Forcepoint has launched an AI Data Security platform designed to bring data protection, AI governance, and agent oversight into one control plane—a timely move as enterprises struggle to let employees use generative AI without turning prompts, file uploads, and autonomous workflows into new paths for data loss.
The company’s central proposition is straightforward: AI security cannot be treated as a separate visibility exercise bolted onto an existing security stack. Instead, the controls that identify, classify, and protect sensitive information must extend directly into AI interactions. That means governing approved services such as Microsoft Copilot, enterprise ChatGPT deployments, Claude Enterprise, and AWS Bedrock, while also discovering and containing unsanctioned “shadow AI” use and the growing population of autonomous agents.
For organizations built around Windows, Microsoft 365, Azure, Salesforce, Jira, and other mainstream enterprise platforms, the appeal is obvious. Employees increasingly encounter AI inside the same applications where business data already resides. The boundary between a document, a prompt, a cloud application, and an AI-driven action is becoming difficult to see—let alone secure.
Forcepoint’s new platform attempts to make that boundary enforceable again.

AI data security dashboard showing protected data flows, policy enforcement, AI destinations, and blocked shadow AI paths.Overview: AI Governance Meets Data Security​

Most early enterprise AI security programs focused on visibility. Security teams wanted to know which AI applications employees were using, how often they were accessed, and whether corporate data might be leaving approved systems.
That remains useful, but it is not sufficient.
A dashboard that reveals employees are pasting sensitive content into an unapproved AI service may help with investigation after the fact. It does little to stop a customer list, source-code fragment, financial forecast, health record, or regulated payment detail from being submitted in the first place.
Forcepoint AI Data Security is built around a stronger premise: data protection policies should follow sensitive information wherever AI processes it. Rather than treating an AI prompt as a special case that requires an entirely new security model, the platform extends traditional data loss prevention and classification controls to new AI channels.
This includes:
  • Employee prompts submitted to approved AI assistants
  • AI-generated responses that could contain sensitive information
  • File uploads used for summarization, drafting, analysis, or retrieval
  • Autonomous agents that access enterprise applications and data stores
  • Personal AI accounts accessed from managed corporate endpoints
  • Unapproved browser-based AI tools and AI-enabled applications
  • API-based AI integrations connecting enterprise data to models and services
The model is particularly relevant because AI has changed the speed and scale of data movement. A user who once needed to download spreadsheets, copy fields, and manually assemble a report can now ask an AI assistant to summarize a large body of information in seconds. An AI agent can potentially retrieve, transform, and act on business data across several enterprise systems without a human copying and pasting anything at all.
That productivity is the reason enterprises are adopting AI. It is also why conventional point controls increasingly appear inadequate.

The Data-First Security Argument​

Forcepoint’s approach centers on the idea that every AI prompt is a data transfer.
This framing matters because a prompt is not merely text typed into a chatbot. It may contain confidential project details, customer information, intellectual property, legal analysis, internal credentials, code, or data extracted from a protected document. An uploaded file may be even more significant, particularly when AI tools are being used to summarize large documents or answer questions across a collection of corporate content.
AI governance tools can identify the application in use. But Forcepoint is positioning its platform around a more granular question: what data is moving, who is moving it, where is it going, and what should happen at that point of transfer?
The company describes this as a policy framework that connects discovery, classification, control, guardrails, and governance. In practical terms, the workflow is intended to look like this:
  1. Discover sensitive data across enterprise environments.
  2. Classify that data according to its content, business context, and regulatory relevance.
  3. Identify AI applications, agents, integrations, users, and accounts interacting with it.
  4. Apply policy before the data is submitted, shared, summarized, or acted upon.
  5. Block, permit, restrict, warn, redact, or log the activity according to risk.
  6. Report and investigate the resulting activity through a unified console.
This matters because AI is not a single channel. A company may use Microsoft Copilot in Microsoft 365, a corporate ChatGPT environment for research, an Azure-hosted model for an internal application, and a collection of approved or unapproved third-party tools across departments. Meanwhile, users may access consumer accounts on those same services from managed devices.
A data-first approach has the potential to reduce fragmentation. If classification and DLP policy are already established for email, web traffic, endpoints, cloud services, and files, extending those policies into AI interactions can be more practical than starting a separate AI governance program from zero.
That is one of Forcepoint’s most compelling arguments: AI security should build on data security maturity rather than replace it.

What the New Forcepoint AI Data Security Platform Adds​

The announcement covers a broad feature set spanning AI visibility, DLP, cloud access controls, identity attribution, agent governance, classification, and executive reporting.

Visibility Across Approved AI, Shadow AI, and Agents​

Forcepoint says the platform can provide oversight for sanctioned AI services, shadow AI activity, and autonomous agents from a single environment.
This three-part distinction is important.
Sanctioned AI refers to applications formally approved and governed by the organization. These might include enterprise tenants of ChatGPT, Claude, Microsoft Copilot, or AI services connected through AWS Bedrock and other cloud platforms.
Shadow AI covers AI tools, browser extensions, services, personal accounts, and workflows that employees adopt outside formal approval. This category is often difficult to control because the service itself may be legitimate while the way it is being accessed violates company policy.
Autonomous agents present a different challenge. An agent is not just an employee entering a prompt. It can retrieve information, query systems, invoke APIs, generate content, trigger workflows, and perform actions with varying degrees of autonomy.
By bringing those categories together, Forcepoint is aiming to eliminate a common blind spot in AI governance: companies may monitor employee use of AI chatbots while missing the agents and integrations that can access far more data at machine speed.

AI Agent Gateway​

The AI Agent Gateway is arguably the platform’s most notable capability because it targets the emerging problem of agent identity and access.
Forcepoint describes the gateway as a way to enforce least-privileged, field-level data protection for agents accessing enterprise applications such as Salesforce, Microsoft 365, and Jira. The stated goal is to keep agents from retaining direct application credentials.
That is a significant architectural claim.
An agent that holds broad, persistent credentials can become a powerful route to data exposure. If it is misconfigured, manipulated through prompt injection, connected to an unsafe tool, or granted more permissions than necessary, it may retrieve or alter information far beyond the original purpose of the workflow.
A gateway model can help by placing a policy enforcement layer between the agent and the application. Rather than giving an agent unrestricted access to a CRM, collaboration platform, or project-management service, an organization could define more limited rights:
  • An HR assistant may retrieve approved employee-policy documents but not compensation fields.
  • A sales-support agent may access account names and product data but not payment details.
  • A service agent may search tickets but be prevented from exposing customer identifiers in responses.
  • A project agent may read designated workspaces in Microsoft 365 or Jira while being blocked from restricted legal or executive content.
  • An automation agent may perform an approved task without receiving reusable administrator credentials.
The value of this design depends heavily on how well the gateway integrates with identity platforms, SaaS permissions, APIs, and the agent frameworks enterprises actually use. Still, the focus on field-level protection reflects a more mature understanding of agentic AI risk than simple allow-or-block controls.

Real-Time Prompt and Response Inspection​

Forcepoint also emphasizes inline inspection of prompts, AI-generated responses, and file uploads.
For traditional DLP practitioners, this is familiar territory translated into a new workflow. Instead of inspecting email attachments or web uploads alone, the platform looks at the content being sent to and returned from AI tools.
The potential protections include stopping employees from submitting:
  • Personally identifiable information
  • Payment-card data
  • Healthcare and regulated records
  • Confidential financial details
  • Source code and development secrets
  • Trade secrets and unreleased product information
  • Sensitive customer or partner documents
  • Internal information protected by classification labels
Inspection of responses is also notable. AI-generated output can create risk even when a user did not directly upload a sensitive file. An assistant might summarize material retrieved through a connected enterprise system, reveal information from an overly broad data scope, or produce content that violates handling rules.
Response controls could help prevent sensitive material from being displayed, copied, saved, or routed to an inappropriate destination. However, organizations should treat such controls as part of a wider governance strategy rather than assuming all AI output can be perfectly interpreted in real time.

DLP for AI Workflows​

The platform’s data loss prevention for AI capabilities are designed to apply policy to regulated information moving through AI workflows.
This should resonate with organizations that already have mature DLP programs. The fundamental compliance categories have not disappeared because users adopted AI:
  • PII still requires protection.
  • PCI-related data remains tightly controlled.
  • Financial, legal, healthcare, government, and education data still carry specific obligations.
  • Intellectual property remains commercially sensitive even where no explicit regulation applies.
The challenge is that AI can make data easier to aggregate, reinterpret, and distribute. A single prompt may combine details from several files, systems, and conversations. A standard DLP rule that works well for a spreadsheet may need additional contextual handling when the same data appears within natural-language instructions.
Forcepoint’s promise is that existing classification intelligence can be reused across AI. That is operationally attractive, but customers should validate how existing policies translate into AI-specific contexts. A high-volume AI environment can magnify false positives, and poorly tuned restrictions can quickly drive employees toward unsanctioned tools.

Microsoft 365 and Windows Environments Are Central to the Opportunity​

The Forcepoint announcement is particularly relevant to organizations where Windows endpoints and Microsoft 365 form the core productivity stack.
Microsoft Copilot is woven into the workflows users already understand: Outlook, Teams, Word, Excel, PowerPoint, SharePoint, and other Microsoft 365 services. That integration can make AI more useful, but it also raises the consequences of overshared data, inconsistent permissions, and loose information governance.
A Copilot deployment cannot be secured solely by asking whether the Copilot service itself is approved. The larger questions include:
  • Which SharePoint sites and Teams channels are accessible?
  • Are Microsoft Purview sensitivity labels consistently applied?
  • Do employees have access to more data than their current role requires?
  • Can a user submit restricted content to external AI services from a corporate browser?
  • Are personal and corporate AI accounts distinguishable on managed Windows devices?
  • Do data policies apply consistently to web, endpoint, email, SaaS, and AI channels?
  • Are internal agents using Microsoft Graph, Microsoft 365 APIs, or other connectors appropriately constrained?
Forcepoint’s references to Microsoft 365 integration and Microsoft Information Protection tagging suggest the platform is designed to operate alongside Microsoft-centric governance environments rather than replace them.
That is the right direction. Microsoft 365 security, identity, data classification, endpoint management, and AI governance each solve part of the problem. Enterprises should expect a third-party AI data security platform to complement—not duplicate or undermine—their established Microsoft controls.

Personal Versus Corporate AI Tenants​

One of the more practical features is personal versus corporate tenant detection.
An enterprise may permit employees to use an approved corporate AI tenant with contractual privacy and retention protections while blocking them from using a personal account on the same service. This is a far more nuanced policy than simply allowing or banning a domain.
For example, an employee could be allowed to access a corporate AI service for approved internal work but prevented from uploading files through a personal account. The distinction is essential because consumer and enterprise versions of the same product can have sharply different data handling, identity, administration, and audit capabilities.
For Windows administrators, endpoint visibility will be central. Policies must account for browsers, installed applications, browser profiles, sign-in state, remote work, unmanaged devices, and BYOD scenarios. A control that works only inside a managed network is unlikely to be enough.

The Role of Shadow AI Controls​

Shadow AI is often discussed as if it were simply an employee compliance problem. In reality, it is frequently a symptom of a productivity gap.
Users adopt unapproved AI tools because the approved option is unavailable, slow to procure, difficult to use, lacks a needed capability, or is poorly integrated into their daily work. Security teams can block risky services, but a blanket prohibition without usable alternatives often pushes activity into less visible channels.
Forcepoint says it can discover, allow, restrict, or block unsanctioned AI applications inline and in real time. This capability is valuable when it is paired with thoughtful policy design.
A mature shadow AI program should generally separate tools and activities into tiers:
  1. Approved and governed
    Corporate AI services with supported identity, logging, contractual protections, and defined data rules.
  2. Conditionally permitted
    Services allowed for low-risk tasks, but with uploads disabled or sensitive-data controls applied.
  3. Restricted
    Tools that may be used for public, non-sensitive content but not corporate documents, source code, customer data, or personal information.
  4. Blocked
    Services or categories that pose unacceptable privacy, compliance, malware, account, or data-exfiltration risk.
A single console that can enforce those distinctions across web and endpoint channels could reduce operational friction. But enforcement policy must be clear enough for users to understand. The most successful programs explain what is safe to do, what is prohibited, and which approved alternative is available.

AI Detection and Response: Beyond Traditional DLP Reporting​

Forcepoint refers to its unified oversight layer as AI Detection and Response, or AIDR.
The name echoes established security categories such as endpoint detection and response, but the focus here is data movement through AI applications and agents. The platform is intended to monitor a range of API-connected AI services and provide a single view across approved AI, shadow AI, agent activity, and associated policy events.
This is a logical evolution. Organizations need more than a static inventory of AI tools. They need to investigate events in context:
  • Was a sensitive prompt blocked or merely logged?
  • Which user submitted it?
  • Was the activity carried out directly by a person, by an agent, or by both?
  • Which account and tenant were involved?
  • Did the action originate from a managed Windows endpoint?
  • Was a file uploaded, summarized, transformed, or shared onward?
  • What classification or policy triggered the event?
  • Is similar behavior happening elsewhere in the business?
Identity attribution is especially important. AI environments can obscure responsibility when a user invokes an agent that invokes a connector that retrieves data from another service. Forcepoint’s stated ability to associate activity with a person, an agent, or a combination of both addresses a real governance need.
However, enterprise buyers should ask detailed questions about audit integrity, log retention, API coverage, event correlation, and the handling of third-party agent frameworks. A clean dashboard is useful, but defensible governance depends on whether the underlying event data remains complete and attributable when an incident, audit, or legal review occurs.

ARIA, Natural-Language Policy Assistance, and the Automation Trade-Off​

The platform includes an embedded AI assistant called ARIA, designed to provide natural-language recommendations for creating, governing, and enforcing policies.
This could lower the operational barrier for organizations that lack large DLP engineering teams. Data protection policies are often complex, time-consuming to maintain, and difficult to translate into controls that work consistently across endpoints, cloud applications, web traffic, and AI interactions.
An assistant that can identify policy gaps, unsafe data flows, and apparent exposure to unsanctioned AI tools may help teams move faster. It could also make DLP more accessible to IT and security staff who understand the business risk but do not have deep experience with every policy syntax or classification model.
Still, AI-generated governance recommendations require guardrails of their own.
Security policy is not a purely technical exercise. A recommended control may affect productivity, legal obligations, customer service, software development, accessibility, records management, or a business unit’s ability to use approved tools. Automatically generated policies should be reviewed before they are enforced broadly, particularly in environments where an inaccurate classification rule could block legitimate work at scale.
The most sensible use of an AI policy assistant is likely as a human-supervised accelerator:
  • Surface potential data flows that lack controls.
  • Suggest policy language or enforcement options.
  • Identify overly permissive configurations.
  • Prioritize high-risk activity for review.
  • Explain why a rule triggered.
  • Assist with reporting and investigation.
  • Keep an approval workflow for meaningful policy changes.
Automation can reduce workload. It should not eliminate accountable decision-making.

Strengths of Forcepoint’s New Platform Strategy​

Forcepoint’s AI Data Security announcement stands out for several reasons.

One Policy Model Across Multiple AI Risks​

The strongest strategic point is the effort to unify sanctioned AI, shadow AI, and agentic AI under a shared policy model. These problems are often purchased, managed, and reported through separate products, creating gaps between visibility and enforcement.
A data-centric policy layer has the potential to be more durable than application-specific controls. AI services will change quickly, but core data categories—customer records, intellectual property, financial data, credentials, regulated information—remain sensitive regardless of where they travel.

Protection at the Point of Interaction​

Inline inspection of prompts, responses, and file uploads aims to move organizations from retrospective analysis to prevention. That is a meaningful improvement over discovering an exposure only after sensitive data has already reached an external service.

Strong Alignment With Existing Enterprise Controls​

Forcepoint is not asking organizations to invent an entirely separate set of data categories for AI. Extending existing DLP classifications and information protection rules into AI workflows could limit duplicated policy work and reduce administrative complexity.

Agent Security Is Treated as an Access-Control Problem​

The emphasis on least privilege and avoiding direct agent credentials is important. The industry conversation around AI agents often focuses on their productivity potential, but the access model is what determines their real-world risk. A well-designed gateway can make agent use more auditable and less dependent on broad standing permissions.

Practical Relevance for Microsoft-Centric Enterprises​

Support for Microsoft 365 environments, tenant awareness, information protection tagging, endpoint visibility, and AI integrations gives the platform a clear use case for Windows-heavy organizations. AI governance is rapidly becoming part of day-to-day endpoint, browser, cloud, and collaboration security—not an isolated innovation project.

Risks, Limitations, and Questions Buyers Should Ask​

The platform’s direction is promising, but the claims warrant careful validation in a proof of concept.

Coverage Claims Must Be Tested Against Real Workflows​

“Every prompt,” “every agent,” and “single-console” messaging can sound comprehensive, but coverage depends on how employees and applications actually connect to AI services. Browser access, desktop applications, API calls, embedded copilots, private model endpoints, remote devices, and custom agents do not all expose the same enforcement points.
Buyers should test the exact AI tools, SaaS connectors, browsers, endpoint configurations, and network paths used in production.

DLP Accuracy Remains Difficult​

AI does not eliminate the longstanding DLP challenge of balancing detection quality with user experience. False positives can frustrate users, while false negatives can create a false sense of security.
Organizations should measure:
  • Detection accuracy for their sensitive content
  • Contextual understanding of structured and unstructured data
  • False-positive rates for prompt inspection
  • Policy impact on legitimate business workflows
  • Ability to tune rules by department, role, tenant, device, application, and destination
  • Performance impact during real-time inspection

Agent Governance Requires More Than a Gateway​

An agent gateway is valuable, but it does not solve every agentic AI risk. Organizations still need clear inventories, ownership, approval processes, lifecycle management, testing, prompt-injection defenses, tool restrictions, logging, and separation of duties.
The platform can become a major control point, but it cannot substitute for sound agent architecture.

Data Residency and Privacy Need Scrutiny​

Because AI security platforms inspect sensitive prompts, files, and responses, enterprises must understand how the security service processes and retains content. This is especially important for regulated organizations, public-sector environments, and companies with regional data residency obligations.
Forcepoint’s cloud and on-premises delivery options may be relevant here, but organizations should verify deployment architecture, telemetry handling, encryption, retention, administrative access, and regional support before committing.

Platform Consolidation Can Create Dependency​

A unified platform may simplify policy management, but it can also centralize operational dependency. If an organization relies on one vendor for discovery, classification, endpoint enforcement, web controls, AI inspection, reporting, and agent access, resilience and integration planning become essential.
Security teams should assess API availability, export options, integration with SIEM and SOAR platforms, interoperability with Microsoft security tooling, and the ability to maintain visibility if a service or connector is unavailable.

What a Sensible Deployment Looks Like​

The most effective rollout will not begin with an enterprise-wide block list. It will start with discovery and a focused set of high-value controls.
A practical deployment sequence could include:
  1. Inventory current AI use across managed Windows devices, browsers, SaaS applications, and cloud environments.
  2. Separate approved enterprise AI tenants from personal accounts, especially where the same AI service is used in both contexts.
  3. Identify high-risk data categories such as customer records, credentials, PCI-related data, source code, confidential financial material, and regulated documents.
  4. Map high-value AI workflows in Microsoft 365, Salesforce, Jira, developer environments, support operations, HR, legal, and finance.
  5. Apply alert-only controls first to understand how policy rules behave in real business activity.
  6. Move high-confidence policies to inline enforcement, beginning with data types that should never be submitted to unapproved AI services.
  7. Evaluate agents separately from employee chat use, focusing on permissions, identities, connectors, actions, and credential handling.
  8. Establish executive reporting that shows both risk reduction and business enablement, rather than reporting only on blocked events.
  9. Review policies continuously as new AI services, models, agent frameworks, and user workflows appear.
The key is to avoid treating AI security as a simple binary choice between unrestricted access and blanket prohibition. Organizations need controls that let approved, useful AI work continue while enforcing meaningful boundaries around sensitive information.

The Bottom Line​

Forcepoint’s AI Data Security platform arrives as enterprises move beyond the first phase of generative AI adoption. The question is no longer whether employees will use AI. They already are. The challenge is whether organizations can govern the data, identities, permissions, prompts, files, and automated actions that make AI valuable without creating a parallel set of unmanaged risks.
The company’s strongest idea is that AI governance must be anchored in data security. Visibility into AI use is necessary, but it is not the same as controlling data once it enters a prompt, an agent workflow, a cloud connector, or an external model service.
For Windows and Microsoft 365 organizations, the platform’s mix of DLP, classification, tenant-aware controls, agent access governance, and centralized reporting addresses a real and rapidly expanding problem. Its success will depend on coverage, accuracy, integration quality, and the ability to apply policy without disrupting legitimate work.
If Forcepoint can consistently deliver on its claim of bringing protection into the AI interaction itself—not merely identifying risk afterward—it will offer enterprises a more practical path to using AI at scale while keeping sensitive data under meaningful control.

References​

  1. Primary source: Channel Insider
    Published: 2026-07-24T08:08:36+00:00
  2. Related coverage: forcepoint.com