Proofpoint unveils 2 agentic security systems

Proofpoint has announced two agentic security systems that detect attacks based on intent, protect enterprise data and secure AI use.

The Agentic Data and AI Security system combines AI runtime protection and data governance in a single platform. Besides giving AI agents access only to the data required for their intended tasks, it also translates existing business policies into controls that can be enforced at runtime.

“You cannot secure AI without securing the data it acts on, and you cannot secure data without understanding how AI is using it,” said Mayank Choudhary (top), Executive Vice President and General Manager of Proofpoint’s Data Security and Governance Group.

“Intent and access are two sides of the same coin. Securing them separately leaves critical context behind. Bringing AI run-time protections and AI data governance together gives organisations that context, and the ability to act on risk at the speed AI now moves,” he added.

The system is built on Proofpoint’s Knowledge Graph, which connects AI activity with data sensitivity, identity, access, behaviour, and intent. Three autonomous agents detect suspicious activity, reconstruct incidents and recommend remediation, including access changes and data-loss prevention policy updates.

Proofpoint has also introduced Semantic Business Policies that let enterprises express governance requirements in plain language and convert them into continuously enforced AI controls. Its Agentic Insights capability uses autonomous reasoning agents to analyse AI interactions, tool use, policy decisions, and behavioural patterns to identify emerging risks.

“Organisations have spent decades defining how their businesses should operate,” said Ryan Kalember, Chief Strategy Officer of Proofpoint. “The challenge now is making those rules enforceable as AI takes on more consequential work. Business intent needs to become part of the security control itself, with the ability to identify new risks and adapt as AI behaviour evolves.”

The Agentic Data and AI Security system’s capabilities, including Semantic Business Policies and Agentic Insights, are expected to become available by end 2026.

Collaborative security

Also announced is Agentic Collaboration Security, which applies intent-based detection and agentic capabilities across email, collaboration tools and browsers. The system identifies attacks that resemble legitimate business activity, such as compromised supplier accounts, fraudulent payment requests and highly targeted attacks against executives.

“Attackers increasingly operate inside the relationships and workflows organisations already trust,” said Tom Corn, Executive Vice President and General Manager of Proofpoint’s Threat Protection Group. “That changes the detection problem. Security needs to understand what an interaction is trying to accomplish, reason over the context around it, and act before the attacker succeeds. Not with disparate tools, but as one system that gets smarter with every decision it makes.”

The system uses Proofpoint’s Knowledge Graph and Nexus Intent-Based Detection Model to analyse business relationships, communication patterns, data access, and user risk. Most decisions are resolved in under half a second while ambiguous interactions receive deeper analysis.

New capabilities include autonomous threat investigation, adaptive protection for high-risk users and dedicated detection models for executives and finance approvers.

Proofpoint also plans to add Advanced Browser Protection, developed with Push Security, to detect post-click phishing, malicious URLs, browser extensions, OAuth phishing, credential theft, and session hijacking.

The new Agentic Collaboration Security capabilities are expected to be available from Q1 of 2027 as an update to Proofpoint’s existing collaboration security solution.

Tagged with: