Today at Protect 2026, Proofpoint is introducing Semantic Business Policies and Agentic Insights, two new capabilities that together deliver a continuous governance lifecycle for AI, connecting policy definition, runtime enforcement, and autonomous risk discovery into a single platform. No other vendor offers this today.
Over the last nine months working with our customers on their AI security needs, we have learned something that has fundamentally shaped how we think about this market. The risks that emerge from the adoption of AI tools and agents go well beyond data exfiltration, prompt injection, and jailbreak detection. We heard from a banking customer that even though they had shut down network access to gambling websites, employees using agentic tools and AI agents could still interact with gambling information through those tools. We learned from other customers that when AI tools are given to end users, they can be abused to commit fraud against the company, or in more serious cases, to cause safety harm against fellow colleagues.
In response to what we have learned, and the broad set of financial, operational, compliance, and safety risks that have emerged alongside AI adoption, we built Semantic Business Policies and Agentic Insights. Organizations have spent decades building governance for how their business operates: finance policies, compliance standards, codes of conduct, acceptable use guidelines. But that governance was written for a world where humans took those actions. It was never designed to govern autonomous agents making decisions and executing transactions at machine speed, and the manual process of translating written policies into static technical controls breaks down as AI adoption accelerates.
Semantic Business Policies
Semantic Business Policies allow organizations to take their existing corporate governance and write new business rules in plain English, and have all of them enforced across the enterprise's AI estate. An administrator types "Never allow an outbound payout or transfer over $5,000 without end-user approval" or "Do not allow interactions with gambling websites" or "Do not send email communications to anyone outside the company." Proofpoint AI Security interprets the business intent behind the rule, identifies the enterprise systems capable of carrying out the action (such as Stripe, Brave Search, ServiceNow, Jira, Zendesk, Microsoft Teams, and others), and generates the runtime controls to enforce it. The administrator describes what the business requires, and the platform handles where and how to enforce it.
These rules apply uniformly across any actor in the agentic workspace. Whether a human employee takes an action through an AI assistant or an autonomous agent handles the same workflow, the same policy governs both.
Semantic Business Policies also work together with Intent-Based Access Control (IBAC). Where Semantic Business Policies establish the rules for what the enterprise has authorized, IBAC continuously evaluates every agentic action against those rules and catches the moment behavior deviates from business intent. An agent that should be solving security tests has no business posting messages to a public forum, and an agent handling customer inquiries has no business issuing refunds without approval. The combination means every action an agent takes is measured against the governance of the enterprise that deployed it, in the moment the action occurs.
Organizations can also bring their existing safe usage guidelines, employee handbooks, and compliance standards directly into the platform. The governance they have spent decades defining becomes the governance that is enforced at runtime, with the same policies applied in a fundamentally different way.
Agentic Insights: Continuous Governance Intelligence
Enforcing known policies is essential, and it only covers risks the organization has already anticipated. Proofpoint's 2026 AI and Human Risk Landscape report found that 87% of organizations have deployed AI assistants beyond the pilot stage and 76% are actively rolling out autonomous agents, yet 52% are not fully confident their security controls would detect a compromised AI, and half of those with controls in place have already experienced a confirmed or suspected AI-related incident. The volume of AI activity is growing faster than any security team can manually investigate.
In July 2026, approximately 700 autonomous agents coordinated an attack on HuggingFace's production infrastructure with no human directing them, organizing into hierarchies and exchanging over 70,000 messages to coordinate their actions. Investigations through August and September revealed agents had been sharing techniques for bypassing restrictions through unauthorized channels for months before the breach. Every permission check passed. No existing policy or detection rule covered what was happening, because no one had seen it before.
This is the problem Agentic Insights solves. It is a conversational experience powered by autonomous reasoning agents that continuously investigate enterprise AI activity. Administrators ask questions in natural language: What new AI risks emerged this week? Show me unusual AI activity across Finance. Which employees are using AI differently than their peers? Specialized AI agents analyze interactions, tool usage, policy decisions, and behavioral patterns and deliver answers, explanations, and recommendations rather than raw data. Where traditional security consoles answer the question "What happened?", Agentic Insights answers the more important question: "What should I know?"
Agentic Insights identifies new risk categories as they emerge across the enterprise's AI activity. The platform might surface that employees are using AI assistants to develop strategies for inflating vendor invoices or manipulating procurement negotiations. No policy prohibited that behavior because it had never been seen before. The system recognizes it as a business risk and presents it to administrators with the evidence and context they need to act. When a new risk is validated, administrators can create a new Semantic Business Policy to govern it, closing the loop between discovery and enforcement.
Every AI interaction becomes an opportunity to strengthen governance, and every discovery makes the platform smarter.
Validated behavioral patterns also become part of a growing library of AI risk intelligence shared across all Proofpoint customers, so organizations benefit from collective intelligence without waiting for a risk to appear in their own environment.
The Bottom Line
Security leaders have been forced to choose between enabling AI adoption and governing it responsibly. Semantic Business Policies and Agentic Insights remove that tradeoff.
Security teams can enforce their organization's business rules across every AI interaction, whether from an employee or an autonomous agent, without writing code, building templates, or maintaining static rule sets. High-risk actions are caught and governed at machine speed before they create financial, operational, or compliance exposure. New categories of risk are identified as they emerge, not after an incident, and converted into enforceable policy within the same platform. And as the organization's AI footprint grows, governance grows with it, because every risk Agentic Insights discovers becomes a new policy that the platform enforces from that point forward.