Proofpoint is expanding its security portfolio with two agentic systems designed to automate how organizations detect, investigate, and remediate risks across AI, enterprise data, and collaboration tools.
At its flagship Proofpoint Protect 2026 event in San Diego, California, the company introduced:
- Agentic Data and AI Security System: A unified agentic system that combines AI and data security. It is powered by the Proofpoint Knowledge Graph and uses three autonomous agents to detect, investigate, and remediate risk. Semantic Business Policies and Agentic Insights also help translate business intent into runtime controls and uncover emerging risks across human and AI activity.
- Agentic Collaboration Security System: Combines intent-based detection and agentic capabilities to identify sophisticated attacks before, during, and after they reach people. It then reasons what an interaction it is trying to accomplish, uses context to distinguish malicious intent from legitimate activity, and turns those decisions into action across email, collaboration tools, and the browser.
Proofpoint connects AI security with data governance
The Proofpoint Agentic Data and AI Security secures AI and data as one connected risk.
Organizations can use it to safely deploy AI agents with access to only the data they need based on intent, while translating existing business policies into runtime controls and continuously uncovering emerging risks across human and autonomous AI activity.
“You cannot secure AI without securing the data it acts on, and you cannot secure data without understanding how AI is using it,” said Mayank Choudhary, executive vice president and general manager, Data Security and Governance Group, Proofpoint.
“Intent and access are two sides of the same coin. Securing them separately leaves critical context behind. Bringing AI run-time protections and AI data governance together gives organizations that context, and the ability to act on risk at the speed AI now moves,” adds Choudhary.
Three agents automate detection, investigation and remediation
Further, as AI governance extends beyond data loss, agents can interact with enterprise systems, make decisions, and execute transactions, thereby creating financial, operational, compliance, and safety risks.
The new agents work within the system:
- The Detection Agent: Identifies intent and access as a single signal, surfacing the handful of actions that matter instead of the flood of anomalies traditional tools can’t stop generating.
- The Investigation Agent: Automatically reconstructs what happened across data, identity, and behavior, turning an investigation that once took days of manual correlation into minutes.
- The Remediation Agent: Turns understanding into action, from access remediation to DLP policy optimization, with a human in the loop for governance.
Collaboration security shifts toward intent-based detection
The Agentic Collaboration Security System brings together a new intent-based detection model and agentic capabilities to protect how people communicate and collaborate.
The system reasons about what an interaction is trying to accomplish, uses context to distinguish malicious intent from legitimate activity, and turns those decisions into action across email, collaboration tools, and the browser.
Proofpoint Knowledge Graph is at the foundation of the system, combining threat intelligence on active campaigns, industry attack patterns, and compromised suppliers with organizational context including business relationships, communication patterns, data access, and user risk.
“Attackers increasingly operate inside the relationships and workflows organizations already trust,” said Tom Corn, executive vice president and general manager of the Threat Protection Group at Proofpoint. “That changes the detection problem.”
The new Nexus Intent-Based Detection Model reasons about the organizational context through a multi-stage analysis that adapts to the ambiguity of each interaction.
Knowledge Graph and Nexus model combine to provide a shared foundation, allowing intelligence from one control point to inform detection, investigation, and user protection across the system.
“Security needs to understand what an interaction is trying to accomplish, reason over the context around it, and act before the attacker succeeds. Not with disparate tools, but as one system that gets smarter with every decision it makes,” Corn said.
Proofpoint extends protection into the browser
Proofpoint also introduced Advanced Browser protection, an offering that provides a comprehensive security control point, extending continuous collaboration security beyond the gateway and inbox to the browser.
It was built in partnership with Push Security, unifying Proofpoint’s email threat intelligence with browser-native protection to help organizations stop post-click phishing and malicious URLs in the browser, malicious browser extensions, OAuth phishing, credential theft, session hijacking, and other browser-borne attacks.
Further, browser telemetry is integrated into Threat Protection Workbench, the Proofpoint Security Graph, and the Investigation Agent. This gives security teams unified visibility and investigation workflows across the entire collaboration attack chain from message delivery through browser interaction.




