Intent-Based Defense: How Security Teams Are Learning to Govern AI Agents
At Proofpoint Protect, security leaders outlined a shift from blocking AI deployments to enabling them safely, with intent-based models and knowledge graphs emerging as the foundation for controlling both human and machine actors in the enterprise.

The conversation at this week's Proofpoint Protect event has moved past whether large organizations will deploy AI agents to the harder question of how to manage them once they are running. Attackers are leveraging AI to craft convincing phishing messages and execute attack chains at speeds no human can match. Inside enterprises, the AI agents that companies deploy function as privileged insiders—they have entry to sensitive data, critical systems and employee inboxes.
The coming era of AI security will turn on understanding intent. Security teams are constructing knowledge graphs and intent-focused frameworks that can distinguish between legitimate actions by humans and agents versus malicious ones. Governance rules that were once written as policy documents are being transformed into automated, real-time enforcement mechanisms. The urgency has intensified as research labs move faster: Anthropic PBC has broadened Project Glasswing to distribute its Mythos Preview model, designed to find vulnerabilities, to a wider circle of defenders.
The large enterprises that are competing, they look at the transformation edge that they're trying to get as the competitive edge. So their game is speed. They know that if they can beat the competition with better products and better outcomes, they win. Now, the risk is the security piece.
John Furrier, executive analyst for theCUBE Research
Executives and researchers from Proofpoint Inc. and Anthropic discussed these challenges with Furrier at the San Diego event, with coverage provided by theCUBE + NYSE Wired. The discussions touched on threats posed by agents, knowledge graph architecture, the consolidation of security platforms and the dual nature of AI agents as both opportunity and risk.
Eight Key Takeaways
1. Security teams shift from blocking AI to enabling safer adoption.
Organizations are embracing agentic AI with measured confidence, and security teams face pressure to move away from blocking initiatives and toward facilitating responsible AI rollouts. The ability to determine what an agent or person actually intends to do has become paramount, since an agent pursuing a given objective can optimize itself into performing something entirely different, according to Molly McLain Sterling, senior director of cybersecurity strategy at Proofpoint.
2. Intent becomes the foundation for two new agentic security systems.
Proofpoint unveiled two fresh agentic systems designed for collaboration security and data and AI security, each anchored in a knowledge graph that documents interactions between people and AI and their data access patterns. Since enterprises cannot realistically patch all vulnerabilities, they require alternative safeguards that assess the intent behind every action by humans and agents, explained Sumit Dhawan, chief executive officer of Proofpoint.
3. Tiered intent models target attacks that appear legitimate.
Threat actors are increasingly compromising legitimate vendor communications without deploying malicious code, prompting Proofpoint to add intent-based models to its Nexus detection suite operating across Flash, Extended-Thinking and Deep-Thinking tiers. A new Community Hyperloop mechanism distributes each detection discovery to all customers at machine speed, noted Tom Corn, executive vice president and general manager of the Threat Protection Group at Proofpoint.
4. AI agents emerge as insider risks concentrated on enterprise endpoints.
Roughly 99% of agentic activity tracked by Proofpoint operates on standard endpoints rather than cloud infrastructure, making its network of tens of millions of endpoint sensors critical to agent defense. Policies originally designed for human users must be converted into real-time controls that agents can interpret and follow, emphasized Ryan Kalember, chief strategy officer of Proofpoint.
5. Anthropic urges enterprises to engineer for trust before scaling agents.
Anthropic has delayed the general availability of its Mythos Preview model to construct safeguards and prioritize access for defenders, recognizing that emerging models can combine minor vulnerabilities into critical exploits. Organizations should establish written policies, implement sandboxing and monitoring capabilities, and begin with limited deployments where the potential damage is clear and contained, advised Robert Bair, head of national security partnerships at Anthropic.
6. Proofpoint nears $2.5B in annual recurring revenue as customers consolidate.
Proofpoint's annual recurring revenue stands near $2.5 billion and is expanding at close to 20%, a figure that includes Hornetsecurity following its acquisition. The company has doubled in size since Thoma Bravo LP acquired it and took it private in 2021. Security leaders are consolidating their vendor portfolios to redirect spending toward AI capabilities, with one Canadian bank exemplifying the trend by replacing four separate suppliers through a $25 million, five-year agreement, shared Remi Thomas, chief financial officer of Proofpoint.
7. AI divides cyberattackers into increasingly skilled and sloppy camps.
Sophisticated threat actors are using AI to accelerate malware creation and translate phishing content into as many as 16 languages, while less capable attackers are becoming more careless. Traditional signature-based detection methods are losing effectiveness too rapidly, so defenders must develop adaptive detection approaches that predict attacker behavior, highlighted Selena Larson, principal threat researcher at Proofpoint.
8. Knowledge graphs become the control layer for human and AI access.
As both humans and AI agents gain direct access to enterprise data, organizations require visibility into the reasons behind each access request and the permissions each actor should possess. Proofpoint is constructing a knowledge graph that links actors, their actions and data assets, forming a contextual foundation for governance, detection and response as AI systems run continuously, according to Mayank "MC" Choudhary, EVP and GM of the Data Security and Governance Group at Proofpoint.