AI assistants and agents are changing how work gets done. To secure them, organizations need AI security and data security to operate as one system.
AI is now an active participant in how work gets done. Employees use it to create, analyze, and decide, while AI assistants retrieve information across enterprise systems and AI agents increasingly act on users' behalf.
Every AI interaction is ultimately a data interaction, yet most organizations still secure AI and data risk separately. That separation creates a blind spot. AI security tools may see what an agent is doing and why, but not the sensitive data behind the action. Data security tools may see where sensitive data lives and who or what can access it, but not what an AI agent is trying to accomplish.
Consider a supply-chain agent with a legitimate objective that receives a prompt injection buried inside its own data source, quietly instructing it to pull records for every supplier and skip audit controls. Access alone won’t catch that, because the agent still has valid credentials. Intent without access is meaningless. Access without intent is blind. You need one intelligent system.
One Agentic System for AI and Data Risk
That's why Proofpoint is introducing the industry's first Agentic Data & AI Security System, providing intent-aware data security and access-aware AI security, built on a simple premise: AI security and data security must operate as one system. The Proofpoint Knowledge Graph is the foundation, connecting intent, access, identity, behavior, and data context into one place, and three new agents work from that shared understanding of risk, not partial views of it.
AI interactions across identities, data, and applications now multiply at machine speed. Manual investigation and static rules can't keep pace, and neither can human analysts working alone. The system is built to close that gap:
- Zero-Touch Detection: The Data and AI Detection Agent connects intent, access, and behavior into a single signal, grouping related DLP findings and chaining user behaviors to prioritize the risks that matter most, so analysts can act instead of tune rules.
- Instant Investigation: The Data and AI Investigation Agent automatically triages DLP alerts, risk chains, and data loss actions, reconstructing what happened across data, identity, and behavior in minutes. It's the moment AI security has an equivalent of the Tesla moment for automotive: investigation stops being a manual craft and starts being instant.
- Protection Optimization: The Data and AI Remediation Agent turns investigation findings into action, from access remediation and overexposed or overshared data to DLP policy optimization, with human governance of consequential decisions, so fixes happen at the pace risk emerges instead of waiting on a ticket queue.
People stay in control, approving consequential actions as routine detection, investigation, and remediation become autonomous. Teams can focus on judgment, governance, and business risk instead of chasing alert volume.
Deep Controls for AI and Data
Point tools separate AI behavior from data risk. Proofpoint brings AI runtime security, DSPM, data access governance, DLP, and insider threat management into one control plane, so teams can govern what AI can do, what data it can reach, and whether each action should be allowed.
Each of these controls is also getting deeper on its own:
- AI Runtime Security discovers sanctioned apps, shadow AI, agents, and MCP servers, then protects activity at runtime using identity, intent, and access. Teams can express business rules in plain language and enforce them automatically, applying the same scrutiny to agents acting on someone’s behalf as to the person themselves.
- Data Security Posture and Access Governance adds autonomous access remediation that corrects excess access without a ticket, adaptive AI data classification trained on business context, and governance that brings humans, agents, and non-human identities into one access model. Access governance finally matches how work gets done.
- Multi-channel Data Loss Prevention adds zero-touch AI-generated DLP policies teams approve instead of writing from scratch, agentic investigation that gathers context and resolves alerts automatically, and real-time DLP for Claude in AI prompts. DLP becomes a system that runs, learns and improves.
- Insider Threat Management adds predictive insider risk through risk chains that connect early warning signals automatically, agentic investigation, and agent-driven case management that assembles evidence, workflow, and disposition into a single record. Insider risk shifts from after-the-fact investigation to earlier intervention.
Semantic Business Policies and Agentic Insights helps teams govern AI without writing complex policies or predicting every risk in advance.
Proofpoint Semantic Business Policies translate natural-language requirements into enforceable AI controls, evaluating actions by intent, not just permissions. Agentic Insights uses autonomous reasoning to surface risks nobody defined yet, and turn validated findings into new policies automatically, so governance improves as AI use evolves.
Together, these controls run on one sensor, one workbench, and one MCP layer: a single endpoint agent instead of four separate deployments; one console where every finding across all four risk domains gets investigated; and one integration layer every AI agent connects through.
Unifying Risk Analysis on a Single Knowledge Graph
Every control, from detection and investigation to AI runtime security, DSPM, DLP, insider threat, and policy enforcement, reasons from the same foundation: the Proofpoint Knowledge Graph. It connects data sensitivity, identity, access permissions, AI activity, user and agent behavior, policy decisions, and intent signals into one unified understanding of risk.
Because those controls operate from the same graph, teams can determine whether access is appropriate, behavior is unusual, sensitive data is exposed, or an AI action should be allowed—then prioritize risks, investigate and reconstruct incidents faster, and act before exposure spreads.
One Agentic System to Accelerate AI Adoption
AI should accelerate the business, not force a choice between innovation and control. Organizations need the confidence to put AI in employees' hands, deploy agents into critical workflows, and connect AI to enterprise data without expanding risk. That requires one system that unifies deep AI security, deep data security, shared intelligence, and agentic operations.
With the Proofpoint Agentic Data & AI Security System, customers can adopt AI faster, maintain control of sensitive data, reduce operational burden, and stay ahead of emerging threats.
Availability
Proofpoint's existing AI runtime security, DSPM/DAG, multi-channel DLP, and Insider Threat Management solutions are available today. Agentic DLP Triage is available today in the US and Europe. New AI Runtime Security, DSPM/DAG, DLP, and Insider Threat Management capabilities are expected sooner, while the Data and AI Detection, Investigation, and Remediation Agents, along with Semantic Business Policies and Agentic Insights for AI Security policies, are expected to be available in Q1 2027.