Last week, OpenAI published an open letter calling for a global surge in cyber defense. Proofpoint is proud to stand alongside frontier labs, fellow security vendors, and global enterprises in signing it.
The premise—one I've been talking about for the past year—is simple: AI is compressing the timeline on both sides of the cyber fight. Attackers are using AI to industrialize social engineering, make sense of stolen data, exploit vulnerabilities faster, and automate increasingly sophisticated attacks. However, AI also gives defenders an extraordinary opportunity to change the economics of cyber defense, but only if we act now.
We have a window to put frontier AI to work for defenders before these capabilities become ubiquitous in the hands of attackers, but that window won't remain open indefinitely. At Proofpoint, we intend to take action.
How Proofpoint approaches agentic AI security
-
Partnering at the frontier. Proofpoint is a member of the OpenAI Daybreak Cyber Partner Program, giving us governed access to frontier AI capabilities that we can put to work across defensive security operations, products, and customer workflows.
-
Protecting the new AI attack surface. We're building security for a world in which people, copilots, models, and autonomous agents all interact with sensitive enterprise data.
-
Embedding security into AI workflows. We're making Proofpoint intelligence and controls available through MCP and other interfaces so customers can bring security directly into the agents and workflows they're building.
-
Putting frontier AI to work inside Proofpoint. We're using advanced models like Mythos internally to stress-test our defenses, identify vulnerabilities, improve detection, and strengthen our products and infrastructure.
-
Advancing collective defense. We're sharing what we learn and working across the ecosystem, because no company can address the scale and speed of AI-enabled cyber risk alone.
Part of that job is helping customers manage AI adoption happening inside their own walls, not just AI-enabled threats coming from outside. Every new AI assistant and every agent given a mailbox or permissions expands the enterprise AI attack surface. Attackers are already adapting, embedding malicious prompts in email and documents to manipulate the copilots employees now trust. At the same time, the timeline from CVE to exploit has shrunk dramatically.
That's why we built models to prevent prompt injection into our products and released Active Exploits Protection: to detect and stop AI-targeted exploits before they compromise the AI agents and agentic workflows our customers depend on.
It's also why our AI Security and Data Security products exist as a unified layer rather than a bolt-on. Protecting people has always meant protecting the data they touch and the systems they use. Now, that includes AI assistants and agents acting on their behalf and increasingly autonomously.
Discovery, real-time controls, and intent-based detection have to work together because a threat that reaches an AI agent can influence a human decision or trigger an autonomous action downstream.
Security has to go where defenders work
Being a good partner to defenders also means rethinking how we deliver security. Teams don't need another dashboard to check. They need protection embedded in the workflows and agents they're already building.
That's why we're investing in MCP access to Proofpoint's detection, prevention, and intelligence capabilities, allowing an organization's AI agents to securely query our threat intelligence and controls directly. It's also why we're building unified experiences like workbenches and moving toward headless capabilities that can be embedded wherever a customer's security architecture lives.
If AI is going to be woven into cyber defense, our products need to meet that reality.
We're putting frontier AI to work inside Proofpoint, too
The same frontier capabilities we're helping our customers manage are ones we're putting to work securing Proofpoint itself. We're putting the latest cyber-capable models from Anthropic and OpenAI to work hardening our products and infrastructure:
-
Stress-testing detection logic against the kinds of AI-generated cyberattacks we expect to see at scale
-
Using model-driven analysis to identify gaps in our environment and codebase faster
-
Holding ourselves to the same standards we're asking of others
Applying frontier capabilities to the hardest problems isn't just a principle we're endorsing. It's a foundational practice we're building into how we run our own house.
Collective defense requires collective action
None of this works if it stays inside any one company's four walls. No single vendor can out-build the scale of AI-enabled cyberthreats and new agentic risks to data. It will take frontier labs responsibly sharing model access and threat intelligence, cybersecurity companies sharing tools and playbooks, enterprises sharing what they're seeing, and governments helping under-resourced defenders—especially hospitals, utilities, schools, and local governments.
Proofpoint has spent this year building toward a world where protecting people means protecting their AI agents and data too, and where our capabilities are available wherever defenders need them. Signing this commitment is a continuation of that work.
The window is open. We intend to help you use it.
Related reading
FAQ
How is AI changing cyber defense?
AI is accelerating both attack and defense. Attackers can use AI-powered capabilities to scale social engineering, analyze stolen data, and move faster from vulnerability discovery to exploitation. At the same time, security teams can use advanced AI tools and foundation models to improve detection, identify vulnerabilities, and strengthen defensive operations. The opportunity now is to put frontier AI to work for defenders while that advantage remains meaningful.
Why do AI agents create a new security challenge for enterprises?
AI agents can interact with email, applications, and sensitive data, and increasingly take actions on a user’s behalf. As organizations move from experimenting with AI tools to deploying AI agents across the enterprise, the AI attack surface expands. Security therefore needs to protect not only people and data, but also the agents and workflows connecting them.
What role does prompt injection play in AI security?
Prompt injection can manipulate an AI assistant or agent through malicious instructions embedded in content such as email or documents. As organizations give AI systems greater access to sensitive data, applications and business processes, security teams need to account for the possibility that malicious prompts could influence an AI agent’s decisions or actions.
Why does AI cyber defense require collective action?
AI-enabled threats operate at a scale and speed no single organization can address alone. Effective cyber defense increasingly depends on frontier AI labs, cybersecurity companies, enterprises and governments sharing capabilities, threat intelligence and lessons learned. That collaboration can help security teams put advanced AI capabilities to work for defense and adapt as attackers adopt them too.