The new platform, built on Proofpoint’s existing knowledge‑graph technology, is aimed at the company’s existing base of more than 14,000 enterprise customers who already use its data security and governance products.

At the core of the offering are three autonomous agents – a detection agent that flags significant AI actions by assessing intent and access together, an investigation agent that reconstructs incidents across data, identity and behaviour, and a remediation agent that can recommend or automatically apply changes such as access adjustments and updates to data‑loss‑prevention policies, while keeping human oversight for governance decisions.

Proofpoint also introduced “Semantic Business Policies,” a tool that translates plain‑language business rules into enforceable runtime restrictions for AI activity; for example, a rule prohibiting interaction with gambling content can be expressed in everyday language and automatically applied to AI‑driven processes.

The system incorporates intent‑based access control, evaluating whether an AI action aligns with both corporate policy and the stated purpose of the employee or autonomous agent involved, whether the AI is accessed directly by a worker or acts independently on the worker’s behalf.

The launch comes as organisations move AI tools beyond pilot projects. Proofpoint’s 2026 AI and Human Risk Landscape report found that 87 % of surveyed companies have deployed AI assistants in production, yet 52 % say they lack confidence that existing controls can detect a compromise.

Mayank Choudhary, Executive Vice President and General Manager of Proofpoint’s Data Security and Governance Group, said the company views AI and data security as inseparable, noting, “You cannot secure AI without securing the data it acts on, and you cannot secure data without understanding how AI is using it.”

A further addition, called Agentic Insights, uses autonomous reasoning to examine AI interactions, tool usage, policy decisions and behavioural patterns, surfacing risks that have not yet been codified in formal policies and suggesting new Semantic Business Policies to address them.

Industry analysts see the move as part of a broader shift among security vendors toward AI governance rather than treating AI as just another endpoint, with the promise of reducing manual effort required to correlate data‑access logs, user‑behaviour signals and AI actions after an incident.

Ryan Kalember, Proofpoint’s Chief Strategy Officer, highlighted the challenge of translating decades‑long business rule sets into controls that function in AI‑led environments, saying, “Business intent needs to become part of the security control itself, with the ability to identify new risks and adapt as AI behaviour evolves.”