Proofpoint Targets AI, Data Risks with Agentic Security

Proofpoint launches agentic security systems for AI, data and collaboration, adding autonomous detection, investigation and remediation.

Written By
Jordan Smith
Jordan Smith
Sep 24, 2026
4 minute read
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Proofpoint is expanding its security portfolio with two agentic systems designed to automate how organizations detect, investigate, and remediate risks across AI, enterprise data, and collaboration tools.

At its flagship Proofpoint Protect 2026 event in San Diego, California, the company introduced:

  • Agentic Data and AI Security System: A unified agentic system that combines AI and data security. It is powered by the Proofpoint Knowledge Graph and uses three autonomous agents to detect, investigate, and remediate risk. Semantic Business Policies and Agentic Insights also help translate business intent into runtime controls and uncover emerging risks across human and AI activity.
  • Agentic Collaboration Security System: Combines intent-based detection and agentic capabilities to identify sophisticated attacks before, during, and after they reach people. It then reasons what an interaction it is trying to accomplish, uses context to distinguish malicious intent from legitimate activity, and turns those decisions into action across email, collaboration tools, and the browser.

Proofpoint connects AI security with data governance

The Proofpoint Agentic Data and AI Security secures AI and data as one connected risk.

Organizations can use it to safely deploy AI agents with access to only the data they need based on intent, while translating existing business policies into runtime controls and continuously uncovering emerging risks across human and autonomous AI activity.

“You cannot secure AI without securing the data it acts on, and you cannot secure data without understanding how AI is using it,” said Mayank Choudhary, executive vice president and general manager, Data Security and Governance Group, Proofpoint.

“Intent and access are two sides of the same coin. Securing them separately leaves critical context behind. Bringing AI run-time protections and AI data governance together gives organizations that context, and the ability to act on risk at the speed AI now moves,” adds Choudhary.

Advertisement

Three agents automate detection, investigation and remediation

Further, as AI governance extends beyond data loss, agents can interact with enterprise systems, make decisions, and execute transactions, thereby creating financial, operational, compliance, and safety risks.

The new agents work within the system:

  • The Detection Agent: Identifies intent and access as a single signal, surfacing the handful of actions that matter instead of the flood of anomalies traditional tools can’t stop generating.
  • The Investigation Agent: Automatically reconstructs what happened across data, identity, and behavior, turning an investigation that once took days of manual correlation into minutes.
  • The Remediation Agent: Turns understanding into action, from access remediation to DLP policy optimization, with a human in the loop for governance.

Collaboration security shifts toward intent-based detection

The Agentic Collaboration Security System brings together a new intent-based detection model and agentic capabilities to protect how people communicate and collaborate.

The system reasons about what an interaction is trying to accomplish, uses context to distinguish malicious intent from legitimate activity, and turns those decisions into action across email, collaboration tools, and the browser.

Proofpoint Knowledge Graph is at the foundation of the system, combining threat intelligence on active campaigns, industry attack patterns, and compromised suppliers with organizational context including business relationships, communication patterns, data access, and user risk.

“Attackers increasingly operate inside the relationships and workflows organizations already trust,” said Tom Corn, executive vice president and general manager of the Threat Protection Group at Proofpoint. “That changes the detection problem.”

Advertisement

The new Nexus Intent-Based Detection Model reasons about the organizational context through a multi-stage analysis that adapts to the ambiguity of each interaction.

Knowledge Graph and Nexus model combine to provide a shared foundation, allowing intelligence from one control point to inform detection, investigation, and user protection across the system.

“Security needs to understand what an interaction is trying to accomplish, reason over the context around it, and act before the attacker succeeds. Not with disparate tools, but as one system that gets smarter with every decision it makes,” Corn said.

Proofpoint extends protection into the browser

Proofpoint also introduced Advanced Browser protection, an offering that provides a comprehensive security control point, extending continuous collaboration security beyond the gateway and inbox to the browser.

It was built in partnership with Push Security, unifying Proofpoint’s email threat intelligence with browser-native protection to help organizations stop post-click phishing and malicious URLs in the browser, malicious browser extensions, OAuth phishing, credential theft, session hijacking, and other browser-borne attacks.

Further, browser telemetry is integrated into Threat Protection Workbench, the Proofpoint Security Graph, and the Investigation Agent. This gives security teams unified visibility and investigation workflows across the entire collaboration attack chain from message delivery through browser interaction.

Jordan Smith

Jordan Smith is an enterprise technology and cybersecurity journalist with nearly a decade of experience covering B2B IT, federal technology, artificial intelligence, cybersecurity, cloud computing, and emerging digital trends. His reporting helps business and technology leaders understand how new technologies, security challenges, and infrastructure decisions affect modern organizations. Jordan has reported on enterprise and public-sector technology for TechnologyAdvice, HCLTech, MeriTalk, and Channel Insider. His background spans cybersecurity, cloud infrastructure, AI adoption, digital transformation, and federal IT initiatives, giving him a broad perspective on the tools, policies, and innovations shaping today’s technology landscape. Before joining TechnologyAdvice, Jordan served as a Senior Technology Reporter at MeriTalk, where he covered the federal IT space, and later worked as a US Regional Reporter and Copy Editor/Writer for HCLTech. His experience across reporting, copyediting, podcasting, and event moderation allows him to translate complex technical topics into clear, timely, and useful insights for business audiences. Jordan holds a Master of Arts in Journalism from the University of Nebraska–Lincoln and a Bachelor of Science in Criminal Justice and Psychology from Edgewood University. Through his work, he helps readers stay informed about cybersecurity developments, enterprise technology trends, and the business impact of emerging IT solutions.

Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.