SecurityBrief India - Technology news for CISOs & cybersecurity decision-makers
India
Proofpoint launches AI security system for data risk

Proofpoint launches AI security system for data risk

Wed, 23rd Sep 2026 (Today)
Mara Sugue
MARA SUGUE News Editor

Proofpoint has launched a unified data and AI security system designed to manage risk across both employees and AI agents.

The move reflects a broader shift in cyber security as companies give AI tools access to sensitive information, internal systems and business processes. Proofpoint argues that security teams can no longer rely on separate tools for data protection and AI oversight when autonomous software is taking actions once limited to human users.

The new product, the Proofpoint Agentic Data and AI Security system, is built to connect data sensitivity, identity, access, behaviour and intent in a single framework. The approach is intended to help organisations understand not only what data an AI tool can access, but why it is acting and whether that activity aligns with internal rules.

Built on Proofpoint's existing knowledge graph, the system is aimed at customers already using its data security and governance products. That same foundation secures the data of more than 14,000 enterprises, providing an established base for expanding into AI-related controls.

A central part of the launch is a set of three autonomous agents for detection, investigation and remediation. According to Proofpoint, the detection agent identifies significant actions by assessing intent and access together, while the investigation agent reconstructs incidents across data, identity and behaviour. The remediation agent recommends or applies changes such as access adjustments and updates to data loss prevention policies, with human oversight retained for governance.

The company is also introducing what it calls Semantic Business Policies, intended to convert existing business rules into controls that can be applied during AI activity. In one example, a rule banning interaction with gambling content could be expressed in plain language and turned into an enforceable runtime restriction.

This is paired with intent-based access control, which evaluates whether an AI action matches both company policy and the stated purpose of the employee or agent involved. It is intended to apply whether a worker uses an AI assistant directly or an autonomous agent acts independently on that worker's behalf.

Growing concern

The launch comes as businesses move AI systems beyond trial deployments and into operational use. Proofpoint cited its 2026 AI and Human Risk Landscape report, which found that 87% of organisations had moved AI assistants beyond pilot programmes, while 52% were not confident their controls could detect a compromise.

That gap points to a broader market concern. As AI systems gain the ability to discover information, make decisions and execute transactions, security risks extend beyond conventional data leakage to include operational, financial, compliance and safety issues.

Mayank Choudhary, Executive Vice President and General Manager, Data Security and Governance Group, Proofpoint, said the company sees those problems as inseparable. “You cannot secure AI without securing the data it acts on, and you cannot secure data without understanding how AI is using it,” Choudhary said. “Intent and access are two sides of the same coin. Securing them separately leaves critical context behind. Bringing AI run-time protections and AI data governance together gives organisations that context, and the ability to act on risk at the speed AI now moves.”

Proofpoint is also adding a feature called Agentic Insights, which uses autonomous reasoning to examine AI interactions, tool use, policy decisions and behavioural patterns. The aim is to identify risks a company has not yet defined through formal rules or policies.

When such a risk is validated, the system can recommend a new Semantic Business Policy to address similar behaviour in future. That creates a feedback loop in which the platform not only enforces existing rules but also proposes new ones as AI behaviour changes.

Market shift

The announcement highlights how security vendors are repositioning around AI governance rather than treating AI simply as another endpoint or cloud workload. The commercial opportunity lies in helping customers manage autonomous systems that can move rapidly across applications, datasets and workflows with limited direct supervision.

For businesses, the appeal of a unified model is that policy enforcement, monitoring and response can operate from a shared view rather than through disconnected tools. That may reduce the manual effort of correlating data access logs, user behaviour signals and AI actions after an incident has occurred.

Ryan Kalember, Chief Strategy Officer, Proofpoint, said the challenge is translating long-standing business rules into controls that work in AI-led environments. “Organisations have spent decades defining how their businesses should operate,” Kalember said. “The challenge now is making those rules enforceable as AI takes on more consequential work. Business intent needs to become part of the security control itself, with the ability to identify new risks and adapt as AI behaviour evolves.”