Box adds security controls to govern AI agents working with enterprise content

Box adds security controls to govern AI agents working with enterprise content

Box adds security controls to govern AI agents working with enterprise content Box Inc. today introduced security controls aimed at the artificial intelligence agents now working across enterprise content. The controls apply to agents built in Box and to outside tools connected to it, including Anthropic PBC’s Claude, OpenAI Group PBC’s ChatGPT and Google LLC’s Gemini. Rather than run as a separate product, the controls sit at the content layer, where the files already are. Box said that lets it vet and record each agent action, then block anything that falls outside set permissions. The company is aiming the release at customers that want to move agent use beyond small pilots into production. The push targets a barrier Box’s own research flags as the main obstacle to agentic AI. In the company’s 2026 State of Enterprise AI report, 90% of information technology leaders surveyed named security, regulatory and trust concerns as the biggest reason they hesitate to give AI agents access to enterprise content. Among the new capabilities are agent guardrails that limit what custom Box agents can do based on content sensitivity, including label-based access controls, required approval for deletion actions and disabled external sharing. Prompt injection detection screens every input before it reaches a model and can log, alert on or block suspicious attempts. A separate set of Model Context Protocol guardrails governs external agents connected through the Box MCP Server, letting administrators scope permissions such as allowing file creation only in approved folders. The release bundles several more controls. Classification-based access policies can wall off tagged content so agents cannot read or search it. Activity oversight sets threshold alerts on outside agent behavior, and audit trails keep compliance-ready records of each session. A human-in-the-loop setting holds high-impact actions for sign-off. Manoj Asnani, vice president of AI security, privacy, compliance and governance products at Box, said the controls are meant to ensure agents can function without accessing, modifying or exposing content beyond the scope of their task. He said 83% of organizations are already experimenting with AI agents on their most critical work. Box pointed to regulated industries as early beneficiaries, citing financial services firms guarding merger analysis and trade information, healthcare organizations securing patient data and law firms governing AI across contract and discovery workflows. The capabilities build on a security push that dates to the 2019 launch of Box Shield and the debut of Box Shield Pro late last year, which brought agentic AI to content classification and threat detection. “Box’s new security and governance controls address the primary barriers of privacy and unauthorized access directly where the data lives,” said Amy Machado, senior research director for content and knowledge management strategies at International Data Corp. “Box is establishing a vital trust standard that allows enterprises to confidently scale both native and third-party AI agents across their most sensitive content.” Box said the new controls will roll out to customers on its Enterprise Advanced plan in the coming months. Image: Box A message from John Furrier, co-founder of SiliconANGLE: Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities. 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network. Are you AWS customer? Support SiliconANGLE Financially by buying your AWS services from our Marketplace portal page and links. About SiliconANGLE Media SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI. Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.

Original Source

Read the full article at Siliconangle →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.