Inside Proofpoint Protect 26: How Agentic AI Is Rewriting Data and AI Security

Proofpoint's Protect 26 conference made one thing clear: the era of static, rule based data protection is ending, and agentic AI is stepping in to fill the gaps that manual controls and human analysts simply can't keep up with anymore. Here's a breakdown of what stood out most from the sessions and keynotes I attended.

One of the speakers had a fascinating thought experiment centered around the Bill Murray classic movie Groundhog Day, theorizing that Bill Murray repeated that day at least 7,000 times. That number accounts for the time needed to master jazz piano, French poetry, chainsaw ice sculpting among others, while also getting to know nearly every single resident in Punxsutawney, Pennsylvania. The speaker brought the story back around by explaining that AI agents could create the same results for us, without having to run the risk of going crazy enough to let a groundhog drive us off a cliff. Thousands of agents, running defined tasks daily, can create years' worth of value each day, if organized correctly. 

The New Stack: Agentic Data & AI Security System

The centerpiece of the event was Proofpoint's reframed platform architecture, which now sits on a layered "Agentic Data & AI Security System." At the base are Sensors (Email, Endpoint, API, Browser, MCP, and Inference Hooks) feeding into the Proofpoint Knowledge Graph. On top of that sit the Nexus Models, which now include both Intent Models and Access Models, and above those sit the new Agentic Capabilities layer: Zero Touch Detection, Instant Investigation, and Optimize Protection. The top layer is where it all surfaces for customers: AI Run Time Protection, Insider Risk, Data Loss Prevention, and DSPM.

The addition of Intent Models to the Nexus lineup stood out. The Knowledge Graph is no longer just correlating data movement and user activity, it's now fusing that with intent signals, which is the foundation that makes a lot of the agentic claims below actually plausible rather than just marketing language.

Zero Touch Detection and Optimize Protection

Two of the new Agentic Capabilities got their own dedicated deep dives:

Zero Touch Detection is built to detect known and unknown risks while eliminating manual controls entirely, with the pitch being increased detection confidence without an analyst having to hand tune rules.

Optimize Protection focuses on right sizing: right sizing controls, right sizing data access, and continuous learning that adjusts protections over time rather than leaving them static. This is where the "set it and forget it" promise of agentic security starts to feel real.

Proofpoint User Risk Agents: Purple Teaming for Humans

This was, for me, the most interesting idea of the whole conference, and it's a genuinely different way of thinking about human risk.

Proofpoint is introducing a paired set of user risk agents that work in a continuous feedback loop with each other, a true purple teaming approach: red and blue working together as a single, ongoing system rather than two separate exercises. On one side is a Blue Team agent, whose job is to profile individual users over time and use that profile to coach them, nudging behavior, flagging risky habits, and reinforcing good ones as they show up in real activity. On the other side is a Red Team agent, whose job is to profile the same users specifically to find ways to exploit them, generating realistic, personalized synthetic attacks aimed at their actual behavior patterns rather than generic phishing templates.

The key detail is that these two agents aren't running in isolation. The Red Team agent's results feed directly back into the Blue Team agent. So when the Red Team agent finds a new way to trick a specific user, that outcome becomes training signal for the Blue Team agent, which then adjusts its coaching for that person. Over time this creates a closed loop: attack, learn, coach, repeat. Instead of a once a year phishing simulation and a static training module, you get an ongoing purple team relationship between two agents that are constantly probing and constantly adapting, with the human user as the one actually getting sharper as a result.

It's a genuinely novel approach to the human risk problem, and it also raises fair questions about how synthetic, personalized attack generation gets governed responsibly, even when the intent is protective.

DSPM Continues to Mature

DSPM also got some attention this year, mostly incremental improvements rather than a big reveal. The framework still breaks down into Discover, Classify, and Remediate Access, and the newer additions were Adaptive Classifiers for the classify stage and expanded remediation coverage for on prem systems and Agent Access Revocation.

There was also a preview of a related capability, Data Security Posture and Access Governance, expected in Q4 2026, which adds autonomous access remediation, adaptive classification trained on your own business context, and governance that unifies humans, non human identities, and agents into a single access model. A big piece of news about the future of DSPM at Proofpoint wouldn't be expanded on, but the news cycle should keep us all interested in the exciting possibilities there. 

AI Run Time Protection: Treating Agents as Insiders

The AI Run Time Protection session was built around three pillars: Discover & Observe every AI model, actor, and action (including skills, plugins, and MCP tools, now extending to any AI gateway), Protect with intelligent models enforcing in real time via new Semantic Risk Policies, and Investigate, which treats agents explicitly as insiders, applying agentic investigation and agentic insights to all run time risks.

The detail that stuck with me most was that Proofpoint is now consuming inference hooks to understand intent at the model level. That's a meaningful shift. It's not just watching what data moves, but trying to infer why an AI action is happening in the first place.

A Few Other Noteworthy Notables 

A handful of other items from the presentations that are worth calling out:

  • Push Security's browser plugin is now fully integrated for post click phishing protection, closing a gap that traditional email gateway filtering never could, since it catches credential theft after a user has already clicked through.
  • Browser protection capabilities are expanding more broadly, reinforcing the idea that the browser is becoming as important a sensor as email or endpoint.
  • Collaboration protection deserves to be its own category within email security rather than a sub feature. As more sensitive communication moves into Slack, Teams, and similar tools, lumping it under "email" undersells the exposure.

The Takeaway

If there's a single thread running through Protect 26, it's that Proofpoint is trying to close the loop between detecting risk and acting on it, without a human in the middle for every step. The purple teaming approach behind the user risk agents is the clearest example of that philosophy applied to people rather than systems: continuous attack, continuous learning, continuous coaching. Combined with intent models, inference hooks, and non-human identity governance, the direction is unmistakable. Proofpoint is treating AI agents as first class citizens in the security model, both as things to protect against and things to protect with.

Technologies