Proofpoint has announced the Proofpoint Agentic Data and AI Security system, a unified platform designed to help organisations manage AI and data security as a connected risk.

The company said the new system brings AI runtime security and data governance together, allowing organisations to control how AI agents access sensitive information while identifying emerging risks across employees and autonomous AI systems.

Proofpoint said traditional security tools often address either AI behaviour or data exposure, leaving gaps between the two. Its new system is designed to analyse AI activity alongside data sensitivity, identity, access, behaviour and user intent.

Three agents automate detection and response

The system is built on the Proofpoint Knowledge Graph, which connects AI activity with identity, access, data sensitivity, behaviour and intent through the company’s Nexus models.

Three autonomous agents operate using this shared context:

Proofpoint said the approach is designed to reduce manual correlation and allow security teams to respond as AI-driven activity increases.

Turning business policies into AI controls

The company has also introduced Semantic Business Policies, which are designed to translate existing organisational rules into controls that can be applied to AI activity.

For example, an organisation could express an existing policy in plain language by stating that AI systems should not interact with gambling-related content. Proofpoint said its technology can interpret the policy’s intended meaning, identify relevant systems and generate runtime controls to enforce it.

The policies work alongside Proofpoint Intent-Based Access Control to assess AI activity against both an organisation’s requirements and the intended purpose of an AI agent.

This applies whether an employee is using an AI assistant or an autonomous agent is performing actions on the employee’s behalf.

Identifying risks before policies exist

Proofpoint has also introduced Agentic Insights, which uses autonomous reasoning agents to analyse AI interactions, tool usage, policy decisions and behavioural patterns.

The system is designed to identify risks that may not have been anticipated when an organisation originally created its security policies.

When a potential risk is validated, Proofpoint said the platform can recommend a Semantic Business Policy to address similar activity in the future.

The company said this creates a feedback loop in which newly identified risks can be converted into enforceable controls.

AI governance extends beyond data protection

Proofpoint said the need for integrated AI security is increasing as AI agents move beyond information retrieval and begin interacting with enterprise systems, making decisions and executing transactions.

That creates potential financial, operational, compliance and safety risks in addition to conventional data-loss concerns.

According to Proofpoint’s 2026 AI and Human Risk Landscape report, 87 per cent of organisations have moved AI assistants beyond the pilot stage, while 52 per cent are not confident that their existing controls could detect a compromise.

Mayank Choudhary, executive vice president and general manager of Proofpoint’s Data Security and Governance Group, said AI security and data security need to be considered together because AI systems increasingly act directly on enterprise information.

Ryan Kalember, chief strategy officer at Proofpoint, said organisations now need to translate existing business rules into security controls that can operate as AI systems take on more consequential tasks.

Proofpoint said its new system is intended to combine AI runtime protection, data governance, automated investigation and remediation in a single security framework as organisations expand their use of AI agents.

Proofpoint AI security data security agentic AI cybersecurity AI governance data protection AI agents enterprise security Dubai cybersecurity