...

Box Launches New Controls to Secure AI Agents Operating Across Enterprise Content

Box

Box, Inc. introduced advanced security capabilities today to govern AI Agents operating across cloud content. The Intelligent Content Management platform designed these controls to secure AI Agents within native and third-party systems. Organizations can now extend protection to popular models like Claude, ChatGPT, and Gemini. Consequently, enterprises can safely deploy AI Agents while maintaining visibility over sensitive business data.

“83 percent of organizations are already experimenting with AI agents across their most critical tasks,” said Manoj Asnani, VP of AI Security, Privacy, Compliance & Governance Products at Box. “As these agentic workflows become more deeply embedded in the enterprise, it’s critical to create the proper security controls to ensure agents have what they need to function effectively, without accessing, modifying, or exposing content beyond the scope of its intended task. Box already provides a safe environment for organizations to apply AI to their most critical business knowledge, and with these new controls, we are creating a standard for deploying agents of any kind securely and at scale.”

“As we rapidly advance our utilization of AI agents, we expect Box which has consistently led the development of security management capabilities for secure collaboration to provide the administrative features needed to safely leverage this new era of AI,” said Tatsutoshi Murata, Head of IT Strategy Department at Nomura Research Institute. “In particular, we’ve found it extremely reassuring that Box offers multi-vendor support, allowing us to flexibly switch between AI models, while providing security management capabilities that span prevention, detection, and response. With a protective layer that appropriately manages AI agent access to content, we’re confident our critical content will remain protected as we expand our use of AI.”

Enterprise Guardrails and Multi-Industry Security Capabilities

Importantly, administrators can deploy these native tools immediately without adding extra software layers. The platform embeds protection directly into the content layer. Specifically, administrators can set agent guardrails to enforce label-based access and restrict unauthorized external sharing. The system also inspects every input through prompt injection detection to block malicious commands before execution.

Furthermore, IT teams can govern external connections using Model Context Protocol (MCP) server guardrails. Classification-based access policies prevent AI Agents from accessing sensitive files. Additionally, the platform provides real-time oversight through threshold-based alerts and compliance-ready audit trails. Human-in-the-loop controls ensure human approval for high-impact actions.

“As organizations rapidly adopt agentic AI, securing the content layer becomes the critical foundation for deployment,” said Amy Machado, Senior Research Director, Content and Knowledge Management Strategies, IDC. “Box’s new security and governance controls address the primary barriers of privacy and unauthorized access directly where the data lives. By embedding guardrails, prompt injection detection, and human-in-the-loop oversight into the platform, Box is establishing a vital trust standard that allows enterprises to confidently scale both native and third-party AI agents across their most sensitive content.”

These comprehensive safeguards empower regulated sectors to deploy AI Agents at scale. For example, financial services firms protect proprietary M&A analysis and trading data. Similarly, healthcare organizations secure patient records while building complete audit trails. Law firms manage contract workflows securely, and insurance providers validate claims inputs seamlessly. Ultimately, these unified capabilities enable organizations to deploy AI Agents safely across complex cloud environments. 

 For related updates on digital trust and cybersecurity, explore our SOC News.

Source: Businesswire