Proofpoint Agentic Security: Two Launches, One Knowledge Graph, and Questions Left Open

Proofpoint Agentic Security: Two Launches, One Knowledge Graph, and Questions Left Open

Two announcements at Protect 2026 in San Diego gave Proofpoint agentic security its full shape. The first, Agentic Data and AI Security, treats what AI agents do and what data they touch as one connected risk. The second, Agentic Collaboration Security, reasons about what a message is trying to accomplish. It then acts across email, collaboration tools, and the browser.

Both systems run on a shared Knowledge Graph and Nexus models. Data-and-AI capabilities arrive by the end of 2026; the collaboration system ships in Q1 2027. Neither requires a migration, the company says.

Read together, the launches define Proofpoint agentic security as one bet: intent and access are a single problem. CEO Sumit Dhawan calls it the defining challenge of the next decade — letting people and AI agents work at machine speed “without allowing risk to move at machine speed with them.” The demand side is measurable. Proofpoint’s own 2026 AI and Human Risk Landscape report found that 87 percent of organizations have moved AI assistants past pilot. Yet 52 percent doubt their controls would catch a compromised AI.

Attacks have shifted the same way. The hardest attacks now resemble normal business — a compromised supplier replying inside a real thread, a fraudulent payment request matching an established relationship.

The timing tells its own story. Proofpoint closed its $1.8 billion Hornetsecurity acquisition in December 2025 and bought AI-security startup Acuvity in February 2026. This week it wrapped those pieces, plus its existing data and email portfolios, in unified “system” labels.

Rivals moved earlier. Netskope announced comparable agent-action controls on September 15, and Palo Alto Networks, Microsoft, and a wave of specialists have pushed agentic platforms since March. These launches are less product debuts than the reveal of an 18-month assembly sprint.

The Competitive Picture for Proofpoint Agentic Security

The unified pitch lands in a crowded field, contested from two directions at once. Every major platform vendor claims some version of “first.”

The data-and-AI side: agents meet data

Netskope renamed its AI-security portfolio to Skylight in September and announced Agent Action Control on September 15, a week before Proofpoint’s launch. The capability classifies every agent action into nine intent categories and blocks high-risk actions before they execute. Netskope says the feature ships by the end of the current quarter, which would beat Proofpoint’s year-end target. IDC research director Grace Trinidad endorsed the deterministic, policy-based approach in Netskope’s announcement.

Palo Alto Networks took the acquisition route. Prisma AIRS 3.0, launched at RSAC in March 2026, covers the agentic-AI lifecycle with an AI Agent Gateway in limited preview. Protect AI, a model-security vendor, reportedly went for around $700 million in July 2025. Microsoft made Agent 365 generally available on May 1, embedding agent governance across Defender, Entra, and Purview. Specialists like WitnessAI, Straiker, HiddenLayer, and CrowdStrike’s Falcon AIDR crowd the field further.

The collaboration side: Microsoft and Abnormal

Microsoft publishes quarterly benchmarking data making a blunt claim. Defender for Office 365 misses 59 percent fewer high-severity threats before delivery than the next-closest secure email gateway. In its data, Proofpoint’s threat-miss rate runs 483 per 1,000 employees against Defender’s 194. Analysts quoted by CSO Online call the framing self-serving, but the pressure is real. Every Proofpoint pitch must now prove uplift on Microsoft’s home turf.

Abnormal Security argues the opposite: drop the gateway entirely. More than 3,200 organizations use its API-based, intent-driven behavioral AI, and 76 percent of them run without any secure email gateway. Proofpoint words its central claim carefully — the only secure email gateway with intent-based detection before a message reaches the user. Abnormal reasons about intent after delivery, from inside the mailbox. Whether pre-delivery analysis justifies a gateway is exactly the dispute now playing out.

The browser: everyone’s new control point

Advanced Browser Protection is a partnership, not a purchase. Push Security, founded by former red-team operators, supplies the browser-native layer. It detects session hijacking, OAuth phishing, credential theft, and malicious extensions. Backers include GV, Redpoint, and Datadog Ventures after a $30 million Series B in April 2025.

The field around it is richly valued. Island raised a $250 million Series E in 2025 at a reported $5 billion valuation. Palo Alto paid an estimated $625 million for Talon in 2023, and CrowdStrike acquired Seraphic Security for roughly $400 million in January 2026. Gartner estimates about 10 percent of organizations use secure-enterprise-browser technology today, rising to 25 percent by 2028.

Proofpoint’s differentiator — shared intelligence between the email lure and the browser click — is genuinely distinctive. It is also, so far, the company’s own claim.

What the Data Shows

The strongest demand signal comes from Proofpoint’s own April 2026 survey of more than 1,400 security professionals across 12 countries, including India. Beyond the adoption numbers above, 76 percent of organizations are piloting or rolling out autonomous agents. Only 33 percent feel fully prepared to investigate an AI-related incident, and some 53 percent plan to consolidate onto a unified platform within 12 months. It is vendor research, but it is the largest public dataset on this gap.

Launch blogs carry numbers the press releases omit. Roughly 85 percent of the workday happens in the browser and cloud apps, the company estimates. About a third of intercepted payloads last year never arrived through email at all. Among organizations with AI-related incidents, 67 percent saw threat activity in email — but 57 percent saw it in SaaS apps, 53 percent in AI assistants, and 49 percent in collaboration tools.

Company-reported figures also shifted quietly. Releases through March 2026 claimed “over 10,000” large-enterprise customers; the Protect 2026 releases say “over 14,000.” The jump follows the Hornetsecurity close, though the breakdown is not public. Dhawan’s blog adds texture the announcements skip: a “Satori Access layer” and a Managed Data Guard service. One disclosure matters most for buyers — the Nexus Adaptive AI Engine ships within existing email entitlements, beginning Q1 2027.

What’s New vs. Repackaged in Proofpoint Agentic Security

Genuinely new

Semantic Business Policies are the standout idea. Write “do not allow interactions with gambling content,” and Proofpoint interprets the intent and generates runtime controls automatically. Agentic Insights works as a conversational risk-hunting experience.

The Nexus Intent-Based Detection Model applies multi-stage reasoning, with most decisions resolving in under half a second. Privileged User Protection builds an individual threat model for each high-risk user. Advanced Browser Protection is new to the portfolio, though the technology comes from a partner.

Improved

The Knowledge Graph extends the behavior and data-security graphs announced at RSAC 2026, now fusing AI activity with identity, access, and intent signals. The unified gateway-plus-API architecture dates to March as well. What improves now is the feedback loop between pre- and post-delivery detection.

Repackaged

Back in September 2025, DLP, DSPM, insider-risk management, and data lineage shipped together as “Data Security Complete.” The Secure Agent Gateway, announced at Protect 2025 with Q1 2026 availability, now sits inside the new system. Adaptive User Protection extends the very-attacked-people analytics Proofpoint has published for years. Much of the system language re-labels the existing portfolio under a sharper marketing thesis.

Unclear

How the data system deploys — endpoint daemon, browser extension, network broker, or all three — is not specified. Pricing is absent, as is any performance claim. What the Blue Team and Red Team agents actually do while “continuously testing defenses” is undefined. The fate of messages flagged for deeper analysis is likewise unstated.

The Questions That Weren’t Answered

Liability comes first. The Remediation Agent takes real actions, from revoking access to changing DLP policies, “with a human in the loop for governance.” Which actions require approval, and which run automatically? If an autonomous remediation breaks a production workflow, who owns that outage? The press releases do not say.

False positives come second. Semantic interpretation of plain-language policies is probabilistic, and blocking a legitimate agent action in real time carries business cost. On ambiguous email, does a plausible payment request wait, or does it land in the CFO’s inbox while the system thinks? No benchmark answers either question yet.

Third, the commercial fine print. Is Advanced Browser Protection bundled, priced as an add-on, or dependent on a separate Push contract? Will Proofpoint submit its detection to independent benchmarking, rather than the vendor-run numbers that dominate email-security marketing? Data-residency caveats apply too. India-specific terms are not spelled out.

What Proofpoint Agentic Security Means for You

Existing Proofpoint customers get the best of this launch. The collaboration system arrives as a Q1 2027 in-place update, and the core Nexus detection engine ships within existing entitlements, per the company’s blog. Put both commitments into renewal paperwork now. Plan the browser piece as a change-management exercise too. Push deploys as an extension on users’ existing browsers, lighter than an enterprise-browser swap but still touching every endpoint.

CISOs with AI agents in production should read this as confirmation. Agent governance is consolidating into platform offerings from Netskope, Palo Alto Networks, Microsoft, and Proofpoint, and your 2027 budget conversation will compare all four. Start now by inventorying your agents and drafting the business-intent rules you want enforced. That work is vendor-independent, and it will surface your real requirements.

Microsoft-first organizations should demand measurement, not positioning. Ask Proofpoint for catch-rate deltas measured on your own tenant, seeded with real business-email-compromise and vendor-fraud samples. Nothing here has shipped yet, so the leverage is yours. Whichever vendor first publishes independent effectiveness data on runtime agent controls will separate itself from the Proofpoint agentic security pack — and from everyone else’s agentic branding.

Proofpoint Agentic Security: Two Launches, One Knowledge Graph, and Questions Left Open

Editor’s Note

This article draws on Proofpoint‘s September 22, 2026 press releases and Protect 2026 launch blogs, public announcements from Netskope, Palo Alto Networks, Microsoft, Abnormal Security, and Push Security, and reporting from CRN, CSO Online, and Calcalist. Survey statistics come from Proofpoint’s own 2026 AI and Human Risk Landscape report. Capability descriptions, availability dates, customer counts, and “first” claims are company-reported and not independently verified. No product was tested hands-on.