Proofpoint Unifies Data and AI Security with New Agentic System
Proofpoint has announced its Proofpoint Agentic Data and AI Security System, designed to address AI and data security as a connected risk rather than as separate security challenges. The system brings together AI activity, data sensitivity, identity, access, behaviour and intent through the Proofpoint Knowledge Graph. The company says this approach enables security teams to understand both what an AI system is doing and what data it is accessing.
According to Proofpoint, AI agents are increasingly able to discover, access, transform and act on sensitive enterprise data, creating risks that traditional security tools may not fully capture when AI behaviour and data access are monitored separately. The company’s 2026 AI and Human Risk Landscape report found that 87% of organisations have moved AI assistants beyond the pilot stage, while 52% are not confident that their existing controls could detect a compromise.

“Intent and access are two sides of the same coin,” said Mayank Choudhary, executive vice president and general manager, Data Security and Governance Group, Proofpoint. “Bringing AI runtime protections and AI data governance together gives organisations that context, and the ability to act on risk at the speed AI now moves.”
Three agents for detection, investigation and remediation
The new system uses three autonomous agents built around a shared view of risk. Zero-Touch Detection combines AI intent and data access signals to identify potentially significant activity while reducing the volume of anomalies requiring manual review.
Instant Investigation automatically correlates data, identity and behavioural information to reconstruct security events and accelerate investigations. Protection Optimization can recommend or implement actions such as access remediation and DLP policy optimisation, while retaining human oversight for governance.
Turning business intent into runtime controls
Proofpoint is also introducing Semantic Business Policies, which translate existing governance requirements into controls that can be applied to AI activity. For example, an organisation could express a rule such as “Do not allow interactions with gambling content” in plain language. Proofpoint says its technology can interpret the policy’s intent, identify relevant systems and generate runtime controls to enforce it.
Combined with Proofpoint’s Intent-Based Access Control, the policies are designed to evaluate AI behaviour against both enterprise requirements and the intended purpose of an AI agent or assistant.
Identifying emerging risks
The company’s Agentic Insights uses autonomous reasoning agents to analyse AI interactions, tool usage, policy decisions and behavioural patterns to identify risks that organisations may not yet have explicitly defined. When a risk is validated, Proofpoint can recommend a Semantic Business Policy to address similar behaviour in the future.
“Business intent needs to become part of the security control itself, with the ability to identify new risks and adapt as AI behaviour evolves,” said Ryan Kalember, chief strategy officer, Proofpoint. Proofpoint said the capabilities within the Agentic Data and AI Security System, along with Semantic Business Policies and Agentic Insights, are expected to become available by the end of 2026.



