Box announces AI agent security controls for enterprise content
Box, Inc. (NYSE: BOX) announced a set of new security and governance capabilities designed to give organizations greater control over AI agents that interact with enterprise content.
The new features, set to roll out to customers on the E-Advanced plan in the coming months, apply to both Box-native agents and third-party AI agents, including Claude, ChatGPT, and Gemini.
The capabilities include agent guardrails, prompt injection detection, MCP guardrails for external agents connected through the Box MCP Server, classification-based access policies, agent activity oversight with threshold-based alerts, agent audit trails with session governance, and human-in-the-loop approval controls for sensitive actions.
Box said the controls do not require additional tools to deploy or manage and are built directly into the platform where content resides.
According to Box's 2026 State of Enterprise AI report, 90% of IT leaders surveyed identified security, regulatory, and trust concerns as the biggest barrier to granting AI agents access to enterprise content. The same report found that 83% of organizations are already experimenting with AI agents.
"As these agentic workflows become more deeply embedded in the enterprise, it's critical to create the proper security controls to ensure agents have what they need to function effectively, without accessing, modifying, or exposing content beyond the scope of its intended task," said Manoj Asnani, VP of AI Security, Privacy, Compliance & Governance Products at Box.
Tatsutoshi Murata, Head of IT Strategy Department at Nomura Research Institute, said the company found it "reassuring that Box offers multi-vendor support, allowing us to flexibly switch between AI models, while providing security management capabilities that span prevention, detection, and response."
The announcement follows Box's earlier launch of Box Shield Pro, which the company said extended its security foundation into AI-era content protection.
