Ai
Jul 27, 2026


A new AI Data Security Platform argues that the fix for shadow AI and agent sprawl isn't tighter walls around AI, but protection that moves with the data itself.
[For more news, click here]
For two decades, enterprise security followed a simple rule: build the wall high enough, and the data inside it stays safe. Guard the network perimeter, sort access by department, and sensitive files would mostly stay where they belonged. That rule is breaking down inside almost every large organization right now, and a product launch this week from Forcepoint makes the case for what has to replace it. The Austin, Texas-based cybersecurity company has introduced an AI Data Security Platform, a cloud system built to merge two functions that have largely operated in separate departments with separate tools: protecting sensitive information, and overseeing the artificial intelligence systems that now handle it constantly.
The distinction is not a marketing nuance. It reflects a genuine structural problem that has been building since generative AI moved from novelty to daily workflow. Employees paste client records into chatbots. Autonomous agents pull financial data out of Salesforce, Microsoft 365 and Jira to complete tasks without a human in the loop. Once that information leaves its original system, protecting it and governing the AI that touched it become the same job, even though most companies still staff and budget them as two.
Seventy-nine percent of organizations report struggling to secure the information behind their AI initiatives, a gap Forcepoint's leadership points to as the reason data protection and AI oversight can no longer sit in separate silos. Legacy data loss prevention tools were built to watch files move across a network. They were not built to watch a prompt, a copilot response, or an autonomous agent's mid-task decision to summarize a confidential document. The AI Data Security Platform is Forcepoint's attempt to close that gap by extending the same protective architecture that already secures web traffic, email, endpoints and networks so that it also governs data once it enters an AI system, whether that deployment runs in the cloud or on-premises.
Rather than stopping at visibility, which is where most AI governance tools have historically stopped, the platform is designed to bind policy directly to the information itself and enforce it through every prompt, agent and integration, regardless of channel. Forcepoint frames this as a shift from telling security teams what is at risk to actively keeping that risk contained, adapting automatically as conditions change rather than relying on static rules that need constant manual updating.
Ryan Windham, Forcepoint's chief executive, described the shift in blunt terms.
“For 20 years, security meant keeping sensitive data away from risk. AI flips that,” said Ryan Windham, CEO of Forcepoint. “The data you most want to protect is the data that makes AI worth using. I’d urge every agentic enterprise to stop locking AI down and start securing it where the risk actually lives, in the data itself. Other approaches will only tell you what’s at risk. Forcepoint’s protection travels with your data into AI and proves it can be trusted there.”
The case for that approach is not coming only from Forcepoint's own executives. Roland Cloutier, a strategic security advisor who previously served as chief security officer at TikTok, ADP and EMC, argued that the platform addresses a defensibility problem that has been quietly building inside boardrooms.
“The hardest problem in enterprise security right now is ensuring that sensitive data stays protected once employees put it into AI, whether sanctioned or not,” Cloutier said.
“Forcepoint’s approach is notably different, because it moves past visibility to enforcement that follows the data itself, which is what defensibility to auditors and boards actually requires. Knowing where your data goes is table stakes now. Proving it stays protected is the job across the enterprise, inside and outside of security.”
In practice, the launch bundles several capabilities that previously existed as disconnected products. It gives security teams visibility into every AI agent running across the enterprise, tying each action back to a specific person, agent, or combination of the two, and it introduces an AI Agent Gateway that enforces least-privileged, field-level protection when autonomous agents reach into enterprise applications, preventing those agents from holding direct application credentials.
On the human side, the platform inspects prompts and AI-generated responses in real time, enforces data loss prevention policies specifically for AI workflows, and can identify and tag confidential files so they never make it into an AI-generated summary in the first place. It also gives companies a way to allow or block unsanctioned AI tools inline, and to distinguish between an employee logging into a governed corporate AI account versus a personal one, a distinction that has quietly become one of the more common sources of accidental data leakage.
A unified dashboard, built around what Forcepoint calls AI Detection and Response, is meant to bring all of that together, inspecting data as it flows through connectors to widely used AI systems including ChatGPT Enterprise, Microsoft Copilot, Claude Enterprise and AWS Bedrock. An embedded assistant called ARIA is designed to let non-specialist teams create and enforce AI policy using plain-English recommendations, while a companion reporting layer, Forcepoint Insights, is meant to generate board-ready summaries of risk trends and the users who most often trigger them. The discovery layer extends into unstructured and structured data sources such as Google Workspace, Databricks and Snowflake, identifying and tagging intellectual property and regulated data before it ever reaches an AI tool.
Forcepoint already counts thousands of organizations across financial services, healthcare, government and manufacturing as customers of its existing data protection architecture, and the company says extending that architecture into AI has reduced data security policy management workload by up to 90 percent for some customers, alongside a 31 percent drop in operating costs. Existing customers will be able to add the AI Data Security capabilities on top of the Forcepoint platform they already run, rather than adopting an entirely separate system, which is likely to matter to security leaders weighing whether AI governance requires yet another vendor relationship or simply an extension of the one they already trust.
The AI Agent Gateway and the shadow AI controls will roll out over the coming quarter, while the core platform is available immediately through Forcepoint's global partner network. The company plans to detail its approach further at Black Hat and at Forcepoint AWARE26 Fall, which is now open for pre-registration.
What makes the launch notable is less the feature list than the argument underneath it. As agentic AI adoption accelerates across regulated industries, the companies most eager to use their most sensitive data inside AI systems are the same ones least able to afford a leak. Forcepoint is wagering that the winning approach will not be the one that keeps AI furthest away from valuable data, but the one that lets that data move freely because protection has learned to move with it. If that thesis holds, the AI security category itself may end up looking less like a specialized add-on and more like a basic extension of data protection as enterprises have always practiced it, just finally caught up to where their data actually goes.
Uzbekistan Launches the Silk Road Finance & Technology Forum to Anchor Central Asia's FinTech Future
Infobip's Startup Tribe Turns Five, Freeing Founders From a Hidden Cost of Growth
Related Articles