ai security for agents

Forcepoint is recasting its Data Security Cloud as an AI native control plane for governing autonomous agents and shadow AI, tying deep data protection to granular oversight of AI usage across the enterprise. For security teams, this brings the promise of a single platform that can discover sensitive data, understand AI risk, and enforce guardrails in real time instead of relying on disconnected tools.

Why this development matters right now

The timing of Forcepoint AI Data Security is not an accident. Generative models, copilots, and autonomous agents have moved from experiments to everyday work tools in only a few years, often faster than corporate governance structures can keep up. Shadow AI is already embedded in web traffic, personal accounts, and sanctioned software suites, creating routes for sensitive information to leak into external models without formal approval or oversight.

AI has leapt into everyday work, while shadow tools quietly erode data control and oversight.

Regulators are turning more attention to AI usage, not just to model providers but to enterprises that feed proprietary data into these systems. At the same time, boards are pushing hard to capture productivity gains from AI. That combination creates a simple but hard question for CISOs and data leaders: How do you let the business use AI aggressively without losing control of your data? Forcepoint is positioning its AI native Data Security Cloud and AI Data Security launch as a direct answer to that problem, with a focus on visibility, governance, and protection across agents, sanctioned AI, and shadow tools.

From traditional data protection to AI era risk

Forcepoint has been in the data protection and secure access world for years, originally through classic enterprise data loss prevention engines and secure web gateways. Over time, the company expanded into unified data security that spans endpoints, cloud managed email, software as a service applications, private apps, and custom web properties.

In 2024, Forcepoint introduced its One Data Security offering, a cloud managed platform designed to simplify policy management with a zero trust orientation and AI assisted classification of sensitive data. Those early moves focused on consolidating scattered tools under one policy framework and using AI to reduce false positives and speed up compliance work.

In 2025, the company formally unveiled Data Security Cloud, describing it as a complete AI powered platform that unites visibility and control of data wherever it is created, stored, or moved. That platform brought together data security posture management, data detection and response, enterprise data loss prevention, software as a service security, web security, and email security, all driven by an AI Mesh layer intended to give a unified understanding of risk and data context.

The most recent evolution is explicitly framed around AI usage itself. Forcepoint now brands its offering as the number one AI data security platform and has launched AI Data Security as a cloud service that integrates oversight with protection across autonomous agents, sanctioned AI, and shadow AI. This marks a shift from securing data in general toward securing data as it flows through AI systems specifically.

Inside the AI native Data Security Cloud

At the core of Forcepoint AI Data Security is the Data Security Cloud architecture, which is designed as a cloud native platform for modern distributed workforces and agentic environments. The architecture merges several control planes into one view. Forcepoint describes this as Self-Aware Data Security, where policies and risk scoring adapt dynamically as threats and AI-driven workflows evolve.

Data Security Cloud pulls in capabilities such as data security posture management, data detection and response, enterprise data loss prevention, web and email security, cloud app security, and collaboration protection. It uses an AI Mesh technology layer to continuously discover and classify both structured and unstructured data across cloud applications, collaboration platforms, and modern data lakehouses.

Telemetry from endpoints, networks, software as a service apps, and private applications is consolidated to show where sensitive data lives, how it moves, and how AI tools are touching it. That data feeds risk adaptive controls that adjust enforcement dynamically as user behavior and context change. The idea is that policy is applied to the data itself, then enforced consistently across prompts, agents, integrations, and more traditional channels such as email and web traffic.

The platform continues to rely on Forcepoint enterprise data loss prevention to conduct deep content inspection and contextual analysis, monitoring and blocking unauthorized movement of sensitive information across email, web, and cloud channels. This older strength is effectively repurposed for the AI era, giving the platform the ability to analyze prompts and outputs in line as they travel to public and third party AI systems.

Governing agents, copilots, and shadow AI

One of the clearest themes in Forcepoint messaging is that the platform is designed to govern autonomous agents and contain shadow AI before it leads to unmonitored data exposure or compliance failures. The platform aims to distinguish sanctioned AI services from unsanctioned tools, making that distinction visible across web usage and cloud applications.

Forcepoint describes a discovery and visibility layer where web security identifies AI tool usage across all web traffic, including usage through personal accounts and encrypted sessions, while cloud app security surfaces AI features embedded inside approved platforms that were activated without IT awareness. That inventory is a prerequisite for any meaningful enforcement because policy cannot be applied to tools that remain invisible.

Once these services and features are identified, centralized policies can govern prompts, responses, and data flows to public and third party AI systems. Inline inspection of prompts and outputs, combined with AI powered discovery and classification, allows the platform to identify when sensitive information is at risk of being shared with external endpoints, whether those endpoints are large language models, copilots inside office suites, or autonomous agents interacting with business systems.

Recent descriptions of the AI Data Security cloud emphasize that it spans autonomous agents, sanctioned AI, and shadow AI, covering the full arc from discovery and classification to control, guardrails, and governance. That scope matters because many organizations are starting to experiment with internal agents that orchestrate actions across systems, which can create high value attack paths or accidental data leakage routes if those agents are not constrained.

ARIA and the intelligence layer

A major part of Forcepoint’s story is ARIA, the Adaptive Risk Intelligence Assistant embedded into Data Security Cloud. ARIA is positioned as an always-on AI expert that understands the Forcepoint platform in depth and has awareness of the organization’s data landscape.

Practically, ARIA is meant to help security teams translate business intent into enforceable protection using natural language in seconds. Instead of manually building complex policies across multiple consoles, administrators can describe objectives such as preventing source code from leaving the company through any AI tool or ensuring that regulated personal data is never sent to public models. ARIA then generates policy recommendations and explains them for review.

ARIA also draws information from across Data Security Cloud to correlate cross-solution risk signals and behavioral insights, spotting security gaps as new AI products, such as copilots, are adopted without matching controls. It can flag coverage gaps, suggest new policies, and help propagate those changes consistently across endpoints, cloud services, and collaboration tools from a single interface.

Underneath ARIA is the AI Mesh layer that discovers and classifies billions of structured and unstructured data elements, providing the raw understanding needed for meaningful risk scoring and adaptive protection. Together, ARIA and AI Mesh form the intelligence fabric of the platform, trying to lift security teams out of rule tinkering and into higher-level decision making.

Implications for technology, businesses, and society

For technology teams, the emergence of platforms like Forcepoint AI Data Security signals a shift from simple data loss prevention toward full lifecycle data security tailored for AI-heavy environments. By unifying posture management, detection, prevention, and governance for AI-related flows, these systems aim to reduce the fragmentation that has plagued security operations, where different teams owned separate tools for cloud, endpoint, and application security.

From a business perspective, this kind of platform can make aggressive AI adoption more politically and operationally acceptable. Executives can argue that they are not simply opening the doors to agents and copilots but doing so with guardrails that follow sensitive data wherever it moves. In highly regulated industries, this could be the difference between using public models only in narrow pilots and deploying them more broadly with confidence that regulatory obligations remain intact.

Societally, the move to govern shadow AI and autonomous agents may temper some of the worst risks of uncontrolled model usage. If platforms can reliably detect when corporate or personal data is about to be fed to external models and can block or mask it, that reduces the chance that proprietary information quietly becomes part of someone else’s training set. However, the same controls can raise concerns about employee privacy and increased monitoring of day-to-day work. As security telemetry gets richer and AI analysis more powerful, organizations will need clear policies and communication to maintain trust.

There is also an ecosystem implication. If AI native security platforms become the norm, model providers and application vendors may be pushed to expose more granular controls and telemetry interfaces so that enterprise security systems can effectively govern them. That could accelerate standardization in areas like prompt logging, output tagging, and model endpoint configuration, which are currently fragmented.

Opportunities and risks in Forcepoint approach

Forcepoint’s strategy offers several clear opportunities. The combination of AI Mesh, ARIA, and classic data loss prevention gives a layered view of risk that spans data at rest, in use, and in motion across on-premises and cloud environments. The focus on AI usage, including shadow AI, is timely and grounded in observable behavior across web and software as a service traffic.

The consolidation of controls into a single cloud platform helps reduce the management overhead that has hampered many security teams. By providing unified policy enforcement across endpoints, networks, cloud applications, and private apps, the platform aims to simplify compliance reporting and incident response.

At the same time, several risks and open questions remain. First, Forcepoint is one vendor among many trying to define AI security and data governance. Claims of being the leading or number one platform are marketing statements and should be evaluated against real deployments, independent assessments, and customer outcomes.

Second, the effectiveness of AI Mesh and ARIA depends heavily on training quality, data coverage, and the ability to minimize false positives and false negatives. Overly aggressive controls can frustrate users and push them to bypass systems, while lax controls can leave gaps that give a false sense of security.

There are also interoperability considerations. As organizations adopt multiple AI platforms, including private models, cloud provider services, and specialized agents, the Data Security Cloud must keep pace with new endpoints and interaction patterns. Forcepoint’s messaging indicates ongoing updates and partner programs, but long-term success will depend on sustained integration work with a broad range of AI ecosystems.

Finally, as more decision-making is delegated to embedded assistants like ARIA, governance over the assistant itself becomes important. Security teams will need clear ways to audit ARIA recommendations, understand why certain policies were proposed, and verify that automated changes do not conflict with business requirements or legal obligations. Forcepoint says ARIA provides explanations for administrators, which is a step in the right direction, but mature oversight frameworks will still be required.

Key takeaways and forward-looking insights

Forcepoint AI Data Security illustrates how quickly the security world is adapting to the realities of agentic computing and pervasive AI tools. The company has evolved from traditional data loss prevention into a cloud native platform that unifies data discovery, classification, protection, and AI governance under one intelligence layer.

Three practical takeaways stand out.

First, AI usage is now a primary design point for data security architecture, not an afterthought. Governing prompts, outputs, and agent workflows is becoming as important as governing file transfers and email attachments.

Second, discovery and visibility are non-negotiable. Shadow AI is real, and without an inventory of tools and embedded features, policy cannot be meaningfully enforced.

Third, human security teams will increasingly work alongside embedded AI assistants that help translate business goals into technical controls. That promises faster response and more coherent policy, but it also requires new habits of oversight and validation.

Looking ahead, platforms like Forcepoint Data Security Cloud are likely to influence not just how enterprises secure their data but how they design AI-enabled workflows. If guardrails and governance can be expressed early in the design of agents and copilots, organizations may move toward architectures where security and productivity are co-designed rather than bolted on afterward. The details will matter, and no single vendor will have all the answers, but the direction is clear. AI is now a first-class security concern, and the platforms that can offer trustworthy control over data in this new environment will shape how confidently businesses can embrace the next wave of AI adoption.

Conclusion

AI agents are moving from pilots into everyday workflows, often faster than security teams can keep up. That acceleration is creating a stark gap between how enterprises protect data and how employees and software agents actually use AI tools in practice, especially in the shadow AI that never passes through formal approval channels. Against that backdrop, Forcepoint’s new AI Data Security platform is an attempt to turn AI adoption from a loosely governed experiment into a disciplined, auditable operational layer that treats every AI interaction as a data security event.

Why AI data security is under pressure

Over the past three years, generative AI has shifted from isolated experiments to embedded features inside mainstream business applications and standalone autonomous agents that can act on behalf of users. AI capabilities now sit in customer relationship systems, productivity suites, developer tools and data platforms, often enabled by product updates rather than deliberate enterprise planning.

At the same time, employees are routinely connecting to public AI services with personal accounts, pasting in sensitive content and using browser extensions and plug ins that never went through procurement or security review. Forcepoint and other security vendors describe this as shadow AI, an extension of the long standing shadow information technology pattern where workers adopt unsanctioned tools to get their jobs done faster. The result is a widening gap between traditional data protection policies and the real world flow of sensitive information through prompts, agent actions and AI generated outputs.

Traditional controls such as endpoint protection, web gateways and classic data loss prevention were designed for email attachments, files and network flows rather than conversational prompts and autonomous agents operating at machine speed. Even organizations that invested heavily in data security posture management or cloud access security brokers often find that AI usage cuts across those boundaries and introduces new routes for data to leave the organization.

From perimeter security to data centric AI governance

Forcepoint has been pushing a data centric view of security for several years, culminating in its Data Security Cloud platform that unites discovery, classification, posture management, data loss prevention, web and email controls under a single policy framework. That platform is built around AI Mesh, a classification engine that discovers and labels structured and unstructured data across clouds, software as a service applications, endpoints, email, networks and now AI workflows.

The AI Data Security launch builds directly on that foundation. Rather than treating AI as a bolt on feature, Forcepoint is extending the same unified data policies that already govern channels such as email, web and endpoints to the new domain of AI prompts, agents and integrations. The idea is to apply policy to the data itself and then enforce that policy wherever the data appears, whether that is inside a prompt, a file being summarized or a record being accessed by an autonomous agent.

This approach reflects an evolution in enterprise security strategy. Early AI security efforts focused primarily on visibility, such as inventorying which AI tools were in use or blocking specific domains. Forcepoint’s new platform tries to go further by combining that visibility with enforcement that adapts automatically as risk changes, using contextual intelligence tied directly to the sensitivity of data and user behavior.

Inside the Forcepoint AI Data Security platform

Forcepoint positions AI Data Security as a cloud platform that tracks sensitive information across autonomous agents, sanctioned AI applications and shadow AI, all governed through a single control plane. At its core are several capability layers that map closely to how AI is actually adopted inside organizations.

  1. AI security visibility and governance. The platform provides visibility into every agent running in the environment and ties activity back to a specific person, agent or a combination, through identity attribution. This makes it possible to answer basic questions that many enterprises still struggle with today, such as which agents are active, what systems they touch and who ultimately owns their actions.
  2. AI agent gateway. Instead of allowing agents to hold direct credentials to systems such as customer relationship tools, collaboration suites or issue trackers, Forcepoint inserts a gateway that enforces least privilege access at the level of individual fields. The aim is to let agents perform useful tasks while narrowing the windows where they can see regulated information such as payment card data or patient records.
  3. Real time prompt and response control. The platform inspects prompts and AI generated responses inline, looking for sensitive information and applying policy before data leaves the enterprise or before an AI output reveals more than it should. Combined with data loss prevention for AI workflows, this control is intended to block leakage of regulated data such as personal information or financial details when employees interact with AI tools.
  4. Confidential file protection and tagging. Forcepoint extends its tagging capabilities to confidential files, allowing organizations to mark intellectual property and sensitive documents so that they can be excluded from AI summarization or analysis, even if a user tries to upload them. The platform supports tagging across sources such as productivity suites and data platforms including Google Workspace, Databricks and Snowflake, aligning AI protection with existing data classification practices.
  5. Inline shadow AI controls. To address unsanctioned AI usage, the platform can allow or block AI applications based on policy, in line with web traffic and in near real time. It also distinguishes between corporate and personal tenants, permitting access through governed enterprise accounts while blocking personal account access that bypasses organizational controls.
  6. AI powered discovery and classification. As with the broader Data Security Cloud, AI Mesh supports continuous discovery and classification of sensitive data before it ever reaches an AI tool. This helps security teams prioritize risk hot spots and align AI guardrails with where their most valuable information actually resides, rather than treating all data as equal.

ARIA and the move to natural language governance

One of the most notable elements of Forcepoint’s strategy is ARIA, the Adaptive Risk Intelligence Assistant that acts as an embedded policy assistant across the Data Security Cloud platform. ARIA uses natural language to help security teams create, refine and enforce data protection policies that span traditional channels and AI driven workflows.

Instead of writing complex rules manually, administrators can describe the outcomes they want, such as preventing confidential design files from entering any public AI service or limiting which agents can access particular data stores. ARIA then analyzes activity across endpoints, cloud services and collaboration platforms and generates recommended policies, along with explanations that clarify why those policies matter.

This natural language layer is important because AI adoption itself is largely driven through conversational interfaces. Bringing policy management into that same mode can lower the barrier for overstretched security teams that now have to manage both traditional risks and AI specific threats. It also helps align AI governance with nontechnical stakeholders who need to understand and approve guardrails for their departments.

Governing autonomous agents and shadow AI in practice

Autonomous agents are often presented as the future of enterprise AI, capable of chaining tasks, making tool calls and operating without constant human supervision. That power comes with significant risk. An agent with broad access to customer data or proprietary models can inadvertently exfiltrate information or take actions that violate compliance obligations.

Forcepoint’s platform tackles this by treating every agent as a governed entity with explicit identity and permissions. The AI agent gateway mediates access to business applications, enforcing field level controls that can, for example, allow an agent to view a case status while restricting exposure to fields that contain payment card numbers or personal identifiers. Identity attribution ties the agent’s actions back to an accountable human owner and the specific agent configuration, which is critical for incident response and audit trails.

Shadow AI presents a different challenge. Users may connect to generative AI services with personal accounts from corporate devices or use browser based tools that tunnel through encrypted sessions not immediately visible to traditional security controls. Forcepoint leverages its web security and cloud application security capabilities to inventory AI usage, including tools accessed through personal accounts and embedded AI features that appear inside sanctioned software as a service platforms without clear disclosure. The AI Data Security platform then enforces policies inline, allowing or blocking unsanctioned AI tools and steering usage toward approved services that are under governance.

This combination of discovery, classification, control, guardrails and governance addresses the full arc of AI data security from knowing where data lives to managing how each AI interaction touches that data.

Business impact and early metrics

Forcepoint and its partners frame AI Data Security as a cost and complexity reducer as much as a risk management tool. Independent coverage of the launch notes claims that existing customers can cut data security policy management workloads by up to ninety percent and reduce operating costs by thirty one percent when they extend protection through the platform they already run. Those figures are based on the consolidation of multiple point products into a single data security cloud and the reuse of existing policies across new AI channels.

By unifying AI governance with established data protection tools, organizations can avoid building a separate security stack specifically for AI. Instead, they adjust policies that already govern email, web, endpoints and software as a service systems so those rules apply equally to AI prompts, responses and agent actions. That simplifies compliance reporting, because auditors and regulators can trace how a single set of policies protects data across traditional and AI driven workflows.

The platform is available through Forcepoint’s partner network, with advanced capabilities such as data detection and response for AI, the agentic AI gateway and expanded shadow AI controls rolling out over a defined quarter, which suggests a phased adoption path rather than an all or nothing shift. Existing Forcepoint customers can enable AI Data Security features inside their current deployments, which lowers the barrier to experimentation and allows teams to pilot controls with limited scopes before broad rollout.

How this compares with earlier approaches

Earlier AI security strategies often fell into one of two camps. Some organizations tried to lock down AI entirely, either by blocking access to public tools or prohibiting uploads of sensitive data without offering viable alternatives. Others took a largely permissive stance, relying on awareness training and policy documents with limited technical enforcement.

Forcepoint’s approach tries to thread the needle between these extremes. By positioning AI Data Security as part of a broader self aware data security vision that knows and protects sensitive information everywhere, the company is arguing that AI should be governed using the same principles that already apply to other channels, rather than as an isolated risk domain. AI Mesh and the single policy framework become the spine that connects all of these channels, letting organizations define data centric rules once and carry them across endpoints, web, email, software as a service and AI workflows.

Compared with traditional data loss prevention or standalone cloud access security broker tools, this design emphasizes adaptive controls that respond to context such as user behavior, data sensitivity and changing regulations. It also anticipates the agentic enterprise trend, where AI agents orchestrate complex tasks across multiple systems, by providing visibility and identity mapping specifically tailored to those agents.

Risks, limitations and open questions

Despite the promise, there are real questions enterprises should ask before committing to any unified AI security platform.

First, vendor dependence becomes more pronounced when so many controls are consolidated into a single cloud platform. Organizations adopting Forcepoint AI Data Security are betting that its classification engine, policy framework and agent gateway will keep pace with rapidly evolving AI models and tools over multiple years. If that evolution stalls or diverges from their needs, switching costs could be significant.

Second, adaptive AI powered controls introduce their own complexity. While AI driven classification and policy recommendations can reduce manual effort, they also create potential for misclassification, false positives and over blocking that frustrates users. Forcepoint’s emphasis on explanations through ARIA and identity based attribution helps mitigate this risk, but security teams will still need strong governance processes and human oversight to validate policies and handle exceptions.

Third, the shadow AI problem may be partially addressed but never fully eliminated. Even with inline web controls, tenant detection and software as a service inventory, determined users can sometimes route data through emerging tools or indirect channels that are difficult to monitor. Continuous tuning and collaboration between security, information technology and business units remain essential.

Finally, the regulatory landscape for AI is still settling. Data protection regulations already set expectations for how personal and regulated data must be handled, but forthcoming AI specific rules may require new documentation, transparency and control mechanisms. Platforms such as Forcepoint AI Data Security will need to adapt quickly to provide the audit trails and explainability that regulators and customers increasingly expect.

What this means for enterprises right now

For organizations that are serious about using AI in production, the launch of Forcepoint AI Data Security underscores a broader shift in thinking. AI is no longer something that can be governed with a few manual rules and user guidelines. It requires infrastructure that can see every prompt and agent action, understand the data involved and enforce guardrails consistently across channels.

In practical terms, enterprises should take several steps.

  1. Inventory current and planned AI usage across business units, including embedded AI features in existing tools and unsanctioned services employees are already using.
  2. Map that usage to sensitive data stores and workflows, identifying where autonomous agents or prompts touch regulated or high value information.
  3. Evaluate whether existing data security platforms can extend policies into AI interactions, or whether new capabilities such as agent gateways and inline prompt inspection are needed. Forcepoint’s offering is one example of how vendors are trying to meet that need with unified data centric controls.
  4. Establish clear accountability for AI agents, ensuring each has a defined owner, identity and permission set that fits within broader access management practices.
  5. Pilot shadow AI controls that differentiate between personal and corporate usage and guide employees toward approved AI services under governance, rather than relying solely on restriction.

The core takeaway is that AI governance and data security can no longer be treated as separate conversations. Platforms like Forcepoint AI Data Security are early attempts to fuse them into a single operational discipline, where every AI interaction is governed through consistent, auditable guardrails aligned with existing data protection strategies. Whether this specific implementation becomes the dominant pattern or not, the direction is clear. Enterprises that want to harness agentic workflows at scale will need security architectures that are as intelligent, adaptive and data aware as the AI systems they are deploying.

1 comment

Comments are closed.

You May Also Like

Scientists Believe AI Could Remove Forever Chemicals From Drinking Water Before They Harm Millions

In a race against “forever chemicals,” scientists say AI could scrub PFAS from drinking water—yet one crucial challenge still stands in the way.

White House Adviser Monitors OpenAI Agent Incident After Hugging Face Breach

Leading White House adviser tracks rogue OpenAI agent after the Hugging Face breach, as officials debate kill-switch powers and confront what happens next.

OpenAI Launches GPT-Red: How the New AI “Super-Hacker” Could Strengthen Cybersecurity

The AI “super-hacker” GPT-Red is reshaping cybersecurity with an 84% attack success rate—but its most surprising impact may be yet to come.

Google Gemini 3.1 Pro Found More Vulnerable to AI Jailbreak Attacks Than Claude and GPT

More vulnerable to AI jailbreaks than Claude and GPT, Gemini 3.1 Pro exposes hidden security gaps that could reshape how enterprises trust frontier models.