Proofpoint Protect shifts security focus to intent as AI agents join workforce
At Proofpoint Protect in San Diego, Proofpoint and Anthropic executives said enterprises are moving from blocking AI agents to governing them, with intent-based models, knowledge graphs and new controls aimed at agentic threats.
Proofpoint introduced two new agentic systems for collaboration security and data and AI security, both built on a knowledge graph that tracks how people and AI communicate and access data. Chief Executive Officer Sumit Dhawan said no company can patch every vulnerability, so enterprises need compensating controls that judge the intent of every human and agent.
Molly McLain Sterling, senior director of cybersecurity strategy at Proofpoint, said customers are approaching agentic AI with cautious optimism and security teams are being pushed to stop blocking projects and start enabling safe AI use. Identifying the intent of an agent or a human is now the most critical step, she said, because an agent given a job can optimize its way into doing something else entirely.
Tom Corn, executive vice president and general manager of Proofpoint's Threat Protection Group, said attackers increasingly hijack legitimate supplier email threads without using malware. Proofpoint has added intent-based models to its Nexus detection suite that run in Flash, Extended-Thinking and Deep-Thinking tiers. A new Community Hyperloop spreads each new detection to every customer at machine speed, Corn said.
Ryan Kalember, chief strategy officer at Proofpoint, said about 99% of the agentic activity Proofpoint monitors runs on ordinary endpoints rather than in the cloud, making its tens of millions of endpoint sensors the foundation for agent security. Governance policies written for humans must be turned into real-time controls that agents can understand, he said.
Anthropic held back general release of its Mythos Preview model to build guardrails and get it to defenders first, because new models can chain low-severity vulnerabilities into serious exploits, said Robert Bair, head of national security partnerships at Anthropic. He advised companies to write policy, set up sandboxing and visibility, and start small with a clear view of the blast radius. Anthropic also expanded Project Glasswing to put its vulnerability-hunting Mythos Preview model in more defenders' hands.
Proofpoint's annual recurring revenue is close to $2.5 billion and growing nearly 20%, including Hornetsecurity, after doubling since Thoma Bravo LP took it private in 2021, Chief Financial Officer Remi Thomas said. Security chiefs are consolidating providers to free up budget for AI, including a Canadian bank that replaced four suppliers in a $25 million, five-year deal.
Selena Larson, principal threat researcher at Proofpoint, said AI divides cyberattackers into increasingly skilled and sloppy camps. Skilled threat actors use AI to speed up malware development and copy lures into as many as 16 languages, while low-end actors are getting sloppier. Static detections now lose their value quickly, so defenders must build dynamic ones that anticipate attackers' next moves, she said.
John Furrier, executive analyst for theCUBE Research, said large enterprises competing see the transformation edge they are trying to get as the competitive edge. 'They know that if they can beat the competition with better products and better outcomes, they win. Now, the risk is the security piece,' he said.