
22 Sep 2026
Proofpoint unifies data security and AI security in one agentic system
Proofpoint announced the Proofpoint Agentic Data and AI Security system at Protect 2026, built to secure AI and data as one connected risk with shared identity, access, and data context.
SOFTWARE desk — AI agents need data access to work, and data tools rarely see agent intent; unifying both is the security shape enterprises will demand as agents act faster than manual review.
What the system is supposed to do. The release says it is built to secure AI and data as one connected risk. The capabilities, still the company’s, let an organization deploy AI agents with access only to the data they need based on intent, turn existing business policies into controls that run while the agent is acting, and keep looking for new risks across employees and autonomous agents. An agent, here, is software that takes steps, not only a chat reply. Intent means what the person or the agent is trying to do. Runtime means during the action, not in a review the next day. These lines are the company’s. This desk did not install the system.
The split the page says it is closing. Point security tools were built to see either AI behavior or data risk, not both. The page says Proofpoint is the first vendor to reason across both in one shared graph. First is the company’s word. The body says AI agents now discover, access, transform, and act on sensitive data at a scale no manual review can match. AI tools often see intent but not which data was opened. Data tools see sensitive data but not what the agent meant to do. Seeing only half the picture leaves risk unseen. The same section says AI governance now goes past data loss. Agents can touch company systems, make decisions, and carry out transactions, which the page says creates financial, operational, compliance, and safety risks. File that framing as the company’s. This desk did not count a customer’s agents.
The survey line, and whose numbers they are. Proofpoint’s 2026 AI and Human Risk Landscape report found that 87 percent of organizations have moved AI assistants beyond a pilot, yet 52 percent are not confident their controls could detect a compromise. 87 percent is almost nine in ten. 52 percent is a little more than half. A pilot is a limited trial. A compromise, here, means an attacker got in. The page does not print how many organizations answered. Do not invent a sample size. These figures are Proofpoint’s. This desk did not run the survey. The release says security teams now need to define and enforce AI behavior in real time.
The map the agents share. The system reasons at the agent level, using the same identity, access, and data context that the page says already secures more than 14,000 enterprises’ data. It is built on the Proofpoint Knowledge Graph. The page calls that graph the foundation. It connects AI activity with data sensitivity, identity, access, behavior, and intent through Nexus models. The page names Nexus models. It does not define them. Do not invent a definition. A knowledge graph, here, is the company’s map of those connections. Identity is who or what is acting. Access is what that actor is allowed to open. More than 14,000 is the company’s count. This desk did not audit the customer list.
Three new agents, one risk model. Zero-Touch Detection is the Detection Agent. It sees intent and access as one signal, and it surfaces the handful of actions that matter instead of the flood of anomalies the page says traditional tools cannot stop generating. An anomaly is a behavior that looks unusual. Instant Investigation is the Investigation Agent. It rebuilds what happened across data, identity, and behavior on its own, turning an investigation that once took days of manual correlation into minutes. Correlation means lining those records up by hand. Protection Optimization is the Remediation Agent. It turns that understanding into action, from access remediation to DLP policy optimization, with a human in the loop for governance. Access remediation means fixing who can open what. DLP is data loss prevention, the rules that try to stop sensitive data from leaving. A human in the loop means a person still approves the governance step. Days to minutes is the company’s comparison. This desk did not time an investigation.
Policies written in plain language. Proofpoint Semantic Business Policies translate governance rules a company already has into AI controls that keep running. The example on the page: a rule already in a code of conduct, such as a ban on gambling content, can be written as “Do not allow interactions with gambling content.” Proofpoint says it reads the intent of that sentence, finds the systems that can carry the rule out, and generates the runtime controls that enforce it. Combined with Proofpoint Intent-Based Access Control, those policies judge AI behavior against both the company’s rules and the agent’s intended purpose. That covers an employee working through an AI assistant, and an autonomous agent acting for that employee. File the gambling sentence and the control name as the page’s. This desk did not write a policy.
Risks the company has not written down yet. Agentic Insights uses reasoning agents to look at AI interactions, tool use, policy decisions, and behavior patterns, and to surface risks that are still emerging. A tool, here, is a function the agent can call. When a risk is validated, Proofpoint can recommend a Semantic Business Policy for similar behavior, so the new finding becomes a rule. The page says detection, investigation, and remediation turn the shared context into action, while the policies and the insights keep up with risks the organization has not defined. Together, the release says, they put real risk first, speed investigations with data, identity, access, and behavior, and cut exposure through access fixes, DLP policy changes, and runtime controls. File that as the company’s. This desk did not watch an agent recommend a policy.
Two quotes, as the company’s, not as a count. Mayank Choudhary, executive vice president and general manager of the Data Security and Governance Group, said you cannot secure AI without securing the data it acts on, and you cannot secure data without understanding how AI is using it. He said intent and access are two sides of the same coin, and that securing them separately leaves critical context behind. He said bringing AI runtime protections and AI data governance together gives organizations that context, and the ability to act at the speed AI now moves. Ryan Kalember, chief strategy officer, said organizations have spent decades defining how their businesses should operate, and the challenge is making those rules enforceable as AI takes on more consequential work. He said business intent needs to become part of the security control itself, with the ability to find new risks and adapt as AI behavior changes. File the names, the titles, and those sentences as the release’s. A quote is not a measured detection rate.
When it ships, and what the page leaves blank. Capabilities inside the system, plus Semantic Business Policies and Agentic Insights, are expected to be available by year-end 2026. Expected is the page’s word. It is not a ship date this desk confirmed, and it is not a product a customer can turn on from this page today. The release points readers to two company blogs for more. Those pages are not a second announcement. This filing does not treat them as one. The about box says Proofpoint secures how people, data, and AI agents connect across email, cloud, and collaboration tools. It says Proofpoint is a trusted partner to over 80 of the Fortune 100, over 14,000 large enterprises, and millions of smaller organizations. Over 80 of the Fortune 100, and the second 14,000 line, are the company’s. The page does not print a price. Do not add one.
Plain English for the rest of the card: agent = software that takes steps, not only a reply. intent = what the person or the agent is trying to do. runtime = while the action is happening. Knowledge Graph = Proofpoint’s map of AI activity, data sensitivity, identity, access, behavior, and intent. The page does not define Nexus models. identity = who or what is acting. access = what that actor may open. Detection Agent = Zero-Touch Detection, intent and access as one signal. Investigation Agent = Instant Investigation, days of manual lining-up into minutes, on the company’s comparison. Remediation Agent = Protection Optimization, from fixing access to tuning data-loss rules, with a person still approving. DLP = data loss prevention. human in the loop = a person still approves the governance step. Semantic Business Policy = a rule the company already has, rewritten so the system can enforce it. Agentic Insights = reasoning that looks for risks not yet written as rules. 87 percent and 52 percent are Proofpoint’s survey figures. The page does not print a sample size. More than 14,000 is the company’s enterprise count. Year-end 2026 is when the page says the capabilities are expected. This filing is the 22 Sep announcement.
PRIMARY here: Proofpoint’s 22 Sep 2026 newsroom release, “Proofpoint Breaks Down the Divide Between Data Security and AI Security with the Industry’s First Unified Agentic System,” datelined Sunnyvale, Calif., and Proofpoint Protect 2026, San Diego — Tier A PRIMARY, the company’s own record. The page did not print an hour. The system name, the one-connected-risk line, the intent-based data access, the runtime controls, the half-picture paragraph, the first-vendor sentence, the risks beyond data loss, the 87 percent and 52 percent lines from the 2026 AI and Human Risk Landscape report, the more-than-14,000 enterprises line, the Knowledge Graph, the Nexus models name, the three agents, the gambling-policy example, Intent-Based Access Control, Agentic Insights, the Choudhary and Kalember titles and quotes, the year-end 2026 availability, the two blog links, and the about-box counts are the release’s. NOT claimed: that this desk installed the system, attended Protect 2026, ranked a “first” or a “leader,” ran the survey, counted the 14,000 or the Fortune 100, defined Nexus, timed an investigation, wrote a policy, found a price, a stock tip, or investment advice. Distinct from the already-filed salt-security-aidr, cyera-400m, and outerlimit-16m.
RELATED
On 22 Sep 2026, Proofpoint announced the Proofpoint Agentic Data and AI Security system. The record is the company’s newsroom release. The page says September 22, 2026. It does not print an hour. The dateline is Sunnyvale, Calif., and Proofpoint Protect 2026 in San Diego. The headline calls it the industry’s first unified agentic system for data security and AI security. “Industry’s first,” and the about-box line that Proofpoint is a global leader in human and agent cybersecurity, are the company’s words. This desk did not rank vendors, and it did not attend the event.