At Proofpoint Protect in San Diego, Proofpoint framed governance of AI agents as the central security task, presenting intent-based controls and knowledge graphs that check whether humans and agents do what they should. Attackers already use AI to write flawless phishing lures and chain exploits at machine speed, while enterprise agents operate with access to data, systems and inboxes. With annual recurring revenue close to $2.5 billion, the company links the launch to platform consolidation. The shift matters because agents behave as insiders that perimeter blocking was not built to contain.

Proofpoint bets on intent and knowledge graphs to govern AI agents

Two agentic systems and tiered detection

Proofpoint introduced two agentic systems for collaboration security and for data and AI security, both built on a knowledge graph that tracks how people and AI communicate and access data. Chief executive Sumit Dhawan positioned them as compensating controls for a reality in which no company can patch every vulnerability. For threat detection, the Nexus suite gained intent-based models in Flash, Extended-Thinking and Deep-Thinking tiers to catch attacks that look legitimate. Executive vice president Tom Corn said a new Community Hyperloop distributes each new detection to every customer at machine speed, a response to hijacked supplier threads that carry no malware.

The model judges intent rather than signatures. Instead of asking whether a file contains malware, it asks whether the actor should take this action on this data at this moment, using a graph that connects actors, actions and data. That design reflects where agents run: about 99% of the agentic activity Proofpoint monitors happens on ordinary endpoints rather than in the cloud, supported by tens of millions of endpoint sensors. Chief strategy officer Ryan Kalember said written governance policies for humans must become real-time controls that agents can interpret. Data security chief Mayank Choudhary described the same graph as a contextual layer for governance, detection and remediation while AI systems run continuously.

The event captured a shift from blocking AI projects to enabling safer adoption. Senior director Molly McLain Sterling said identifying intent is now the critical step because an agent given a job can optimize its way into doing something else. The threat picture is splitting: skilled actors use AI to accelerate malware development and translate lures into as many as 16 languages, while low-end actors grow sloppier, according to researcher Selena Larson. Anthropic added urgency by expanding Project Glasswing to place its Mythos Preview model with more defenders after holding back general release to add guardrails. Consolidation reinforces the timing, with growth of nearly 20% including Hornetsecurity after doubling since Thoma Bravo took the company private in 2021.

What agent governance means for business

For companies deploying agents, the consequence is a change in where controls live. Protection moves from network perimeters and cloud logs to endpoints and data-access context, with intent checks applied to every human and agent action. A detection proven in one tenant can then reach all customers at machine speed, which shortens exposure to hijacked-thread campaigns that carry no malware. Consolidation also affects budgets: chief financial officer Remi Thomas cited a Canadian bank that replaced four suppliers in a $25 million five-year deal to free funds for AI. Smaller firms gain the same shared detections as large enterprises, while large firms reduce integrations across collaboration and data estates.

The approach leaves several conditions to verify before purchase. Intent models depend on visibility into endpoints, inboxes and data stores, so gaps in sensor coverage or unmapped data weaken judgments. Anthropic head of national security partnerships Robert Bair advised writing policy first, adding sandboxing and visibility, and starting small with a clear view of the blast radius, since new models can chain low-severity flaws into serious exploits. Static detections lose value quickly against adaptive lures, so buyers should ask how Flash, Extended-Thinking and Deep-Thinking tiers differ in latency, cost and false positives. The news alone does not mean agents are safe to grant broad inbox or system rights.

The marker to watch is whether intent controls and shared detections become standard in procurement: wider delivery of Mythos Preview to defenders, new Hyperloop-driven detections in production, and further consolidation deals on the scale of the Canadian bank agreement. If those three advance together, agent governance will move from pilot guidance to operating infrastructure.