As enterprises race to adopt generative AI, Forcepoint is introducing a new platform aimed at helping organizations—and the partners supporting them—govern how sensitive data is accessed, shared, and protected.
AI Data Security combines AI governance with data security controls to monitor sanctioned AI applications, shadow AI, and autonomous agents from a single platform.
Forcepoint connects AI governance with data protection
The platform delivers protection from the data layer up, understanding where sensitive data lives and where AI risk emerges. It binds intelligent policy to the information itself and enforces it through every prompt, agent, and integration across channels.
“For 20 years, security meant keeping sensitive data away from risk. AI flips that,” said Ryan Windham, CEO of Forcepoint. “The data you most want to protect is the data that makes AI worth using. I’d urge every agentic enterprise to stop locking AI down and start securing it where the risk actually lives, in the data itself. Other approaches will only tell you what’s at risk. Forcepoint’s protection travels with your data into AI and proves it can be trusted there.”
The Forcepoint architecture now governs the platform inside AI, delivered from the cloud or on-prem.
Platform controls access by agents and AI applications
The new capabilities span autonomous agents, sanctioned AI, and shadow AI to address AI data security through discovery, classification, control, guardrails, and governance.
The new Forcepoint Platform innovations include:
- AI security visibility and governance: Users can see every agent running in the environment and tie each activity to a person, an agent, or a combination, with full identity attribution.
- AI Agent Gateway: Enforcement of least-privileged, field-level data protection for autonomous agents accessing enterprise applications like Salesforce, Microsoft 365, and Jira, preventing agents from holding direct application credentials.
- Real-time prompt and response control: Protect sensitive information used with AI by inspecting every prompt and AI-generated response inline.
- Data loss prevention for AI: Stop PII, PCI, and other regulated data leakage by enforcing protection policies across AI workflows.
- Confidential file protection: Keep confidential files out of AI summaries by identifying and tagging them (MIP Tagging) across the Forcepoint Platform.
- Inline control of shadow AI: Contain shadow AI risk by allowing or blocking unsanctioned AI apps by policy, inline, and in real time.
- Personal vs. corporate tenant detection: Restrict AI to governed corporate accounts by allowing corporate-account access while blocking personal-account access.
- AI Detection and Response (AIDR): Govern sanctioned apps, shadow AI, and agents from a unified dashboard to inspect and monitor data flowing through a broad range of API connectors such as ChatGPT Enterprise, Microsoft Copilot, Claude Enterprise, and AWS Bedrock.
- AI-guided, natural language security and governance: Embedded assistant, AIRA, enables teams to create, govern, and enforce AI policies automatically, using plain-English recommendations that eliminate the need for training or policy expertise.
- Single-console AI oversight, powered by Forcepoint Insights: Users gain automated, board-ready reports on risk trends, threats stopped, and top risky users, monitoring approved and unsanctioned AI from one console, with historic usage on connection.
- AI-powered discovery and classification: Identify, tag, and protect IP and regulated data before it reaches any AI tools across unstructured and structured sources, including Google Workspace, Databricks, and Snowflake.
“The hardest problem in enterprise security right now is ensuring that sensitive data stays protected once employees put it into AI, whether sanctioned or not,” said Roland Cloutier, Strategic Security Advisor and former Chief Security Officer at TikTok, ADP, and EMC.
“Forcepoint’s approach is notably different, because it moves past visibility to enforcement that follows the data itself, which is what defensibility to auditors and boards actually requires. Knowing where your data goes is table stakes now. Proving it stays protected is the job across the enterprise, inside and outside of security.”





