Proofpoint has announced the Proofpoint Agentic Data and AI Security system, a unified platform designed to help organisations manage AI and data security as a connected risk.
The company said the new system brings AI runtime security and data governance together, allowing organisations to control how AI agents access sensitive information while identifying emerging risks across employees and autonomous AI systems.
Proofpoint said traditional security tools often address either AI behaviour or data exposure, leaving gaps between the two. Its new system is designed to analyse AI activity alongside data sensitivity, identity, access, behaviour and user intent.
Three agents automate detection and response
The system is built on the Proofpoint Knowledge Graph, which connects AI activity with identity, access, data sensitivity, behaviour and intent through the company’s Nexus models.
Three autonomous agents operate using this shared context:
- Zero-Touch Detection: The Detection Agent analyses AI intent and data access together to identify potentially significant activity while reducing the volume of less relevant alerts.
- Instant Investigation: The Investigation Agent automatically reconstructs activity across data, identity and behaviour, helping security teams investigate incidents more quickly.
- Protection Optimization: The Remediation Agent can take actions such as access remediation and DLP policy optimisation, with human oversight retained for governance.
Proofpoint said the approach is designed to reduce manual correlation and allow security teams to respond as AI-driven activity increases.
Turning business policies into AI controls
The company has also introduced Semantic Business Policies, which are designed to translate existing organisational rules into controls that can be applied to AI activity.
For example, an organisation could express an existing policy in plain language by stating that AI systems should not interact with gambling-related content. Proofpoint said its technology can interpret the policy’s intended meaning, identify relevant systems and generate runtime controls to enforce it.
The policies work alongside Proofpoint Intent-Based Access Control to assess AI activity against both an organisation’s requirements and the intended purpose of an AI agent.
This applies whether an employee is using an AI assistant or an autonomous agent is performing actions on the employee’s behalf.
Identifying risks before policies exist
Proofpoint has also introduced Agentic Insights, which uses autonomous reasoning agents to analyse AI interactions, tool usage, policy decisions and behavioural patterns.
The system is designed to identify risks that may not have been anticipated when an organisation originally created its security policies.
When a potential risk is validated, Proofpoint said the platform can recommend a Semantic Business Policy to address similar activity in the future.
The company said this creates a feedback loop in which newly identified risks can be converted into enforceable controls.
AI governance extends beyond data protection
Proofpoint said the need for integrated AI security is increasing as AI agents move beyond information retrieval and begin interacting with enterprise systems, making decisions and executing transactions.
That creates potential financial, operational, compliance and safety risks in addition to conventional data-loss concerns.
According to Proofpoint’s 2026 AI and Human Risk Landscape report, 87 per cent of organisations have moved AI assistants beyond the pilot stage, while 52 per cent are not confident that their existing controls could detect a compromise.
Mayank Choudhary, executive vice president and general manager of Proofpoint’s Data Security and Governance Group, said AI security and data security need to be considered together because AI systems increasingly act directly on enterprise information.
Ryan Kalember, chief strategy officer at Proofpoint, said organisations now need to translate existing business rules into security controls that can operate as AI systems take on more consequential tasks.
Proofpoint said its new system is intended to combine AI runtime protection, data governance, automated investigation and remediation in a single security framework as organisations expand their use of AI agents.

Comments
0 commentsNo comments yet. Be the first to share your thoughts!