AI agents are ready for the enterprise—security is not
Enterprise AI agents are software systems that act autonomously across business tools and data, making multi-step decisions such as searching, analyzing, creating, modifying, or sharing content without human micromanagement, which creates powerful productivity gains but also introduces new risks of unauthorized data access and unintended actions at scale. Today, that gap between potential and protection is widening fast. Box reports that 83 percent of organizations are already experimenting with AI agents on critical tasks, yet 90 percent of IT leaders say security, regulatory, and trust concerns are the main barrier to giving these agents broad access to company content. Put bluntly, enterprises want the upside of agents but fear losing control of their data and workflows. That fear is reasonable. When agents can write code, move files, trigger workflows, and talk to external systems, every prompt can become a production change. Security that only observes after-the-fact is no longer enough; it has to sit in the execution path.
Box: Content-centric AI agent security controls inside the platform
Box’s answer is to make AI agent security controls native to the content platform instead of another bolt-on tool. It is extending its existing content security and enterprise AI governance framework to cover any workflow where agents search, analyze, create, modify, or share files, keeping access within the strict scope of each assigned task. This matters: when security lives at the content layer, every AI action is automatically permissioned, logged, and auditable without extra plumbing. Box’s agent guardrails let administrators define what custom agents can and cannot do based on policy and content sensitivity, including label-based restrictions, approval requirements before deletion, and bans on external sharing. Prompt-injection detection inspects inputs before they reach a model, with options to log, flag, or block attempts to override instructions or exfiltrate protected data. Human-in-the-loop controls force a person to approve high-impact actions, while classification-based policies can exclude entire categories of documents from agent reach.
Zenity: Runtime boundaries for autonomous AI decisions, not just alerts
Where Box secures content-centric agents, Zenity is going after the heart of autonomous AI safety: the decision layer. Its expanded platform adds Exposure Management and Runtime Boundaries to govern AI decisions before they turn into enterprise actions, especially for long-horizon agents that operate over hours or days across multi-step workflows. These agents can compile code, call APIs, handle sensitive data, and chain tools together; risk often emerges not from one step but from the sequence. Zenity’s view is bluntly opinionated: observing agent behavior after damage occurs is a failure mode. Runtime Boundaries act as a decision engine that evaluates every AI action in real time, considering intent, identity, requested action, accessed data, tools, prior activity, and enterprise policy so it can stop risky patterns before they have business impact. Enterprises define what agents are allowed to do, and Zenity enforces it across coding agents, copilots, Agentforce, MCP servers, and custom systems. This is runtime boundaries AI as a security control, not mere monitoring.
Why visibility and runtime governance are becoming table-stakes
Both moves reflect the same hard truth: enterprise AI governance must evolve from static policies and dashboards to continuous runtime enforcement. Box is building deep visibility into how external systems interact with stored content, including agent activity oversight and threshold-based alerts to flag unusual behavior or potential unauthorized actions, backed by detailed audit trails that support compliance, retention, legal holds, and investigations. Zenity structures AI security as a continuous loop: Surface discovers agents, validates exploitable paths, and prioritizes exposure; Enforce applies Runtime Boundaries to decide whether each action proceeds, is blocked, or terminates the agent; Protect runs AI-driven forensics and incident response while Guardian Agents learn from every investigation to harden future decisions. This creates a feedback cycle where exposure insights inform runtime policies and every decision tightens protection. As AI agents become decision makers, security that merely logs activity is inadequate; enterprises need live control over what agents are allowed to do in the first place.
Practical impact: from file safety to production code and workflows
These aren’t abstract controls; they decide whether autonomous AI is usable in sensitive environments. Box’s capabilities can protect transaction files in financial services, guard patient information in healthcare, govern contracts and discovery materials in law firms, and restrict access to policyholder and claims records in insurance. Because the controls apply across Box-native agents and external models like Claude, ChatGPT, and Gemini, enterprises can switch models while keeping consistent security. Zenity’s Runtime Boundaries give precise control over coding agents and workflow agents, from preventing sensitive data exposure to restricting privileged actions and controlling MCP servers across tools such as Claude Code, Cursor, Microsoft Copilot, Salesforce Agentforce, ChatGPT Enterprise, Amazon Bedrock, Azure AI Foundry, and custom-built agents. The direction of travel is clear: runtime security monitoring and pre-action enforcement are becoming table-stakes for autonomous AI safety. Organizations that treat these as optional add-ons will either throttle their agents’ usefulness or accept unacceptable risk.
What comes next for enterprise AI agents
The next phase is less about flashy new agents and more about who controls them. Box will roll out its new security and governance features to Enterprise Advanced customers over the coming months, signaling that content-native controls will be bundled into mainstream plans, not sold as niche add-ons. Zenity is betting on a continuous AI security loop where runtime decisions, exposure management, and incident learning reinforce each other over time. That is the right instinct: governance cannot be a one-time configuration exercise when agents keep changing tools, data, and tasks. The strategic takeaway for enterprise teams is clear. If you deploy autonomous agents without deep visibility and runtime boundaries, you are outsourcing your change-management and data-protection policies to a probabilistic system. If you bake AI agent security controls into the stack, agents stop being an ungoverned risk and start becoming safe—if demanding—co-workers.






