Proofpoint has rolled out two new autonomous security systems that automate threat detection, investigation, and response across artificial intelligence applications, enterprise data stores, and collaboration platforms. The company unveiled the products at its Proofpoint Protect 2026 conference in San Diego, California, introducing technology designed to address risks created by AI agents operating with broad access to sensitive corporate information. The systems use specialized autonomous agents to identify threats, reconstruct attack sequences, and execute defensive actions across email, browsers, and collaboration tools.
The first product, called the Agentic Data and AI Security System, merges AI protection with data governance through three distinct autonomous agents. The Detection Agent surfaces high-priority actions by identifying intent and access as a unified signal, filtering out the flood of anomalies that conventional tools generate. The Investigation Agent automatically reconstructs incidents across data, identity, and behavior patterns, compressing investigations that previously required days of manual work into minutes. The Remediation Agent converts those findings into corrective actions — from access controls to data loss prevention policy adjustments — while keeping humans in the decision loop for oversight. The system also features Semantic Business Policies and Agentic Insights, which translate organizational rules into runtime controls and reveal emerging risks stemming from both human users and AI activity.
According to Mayank Choudhary, executive vice president and general manager of Proofpoint's Data Security and Governance Group, organizations face a fundamental challenge: "You cannot secure AI without securing the data it acts on, and you cannot secure data without understanding how AI is using it." The report notes that AI governance now extends beyond preventing data leaks, since agents can interact with enterprise systems, execute transactions, and make decisions that create financial, operational, compliance, and safety exposures. Tom Corn, executive vice president and general manager of the Threat Protection Group at Proofpoint, explains that attackers increasingly operate within the relationships and workflows organizations already trust, fundamentally altering the detection challenge. The second offering, the Agentic Collaboration Security System, combines intent-based detection with agentic capabilities to protect communication channels by reasoning about what each interaction attempts to accomplish, using context to separate malicious activity from legitimate business operations.
The collaboration security system relies on the Proofpoint Knowledge Graph, which consolidates threat intelligence on active campaigns, industry attack patterns, and compromised suppliers with organizational context such as business relationships, communication habits, data access rights, and user risk profiles. This foundation powers the Nexus Intent-Based Detection Model, which analyzes organizational context through multi-stage processing that adjusts to the ambiguity inherent in each interaction. Intelligence gathered from one control point flows to detection, investigation, and user protection functions across the entire system, allowing it to improve with each decision. Proofpoint also introduced Advanced Browser Protection, developed in partnership with Push Security, which extends collaboration security beyond gateways and inboxes to the browser itself. The browser offering stops post-click phishing, malicious URLs, harmful browser extensions, OAuth phishing, credential theft, and session hijacking, with browser telemetry integrated into Threat Protection Workbench, the Proofpoint Security Graph, and the Investigation Agent to give security teams unified visibility across the entire attack chain from message delivery through browser interaction.
The launches reflect Proofpoint's strategy to shift security architectures from isolated tools to integrated systems that reason about attacker intent and organizational context simultaneously. The company positions the agentic approach as essential for matching the speed at which AI now operates, arguing that traditional anomaly-based detection can't keep pace with autonomous agents that execute transactions and access sensitive data. By combining AI runtime protections with data governance in a single platform, Proofpoint aims to provide the contextual awareness needed to act on risk as it emerges, rather than after breaches occur. The shift toward intent-based detection and autonomous remediation signals a broader industry move away from signature-based defenses toward systems that understand business logic and attacker behavior. Security teams will need to evaluate whether embedding autonomous agents into their defensive infrastructure introduces new operational dependencies, even as those agents promise to compress response times from days to minutes.

