Proofpoint Data Security Posture Management.

Beyond the Alert: Bringing Context to Insider Risk and AI Investigations

Share with your network!

Proofpoint is announcing two expansions to its communications intelligence capabilities today. Proofpoint Prism Investigator now connects directly to Microsoft 365, and Proofpoint Human Communications Intelligence (HCI) now brings AI communications governance signals into insider risk investigations. Together, they give security, compliance, and legal teams a fuller picture of human and AI activity within the same investigation, from the first flagged alert to a finished set of findings.

Insider risk isn't just a human problem anymore

As employees increasingly use AI to communicate, create content, make decisions and conduct business, organizations need to capture AI interactions, preserve them as business records, and monitor them for regulatory and compliance risk, with the same defensibility as other regulated communications. According to Gartner® “by 2026, more than 80% of enterprises will have used generative artificial intelligence (GenAI) application programming interfaces (APIs) or models, and/or deployed GenAI-enabled applications in production environments, up from less than 5% in 2023.”*  Generative AI, copilots, and AI agents are now part of how people get their work done, and that shift expands where AI risk actually lives: in the prompts someone types, the files attached to those prompts, the responses they get back, and the actions an agent takes on their behalf. All of that is becoming part of the communications trail investigators have to consider. An employee's intent, and the circumstances behind a risky action, increasingly live in conversations with AI, not just conversations with people.

Take a common example: an employee pastes part of a customer contract into a generative AI tool. On its own, that alert doesn't say much. It doesn't tell you if it was a shortcut on a routine task, a policy violation nobody thought twice about, or the first sign of something worse. That answer lives in the story around the alert, not in the alert itself.

The problem is that most teams are still working from isolated signals like this one. An alert tells you an event occurred. It doesn't tell you whether that event fits a pattern, follows a conversation that explains it, or stands alone as something to worry about. Harry Labana, SVP and General Manager of Digital Communications Governance at Proofpoint, has described the gap in terms of flight recorders: a flight data recorder tells you what happened. A cockpit voice recorder makes the why legible, because intent lives in what people say, not just what they do. Communication is what makes intent legible; that's the thinking behind both of today's announcements.The bigger message is that alerts alone don't explain intent. Proofpoint is bringing human communications, AI activity, and data signals together into one defensible narrative, so teams can move from what happened to why it happened.

Prism Investigator, now inside Microsoft 365

For many teams, getting to the right Microsoft 365 content has meant exporting it, staging it, and waiting for that export to land before the investigation can actually start. In the first part of today's announcement, Prism Investigator makes that simple: getting what you need, when you need it. It now connects directly to Microsoft 365, reaching email, Teams messages, and files   as an investigation unfolds, without requiring that content to already sit in an archive.

Prism Investigator determines what a given investigation actually needs and pulls in the relevant Microsoft 365 content on demand, then correlates it with archived communications, data, logs, and other business records already available to the team running the investigation. The output is a complete narrative, not a pile of exhibits, built faster, without losing the auditability that regulatory and legal matters require. For teams juggling a growing docket of investigations, that's the difference between spending the first few days tracking down records and spending them actually investigating.

Bringing AI activity into the insider risk picture

The second part of today's announcement extends Human Communications Intelligence into Proofpoint Insider Threat Management, adding AI communications governance signals: interactions with copilots, generative AI tools, and AI agents, into the context a security or compliance team already uses to assess insider risk.

Capturing what someone typed into an AI tool can flag potential exposure of sensitive or confidential data on its own. But exposure alone doesn't tell you what to do next. That distinction, between an isolated flag and a documented pattern, is exactly what separates communications intelligence from a standard DLP alert. Layering in a person's broader communications and behavior is what turns a flagged prompt into an answer: is this routine, a policy violation worth a conversation, or a pattern that points toward something intentional? HCI combines communications context with behavioral and data activity so teams can make that call with confidence instead of guessing at intent from a single data point.

One intelligence layer, not another tool to manage

Neither of these capabilities lives in a silo. Both are part of the same Proofpoint platform, built to help organizations understand human and AI activity together across data security, insider risk, and AI security. The goal isn't to hand teams another dashboard. It's to make the context that already exists in Microsoft 365, in AI interactions, and in the archive available the moment an investigation needs it, so a team can move from a flagged alert to a defensible answer without switching tools or waiting on another export.

Built in, not bolted on

The industry's answer to AI risk has largely been to pipe more telemetry into the SOC and let a security team correlate it with everything else flowing through their SIEM. That may be a reasonable instinct for some, but it stops at correlation. While it could potentially tell a team that an AI interaction happened near a set of other signals, it can't reconstruct the narrative behind it, tie that interaction to a person's broader communications and behavior, or hand a team findings that are ready to act on.

That's the gap Prism Investigator and HCI are built to close. Neither hands AI and communications context off to a separate system for someone else to interpret. The correlation happens inside the same Proofpoint platform that already covers data security, insider risk, and AI security, so a team isn't stitching together telemetry from multiple tools to guess at intent. They're starting from a narrative Proofpoint already built, with the archive, the AI interactions, and the Microsoft 365 content in one place from the outset.

That gap is already showing up at scale. Citing a 2025 industry report, Proofpoint has noted that 68% of employees have used personal accounts to access free AI tools like ChatGPT, and 57% of them have entered sensitive data while doing it.** As AI takes on a bigger role in how work gets done, the organizations that can explain their AI-assisted decisions, not just record that they happened, will be the ones who can move fast on investigations without second-guessing what they missed.

Read the full announcement and reach out to your Proofpoint representative for availability details for Prism Investigator's Microsoft 365 connection and the new AI-aware HCI capabilities.

* Gartner: Gartner Says More Than 80% of Enterprises Will Have Used Generative AI APIs or Deployed Generative AI-Enabled Applications by 2026 — Gartner press release, October 11, 2023. GARTNER is a trademark of Gartner, Inc. and/or its affiliates.

** Proofpoint (citing Menlo Security's 2025 report): What Is Shadow AI? — Proofpoint threat reference page, which cites Menlo Security's 2025 Report for the 68%/57% figures.