Forcepoint is betting that securing enterprise AI will increasingly mean securing the data that AI applications and autonomous agents can access—and new CMO Vincent Merlin sees channel partners playing a central role in that transition.
Merlin recently joined Forcepoint after a decade in senior marketing roles at Proofpoint and will oversee the data security vendor’s global brand, demand generation, product marketing and analyst relations. But his arrival comes as Forcepoint is also working to establish what it calls “AI data security” as a distinct enterprise security category.
In a Q&A with Channel Insider, Merlin discussed how agentic AI changes traditional approaches to data protection, the risks created when AI agents inherit user permissions, and the opportunity for MSPs and other partners to turn AI security into assessment, architecture and managed services engagements.
Why AI requires a new approach to data security
You’ve spent much of your career helping organizations navigate major technology shifts, from cloud to AI. What convinced you that Forcepoint and AI data security represent the right opportunity for your next chapter?
Every technology shift arrived before anyone knew how to secure it. Companies adopted anyway, because the business upside was too obvious to wait for. And the ones that moved early were able to move early because somebody made it survivable. AI is that story again, but with one difference that matters enormously. Cloud was about where your data lived. AI is about what your data does.
The value you get from AI is directly connected to the quality, context, and sensitivity of the data you put into it. That means the organizations that stand to get the most value from AI are often the ones with the most to lose. Security isn’t a problem sitting next to the AI business case. Increasingly, it is what makes the business case possible.
That reframing is what brought me to Forcepoint. AI data security is a uniquely pivotal moment for the industry, and there are only so many moments in a career when a market is being defined in real time. This is one of them.
What makes Forcepoint particularly compelling is that the company isn’t trying to bolt security onto AI after the fact. It has deep expertise in discovering and classifying sensitive data, that’s the intelligence layer of data security and the controls to adapt protection in real time as risk changes, wherever the data lives: on the device, in the cloud, and now inside AI. The market arrived where Forcepoint already was. That is not a pivot story. It’s the same discipline applied to a new surface. That’s exactly the kind of market-defining opportunity I wanted for my next chapter.
You’ve mentioned that “every technology worth adopting showed up before anyone knew how to secure it.” What makes the current AI moment different from previous technology transitions, and what can enterprises learn from how they approached the web, email, and cloud?
The web, mobile, and cloud changed where data lived across enterprises. Security caught up by moving the controls to those new locations.
AI changes something more fundamental: how data behaves. AI can generate data, transform it, summarize it, combine information that was previously separated, and create content that may be more sensitive than any individual pieces of source data. So the security challenge isn’t simply protecting data as it moves. It’s understanding what is happening to the data and whether that use is appropriate in the moment.
And there’s another major shift: the actor has changed.
A person can be compromised. A person can become an insider. An AI agent can potentially be both, but it operates at machine speed, across systems, and without human judgment. You can’t coach an agent in the moment the way you can coach an employee. You have to design the guardrails into the environment.
Banning the technology never worked. The organizations that came out ahead were the ones that adopted early, understood the risk, and built the guardrails alongside the technology. They didn’t wait for security to give them permission to innovate.
The lesson for enterprises today is the same: don’t choose between AI adoption and security. Build security into AI adoption from the beginning.
Forcepoint’s strategy for securing agentic AI
Forcepoint is positioning itself around the emerging “AI data security” category. What does that category encompass, and why do you believe enterprises need a distinct approach to securing data in the age of agentic AI?
You have to build AI security from the data up. Know the data first, then know the AI interacting with it. A prompt is only sensitive if you know what confidential data is in it. An agent’s request is only risky if you know what it is asking for. Enforcement starts with understanding both data and AI risk. That’s why you have to connect to the AI ecosystem. You have to watch what does into AI and what comes back. And then act on what you find.
That whole loop is what AI data security encompasses. It is not LLM security. It is not one gateway sitting in front of one tool. AI never shows up in one place. You have the tools your company approved. You have the tools employees found on their own. And now you have agents acting on behalf of both. The work is detecting AI and enforcing your rules in the same moment, wherever it touches sensitive data.
Enterprises need a distinct approach because the old model was built to keep sensitive data away from risk. Data is exactly what you want AI to work with. Separation used to be a form of protection. Now it’s become a cost.
Forcepoint CEO Ryan Windham described trust as becoming a “deliverable” for the agentic enterprise. From a marketing and go-to-market perspective, how do you translate that concept into something customers can actually understand and act upon?
You make trust concrete. It’s not a feeling. The first thing you need is the rules you write before anything runs. What an agent may touch. What it may act on. What it may never send. Least-privilege is necessary. What matters most is enforcement that adjusts in real time, the moment data and AI meet.
The second is the record you own. Every enforcement logged as it happens, why the decision was made, in plain language. It’s the reporting an auditor or a regulator will accept without requiring a project to assemble it.
That is what we mean by proving trust in data and AI. Giving AI approval or permission is not command. Command is delivering policy enforcement where AI and sensitive data intersect and showing the evidence.
For a CISO or CIO, this is the difference between claiming the AI program is safe and verifying it. Boards, regulators, and end-user customers ask now. It is AI and data trust you can prove. Marketing’s job is to strip out the abstraction. Show the customers what lands in the audit trail.
AI agents are becoming more capable of accessing data, making decisions, and taking actions on behalf of users. What are the biggest security and data governance challenges you believe organizations are understanding as they move toward agentic AI?
Inheritance comes to mind. Agents do not ask permission because they do not need it. They inherit it from the person or the service account that deployed them.
Identity systems verify who an agent is. Nothing in that model says what the agent may use that authority for. An agent never exceeds its authority. It exceeds your intent. Those are different problems and most organizations are only solving the first one. The fix is to govern the action and control the data before the AI touches it, not only the identity. Inspect the content, pass through what’s allowed, and redact what is not. An agent can read the file, but sending it somewhere else is a separate decision.
The second thing people underestimate is that this is not a rogue-agent story. An agent your company approved inherits permissions the same way an unapproved one does. Sorting risk by whether you sanctioned the tool is not good enough.
Third is the output side. Agents generate new data constantly, and it is often more sensitive than what they started with. Your governance must understand what goes into the prompt and what comes out in the response.
All of which starts with understanding the data itself. Know what you hold, know what matters most, and put controls around the agents, shadow AI, and sanctioned tools reaching for it. This is not a one-time assessment. It runs continuously and adapts as data and AI move.
Building an AI data security category through the channel
You’re joining Forcepoint after a decade at Proofpoint, where you helped significantly scale the company’s growth engine. What lessons from that experience will you bring to Forcepoint as it works to establish AI data security as a market category?
Discipline, mostly. Categories aren’t won with a clever campaign. They’re won by saying the same true thing consistently until the market starts repeating it back to you.
For ten years, I had a ground-floor view of a software company that grew from about $400 million to more than $2.4 billion. What made that work was alignment around a clear story: one that employees, sales, partners, and analysts could all tell and a shift away from features and functions toward the jobs customers actually needed to get done.
I’ll bring that same discipline to Forcepoint, but the opportunity here is different in an important way. Forcepoint has already built and shipped the AI Data Security platform.
So my priority is to help the market understand where AI data security is going, the problems enterprises need to solve today, and why Forcepoint is uniquely positioned to solve them. Then we’ll build the customer proof, partner momentum, and market voice that turns that story into a category.
What role do you see technology partners, MSPs, and other channel organizations playing in helping customers adopt AI while maintaining control over their data and AI interactions?
In a word, central. Forcepoint is channel-led, and in markets around the world the channel is often where the customer relationship lives.
The bigger opportunity is strategic. AI is creating a new set of conversations with customers, and partners are in a unique position to help customers navigate them. They’re being asked what data is going into AI, what those applications and agents can access, and how to scale AI without losing control.
A defined category gives partners a repeatable framework for that conversation. It lets them lead consultatively rather than starting with a feature comparison.
And agentic AI security starts with discovery: what data exists, what agents are running, what AI applications are touching, and what they should never touch. That creates an assessment, architecture, or services opportunity before it ever becomes a software license.
The platform then extends the data security customers already have. They don’t have to rebuild their environment to secure AI. They can extend existing policies.
That’s the opportunity for partners: to move beyond reselling a control and become the people helping customers build a trusted AI and data environment. That’s a much more strategic and valuable place to stand.
Forcepoint’s AI data security priorities for the next 18 months
Going forward, what do you want Forcepoint to accomplish in the next 12 to 18 months regarding defining the AI data security market and helping enterprises move from experimenting with AI to deploying it with confidence?
I’m focused on three outcomes over the next 12 to 18 months.
First, define the category. I want AI data security to become a recognized discipline in the enterprise security task, with Forcepoint helping shape what that means. We earn that position through a consistent point of view, strong customer proof, and partners and customers who can articulate the problem in their own words. If we do that well, we’re not just participating in a category, we’re helping define it.
Second, be in the room when the important AI decisions are being made. I don’t want Forcepoint to be a vendor a security leader thinks about at renewal time. I want us to be one of the two or three companies they call when they’re asking, “How do we safely put our most sensitive data into AI? How do we govern agents? How do we move from experimentation to production?” That means earning trust well before a buying cycle starts.
Third, help customers move from pilots to production. A lot of enterprises are experimenting with AI in a very controlled corner of the business, where the most interesting or sensitive data isn’t allowed anywhere near it. That’s not really an AI strategy. It’s a proof of concept.
The opportunity is to give organizations enough visibility and control over the intersection of data and AI that they can put their most valuable information to work confidently, rather than cautiously.
So the outcome I want isn’t simply more deployments of Forcepoint. It’s more enterprises deploying AI with confidence because they understand where their sensitive data is going, how it’s being used, and what is allowed to happen next.
If we can help create that shift and become synonymous with the security discipline that enables it, I think we’ve done something much bigger than hitting a marketing target. We’ve helped define a market and accelerate the adoption of the technology that market exists to secure.





