse AI activity and data access through a shared identity and risk graph.
  • Announced functions include semantic business policies, autonomous investigation, and controls around agent access and behaviour.
  • Several key capabilities are expected by year-end rather than being generally available today.

Proofpoint has announced an agentic security system intended to combine data protection, AI behaviour, identity, and business-policy enforcement, as vendors increasingly attempt to close gaps between established data controls and autonomous software.

The Agentic Data and AI Security system was unveiled at Proofpoint Protect 2026 and is built around the company’s existing knowledge graph, which links identity, access, data sensitivity, behaviour, and other security context.

Proofpoint says the planned system will use autonomous functions to support detection, investigation, and policy optimisation. It has also announced Semantic Business Policies, intended to translate business requirements into runtime controls around AI activity.

The central premise is that conventional data-security tools can see where sensitive information exists without understanding why an AI agent is accessing it, while AI-security tools may observe an agent’s activity without enough context about the underlying data.

Bringing those views together could help determine whether an action is technically permitted but inconsistent with the business purpose of the agent. Proofpoint says its approach is designed to evaluate behaviour against both access rights and intended purpose.

Those capabilities should not be treated as fully deployed today. Proofpoint says functions within the system, including Semantic Business Policies and Agentic Insights, are expected to become available by the end of 2026.

The distinction is important because enterprise AI security is attracting a large number of announcements while technical architecture, interoperability, and operational practice remain unsettled.

Autonomous agents create a genuine extension of the data-governance problem. An employee may use an AI assistant to summarise a document, while a more autonomous agent might search repositories, call internal applications, transform information, and initiate transactions across several systems.

The latter can have valid credentials and still behave in a way that exceeds the intended task. That makes access decisions more contextual than a conventional allow-or-deny entitlement attached to a user account.

Proofpoint says the system is intended to use connected identity, access, and data context to investigate that activity and recommend or apply controls. Its announced Agentic Insights capability is intended to identify risk patterns not already expressed through a policy.

The company cites its own 2026 AI and Human Risk Landscape research, which found 87% of surveyed organisations had moved AI assistants beyond pilot while 52% lacked confidence that their controls would detect a compromise. Those figures are vendor research and should be read as such rather than a universal measure of adoption.

The architecture is also part of a wider convergence. Identity vendors are building runtime controls for agents, data-security companies are extending governance to AI access, and collaboration-security providers are applying behavioural and intent analysis to interactions that previously involved only people.

Proofpoint is attempting to span several of those functions within one system. That may reduce fragmented context, but customers will need to test how well the platform integrates with the model providers, SaaS services, identity systems, and data stores they already use.

The announcement is therefore best understood as another move towards policy enforcement at the point where AI interacts with sensitive business systems. The proposed functionality is material, but the practical judgement should follow deployment and availability rather than the announcement alone.

×