Cyber security

AI is transforming cybersecurity: systems now assess intentions, not just actions

Speaking from the stage at Protect 2026, Proofpoint’s annual event held in San Diego, CEO Sumit Dhawan explains that the old paradigm of cyber security no longer works

 (Adobe Stock)

3' min read

Translated by AI
Versione italiana

3' min read

Translated by AI
Versione italiana

In modern businesses, AI is no longer merely a tool used by employees, but a sort of digital assistant that plays a very active role in business processes: it helps create content, analyses information, retrieves documents from internal systems and, in the case of AI agents, carries out tasks on behalf of the user. Nowadays, however, any new role involving data work is potentially a threat, and things become even more complicated with AI agents. This software is, in fact, highly versatile, but it can be exploited via instructions written in human language and hidden within documents, emails or other messages. When this happens, the only way to block their actions is to move beyond the traditional cybersecurity model and adopt a more modern one: it is no longer simply a question of who can access data or an application, but also of understanding for what purpose, in what manner and through what chain of actions — whether human or automated — that access is exploited.

The limitations of the permission-based model

Speaking from the stage at Protect 2026, Proofpoint’s annual event held in San Diego, CEO Sumit Dhawan explains that the old paradigm of cyber security – whereby verifying identities and authorisations was sufficient to prevent breaches – no longer works. These controls still need to be in place, but an AI agent today can act using legitimate credentials whilst ultimately producing a dangerous outcome. If an agent operating within one of the supply chain processes, for example, were to be compromised by malicious instructions hidden in an email designed to trick them into gathering information on all suppliers, compiling it into a file and sending it to an email address, from a traditional perspective, the access would appear legitimate: the agent does indeed possess the necessary permissions and can save the data to a file to make it available to someone, but its behaviour would no longer be consistent with the original business objective. And this is where what is known as ‘intent security’ comes into play: combining identity, authorisations, data classification, behaviour, AI activities and intent signals within a single framework enables the defence system to understand the true intentions of the agent or malicious software, providing the necessary context to assess whether or not to block it. This blocking action must be managed entirely by machines because, as a company adopts AI, the number of assistants and agents operating at extremely high speeds becomes very large, and each of these traverses applications, document repositories, cloud services and collaborative tools. The only way to keep them under control is through a system that ‘intuitively understands’ what each of these entities actually intends to do and assesses their reliability. Proofpoint outlines a defence model comprising three agent-based functions: detection, analysis and resolution. The first function correlates intent, access and behaviour to identify potential risks, rather than simply producing a flat list of alerts. The second automatically reconstructs the context of an event, linking data, identities, activities and actions leading to data loss or exposure. The third translates the evidence into action: it reduces excessive privileges, corrects inappropriate sharing, and updates data leakage prevention rules or other protective measures. In other words, the aim is to transform cybersecurity into a process capable of learning from context. According to Dhawan, an effective system should not force teams to anticipate every possible misuse of AI in advance, but should be able to identify inconsistent behaviour, highlight risks that have not yet materialised, and propose new policies based on the evidence gathered.

Loading...

Of course, human staff are not completely excluded from operations, and Proofpoint proposes that decisions deemed significant should remain subject to approval and governance, whilst providing all the functions necessary to implement these controls in line with business needs. In this approach, automation serves to reduce the burden of repetitive tasks — triage, context gathering, alert prioritisation — so that specialists can focus on judgement, risk management and oversight of the most sensitive decisions. The new features of the Proofpoint Agentic Data and AI Security system, Semantic Business Policies and Agentic Insights, which enable this new approach, will be made available by the end of 2026 and will help cybersecurity take a vital step forward in preventing breaches that seek to exploit the growing wave of AI within organisations.

Copyright reserved ©
Loading...

Brand connect

Loading...

Newsletter

Notizie e approfondimenti sugli avvenimenti politici, economici e finanziari.

Iscriviti