AI Governance Takes Center Stage at Proofpoint Protect Event
At the recent Proofpoint Protect event, discussions about cybersecurity shifted from the potential deployment of AI agents by enterprises to the critical need for effective governance of these technologies. Cybercriminals are increasingly utilizing AI to craft highly sophisticated phishing schemes and execute exploits at remarkable speeds. Concurrently, the AI agents that companies deploy internally are acting as insiders, gaining access to sensitive data, systems, and personal inboxes.
Intent-Driven Security Models on the Rise
The next phase of cybersecurity will be heavily influenced by intent. Security professionals are now developing knowledge graphs and intent-based models to assess whether actions are appropriate for human users or AI agents. Furthermore, companies are translating their written governance policies into actionable, real-time controls. This urgency has prompted organizations like Anthropic PBC to broaden the reach of their Project Glasswing, allowing more defenders access to their vulnerability-hunting Mythos Preview model.
Speed: The Competitive Edge for Enterprises
John Furrier, executive analyst for theCUBE Research, noted that large enterprises perceive the digital transformation as a competitive advantage. “Their game is speed,” he stated, emphasizing that those who can provide better products and outcomes will prevail. However, he cautioned that this approach introduces significant security risks.
Insights from Industry Leaders at the Event
During the Proofpoint Protect event held in San Diego, executives and researchers from Proofpoint Inc. and Anthropic participated in exclusive interviews with Furrier. These discussions covered various topics, including the emergence of agentic threats, the role of knowledge graphs, platform consolidation, and the paradoxical landscape facing AI agents.
Shifting Focus from Blocking to Enabling AI
Security teams are increasingly adopting a proactive stance toward agentic AI, shifting from a model of blocking to one that facilitates safer innovation. As stated by Molly McLain Sterling, senior director of cybersecurity strategy at Proofpoint, identifying an agent’s intent—whether human or AI—is critical, especially as AI tools can optimize their tasks, potentially leading to unintended consequences.
Innovative Security Systems Leveraging Knowledge Graphs
Proofpoint also unveiled two new agent-based security systems designed for collaboration and data protection. Both systems leverage a knowledge graph that will monitor interactions between humans and AI to assess data access. As Sumit Dhawan, CEO of Proofpoint, noted, since it is impossible to patch every vulnerability, enterprises require compensating controls that can evaluate the intent of both human users and AI agents.
Combatting Sophisticated Cyber Threats
To counter increasingly sophisticated cyber threats, Proofpoint has enhanced its Nexus detection suite with new intent-based models, which operate across various tiers of analysis. Tom Corn, executive vice president and general manager of the Threat Protection Group at Proofpoint, highlighted that attackers have taken to hijacking legitimate email conversations without relying on malware, necessitating advanced detection capabilities.
Acknowledging Insider Risks from AI Agents
Currently, approximately 99% of the agentic activity monitored by Proofpoint occurs on standard endpoints rather than in the cloud. This reality underscores the importance of transforming governance policies intended for human users into real-time controls comprehensible by AI agents. Ryan Kalember, chief strategy officer of Proofpoint, stressed that ongoing vigilance is essential to mitigate potential insider risks.
Advancing AI Security with Intent Engineering
An urgent recommendation from Anthropic was for organizations to focus on building trust in their AI systems before scaling their usage. Robert Bair, head of national security partnerships at Anthropic, pointed out that the anticipated widespread release of newer AI models must be tempered by developing robust guardrails to prevent the exploitation of low-severity vulnerabilities.
Continued Growth in AI and Cybersecurity Investments
As enterprises embrace the capabilities of AI, Proofpoint’s annual recurring revenue has approached $2.5 billion, marking a nearly 20% growth. This financial progress follows a significant expansion since the company was taken private by Thoma Bravo LP in 2021. Firms are consolidating their security service providers to allocate more budget toward AI innovations, exemplified by a Canadian bank that replaced four vendors in a substantial $25 million, five-year agreement.
Cyberattackers Split into Skilled and Inexperienced
The landscape of cybercriminals is increasingly polarized, with skilled actors leveraging AI to expedite malware development and translate social engineering tactics into multiple languages. Conversely, lower-tier attackers appear less organized. Selena Larson, principal threat researcher at Proofpoint, remarked that traditional static detection methods are rapidly becoming obsolete, urging defenders to adopt more dynamic strategies that can anticipate and counter future attacks.
Knowledge Graphs: The Future of Security Governance
As access to data becomes more fluid, driven by both human and AI activity, organizations must establish clarity regarding access rights and motivations. Proofpoint is developing a comprehensive knowledge graph to connect various actors, their actions, and the data they can access, facilitating improved governance, detection, and response capabilities as AI systems continue to evolve.

