One theme stood out to me at Proofpoint Protect 2026. Artificial intelligence is changing the speed and scale of security, but it is not necessarily rewriting the attacker playbook.
Daniel Blackford, vice president of threat research, told me Proofpoint is still seeing many of the same telemetry signals and security problems despite attackers' growing use of AI.
Sarah Sabotka, staff threat researcher, pointed to another effect of attackers using AI.
Threat actors with legitimate technical skills can use AI to expand their capabilities. It can help them improve phishing campaigns, make translated content more convincing, and target victims across more geographic regions.
But those advantages do not necessarily make attackers more disciplined. Their operational security can still suffer, and AI can sometimes make them sloppy.
For defenders, the challenge is keeping up as AI allows attackers to move faster than security teams can investigate and respond.
Security needs to understand intent
During his keynote, Proofpoint CEO Sumit Dhawan repeatedly emphasized the concepts of "Defend with Intent" and "Access with Intent."
The idea is that traditional identity and behavioral controls may become less sufficient as AI agents gain access to enterprise data and applications.
Proofpoint's Agentic Data & AI Security System attempts to connect an agent's identity and access with its behavior and intent. The Proofpoint Knowledge Graph adds context about the data involved. This system also uses agents to detect and investigate threats, with remediation capabilities built into the process.
That was one of the most important themes I took away from the conference. Security architecture needs to move beyond asking, "Can this identity perform this action?" to asking, "Should this action be happening in this context?"
Proofpoint's Semantic Business Policies are designed around that idea. Organizations can define business rules in natural language. The platform then translates those requirements into runtime controls for employees and autonomous agents.
Intent-Based Access Control evaluates agent activity against those policies as actions occur. An AI agent may technically have permission to issue a refund, for example, while the organization's business policy requires approval before it can do so.
Threat detection is moving in the same direction
Proofpoint is applying intent beyond AI governance.
Its Agentic Collaboration Security System uses intent-based detection alongside autonomous investigation. The system also incorporates user-risk capabilities.
Compromised legitimate accounts can be difficult to distinguish from normal activity. An attacker could take over a supplier's mailbox and study months of correspondence before replying inside an existing thread. The resulting message may contain no malicious attachment or suspicious domain. It may not trigger an obvious behavioral anomaly either.
Proofpoint's Nexus Intent-Based Detection Model instead evaluates what a message is trying to accomplish and whether that objective makes sense in the context of the relationship. It also considers the techniques being used to achieve that objective.
Yaniv Miron, director of threat research, told me one TeamFiltration scenario could reach an organization's crown jewels in about 90 seconds without triggering account lockouts.
Miron also discussed indirect prompt injection. In one example, an attack used a Google Calendar invitation to deliver an indirect prompt-injection payload and later modified the invitation to remove traces of what had occurred. He described much of today's activity as experimentation but expects more indirect prompt-injection attacks in the wild in the coming months.
AI risk extends beyond cyberattacks
Another point that stood out came from Ryan Kalember, Proofpoint's chief strategy officer. He said much of the AI risk Proofpoint sees right now is not traditional cyber risk.
He described employees who feared AI could replace their jobs and repeatedly told an AI system that its answers were wrong in an effort to undermine it.
AI governance therefore has to account for risks beyond conventional security threats such as malware or data theft. Proofpoint says customers are also encountering fraud and prohibited uses of AI. Employee behavior introduces another concern, particularly when it creates regulatory or compliance issues.
Governance also starts with knowing where AI is being used. Organizations need visibility into the AI systems and agents operating in their environment and what those systems can access. They also need to understand which business processes rely on them.
Autonomy still needs measurable trust
The use of agents requires rethinking trust. I asked Daniel Rapp, Proofpoint's chief AI and data officer, how the company knows when to hand off trust from a human to an agent. He told me Proofpoint evaluates agents based on predictive and operational performance.
Proofpoint compares agents with humans using metrics such as unit time and false positives. The company also evaluates false negatives before moving security responsibilities toward autonomous systems.
That evaluation helps determine where automation makes sense rather than assuming a task should be automated simply because an agent can perform it. Proofpoint's architecture still supports human-on-the-loop monitoring, while consequential decisions can require human-in-the-loop approval.
My biggest takeaway from Protect 2026 is that AI security is becoming less about adding another security product and more about redesigning how organizations make security decisions. As agents gain greater access and attackers operate faster, identity and behavioral signals remain important, but they may no longer be enough.
The next phase of enterprise security will increasingly depend on understanding what an agent is trying to do and whether it makes sense in the current context.
Security teams will also need to determine whether the agent should have the access required to carry it out and whether the action is appropriate, even when the agent technically has permission to perform it.
That makes governing agentic AI an important part of determining how much autonomy organizations are willing to give these systems.





