Box Unveils New Controls to Secure AI Agents Operating Across Enterprise Content
Box Unveils New Controls to Secure AI Agents Operating Across Enterprise Content
New capabilities build on Box’s security and governance framework, to help enterprises confidently deploy Box-native and third-party AI agents across their content
REDWOOD CITY, Calif.--(BUSINESS WIRE)--Box, Inc. (NYSE: BOX), the leading Intelligent Content Management (ICM) platform, today announced new security capabilities designed to give organizations greater control over AI agents working with enterprise content. With new agent guardrails, third-party agent activity oversight, prompt injection detection, agent classification-based access policies, and more, customers will be able to extend Box’s enterprise-grade security controls to both Box Agents and third-party agents, such as Claude, ChatGPT, and Gemini. These new capabilities expand Box’s trusted governance framework to agentic workflows, enabling organizations to confidently deploy and scale AI agents while maintaining oversight of how enterprise data is accessed and used.
Box unveils new controls to secure AI agents operating across enterprise content
Share
"83 percent of organizations are already experimenting with AI agents across their most critical tasks,” said Manoj Asnani, VP of AI Security, Privacy, Compliance & Governance Products at Box. “As these agentic workflows become more deeply embedded in the enterprise, it’s critical to create the proper security controls to ensure agents have what they need to function effectively, without accessing, modifying, or exposing content beyond the scope of its intended task. Box already provides a safe environment for organizations to apply AI to their most critical business knowledge, and with these new controls, we are creating a standard for deploying agents of any kind securely and at scale.”
"As we rapidly advance our utilization of AI agents, we expect Box—which has consistently led the development of security management capabilities for secure collaboration—to provide the administrative features needed to safely leverage this new era of AI," said Tatsutoshi Murata, Head of IT Strategy Department at Nomura Research Institute. "In particular, we've found it extremely reassuring that Box offers multi-vendor support, allowing us to flexibly switch between AI models, while providing security management capabilities that span prevention, detection, and response. With a protective layer that appropriately manages AI agent access to content, we're confident our critical content will remain protected as we expand our use of AI."
Introducing new security capabilities for protecting enterprise content
Box’s 2026 State of Enterprise AI report found that security and privacy are the leading obstacles to deploying AI agents at scale. Among IT leaders surveyed, 90% identified security, regulatory, and trust concerns as the biggest barrier to granting AI agents access to enterprise content. Box’s new security and governance capabilities address this concern by being built directly into the platform where content already lives. By providing protections at the content layer, these controls help ensure that every agent action is intentional, permissioned, and auditable.
Whether agents are built in Box or connected through third-party platforms, security is applied at every touchpoint. This allows organizations to move from limited pilots to production-scale AI deployments without compromising on governance.
Box's new security and governance capabilities do not require additional tools to deploy or manage, and include:
- Agent guardrails that define exactly what custom Box AI agents can and cannot do based on content sensitivity and policy, including enforcing label-based access controls, requiring approval for deletion actions, and disabling external sharing to help protect sensitive information;
- Prompt injection detection capabilities that validate every input before it reaches the model by detecting known prompt injection patterns at the content layer and enabling organizations to log, alert on, or block suspicious attempts;
- MCP guardrails that let admins control what external AI agents connected through the Box MCP Server are allowed to do, with scoped permissions such as allowing file creation only in approved folders, blocking external sharing, and permitting content moves only to specific folders;
- Classification-based access policies for both external and custom Box AI agents that enable organizations to exclude content with specified classifications from being read, searched, or accessed;
- Agent activity oversight capabilities that provide visibility into external AI agent activity on customer content and configure threshold-based alerts, enabling organizations to quickly detect and respond to suspicious behavior;
- Agent audit trails and session governance that retain, audit, and provide compliance-ready records for every agent session with full session context, including retention policies and legal holds;
- Human-in-the-loop control features that require human approvals before agents execute sensitive or high-impact actions.
With these new security and governance capabilities, organizations across financial services, healthcare, legal, insurance, and more can confidently deploy AI agents.
- Financial services firms can safeguard sensitive M&A analysis and trade information by enforcing agent-level access controls and catching unexpected agent behavior in real time;
- Healthcare organizations can secure patient data and proprietary research by enforcing classification-based access controls and retaining a complete, compliance-ready audit trail of every agent action;
- Law firms can govern AI across contract analysis and discovery workflows by enforcing policy-driven controls on what agents can access and act on;
- Insurance companies can protect sensitive policyholder data and claims records by validating every agent input for prompt-injection attempts and excluding classified records from being accessed, ensuring only authorized AI agents touch confidential claims and regulatory information across claims processing and reporting workflows.
“As organizations rapidly adopt agentic AI, securing the content layer becomes the critical foundation for deployment,” said Amy Machado, Senior Research Director, Content and Knowledge Management Strategies, IDC. “Box’s new security and governance controls address the primary barriers of privacy and unauthorized access directly where the data lives. By embedding guardrails, prompt injection detection, and human-in-the-loop oversight into the platform, Box is establishing a vital trust standard that allows enterprises to confidently scale both native and third-party AI agents across their most sensitive content.”
Since its inception, Box has made security and compliance central to its mission, helping organizations guard sensitive data while driving productivity and collaboration. That commitment led to the launch of Box Shield in 2019, bringing built-in threat protection and data loss prevention directly into the content management workflow. Over the years, Box has expanded Box Shield with innovations like malware deep scanning, automated classification, and anomalous behavior alerts. This led to the launch of Box Shield Pro earlier this year, extending Box’s proven security foundation into the AI era by protecting enterprise content with AI. Now, together with Box’s new agent security capabilities, enterprises can protect every file, workflow, and AI agent interaction with advanced intelligence and control.
Availability
Box’s new security and governance capabilities for AI agents will be rolling out to customers on the E-Advanced plan in the coming months. To learn more, visit the Box Blog.
Forward-Looking Statements
This press release contains forward-looking statements that involve risks and uncertainties, including statements regarding Box’s new security and governance capabilities, its planned product features and future enhancements, and the market adoption and benefits of such product features and enhancements. There are a significant number of factors that could cause actual results to differ materially from the statements made in this press release, including: (1) adverse changes in general economic or market conditions; (2) Box’s ability to partner with third parties to integrate AI technologies with Box’s Intelligent Content Management platform; (3) delays or reductions in information technology spending; (4) the risk that Box’s customers do not renew their subscriptions, expand their use of Box’s services, or adopt new products or features offered by Box on a timely basis, or at all; (5) Box’s ability to provide timely and successful product introductions, enhancements, new features and modifications to its platform and services; and (6) actual or perceived security vulnerabilities in Box AI or other Box services or any breaches of Box’s security controls. Any unreleased services or features referenced in this or other press releases or public statements are not currently available and may not be delivered on time or at all. Customers who purchase Box products should make their purchase decisions based upon features that are currently available. Additional information on potential factors that could affect Box’s financial results is included in the reports on Forms 10-K, 10-Q and 8-K and in other filings Box makes with the Securities and Exchange Commission from time to time. These documents are available on the SEC Filings section of Box’s Investor Relations website located at These documents are available on the SEC Filings section of Box’s Investor Relations website located at www.boxinvestorrelations.com. Box does not assume any obligation to update the forward-looking statements contained in this press release to reflect events that occur or circumstances that exist after the date on which they were made.
About Box
Box (NYSE:BOX) is the leader in Intelligent Content Management. Our platform enables organizations to fuel collaboration, manage the entire content lifecycle, secure critical content, and transform business workflows with enterprise AI. Founded in 2005, Box simplifies work for leading global organizations, including JLL, Morgan Stanley, and Nationwide. Box is headquartered in Redwood City, CA, with offices across the United States, Europe, and Asia. Visit box.com to learn more. And visit box.org to learn more about how Box empowers nonprofits to fulfill their missions.
Contacts
Investor Relations:
Cynthia Hiponia
ir@box.com
Comms:
Madeline Gile
press@box.com
