Within forty-eight hours, three of the largest names in enterprise security put AI agent risk at the centre of their product roadmaps β and a United Nations scientific panel warned that the safeguards most companies rely on are already slipping behind the agents they are meant to contain. The result is the clearest sign yet that securing autonomous agents has stopped being a feature bolted onto existing tools and has become a distinct category with its own budget line.
The shift matters because the deployment numbers have run far ahead of the controls. Proofpoint's own 2026 AI and Human Risk Landscape research found that 87% of organisations have moved AI assistants beyond pilot stage, while 52% are not confident their controls would detect a compromise. That gap β widespread autonomy paired with thin visibility β is precisely what this week's launches are aimed at.
Proofpoint Fuses Data Security With AI Security
At its Protect 2026 conference in San Diego on 22 September, Proofpoint announced the Proofpoint Agentic Data and AI Security system, pitching it as the industry's first unified approach that treats data risk and AI risk as a single problem rather than two adjacent ones.
The system runs on three autonomous agents that map to the lifecycle of an incident:
- Zero-Touch Detection, which flags consequential actions by assessing an agent's intent alongside its access rather than treating permissions as the only signal.
- Instant Investigation, which reconstructs what happened across data, identity and behaviour.
- Protection Optimization, which recommends or applies remediation such as access adjustments and data loss prevention policy changes, with human oversight retained.
Two additional pieces are arguably more novel than the agents themselves. Agentic Insights analyses AI interactions, tool usage and policy decisions to surface risks nobody wrote a rule for; when one is validated, the platform proposes a Semantic Business Policy to govern similar behaviour in future. That turns governance into a feedback loop instead of a static rulebook β an implicit admission that enterprises cannot enumerate agent failure modes in advance. Proofpoint expects the capabilities to be available by the end of 2026, with a companion Agentic Collaboration Security system following in the first quarter of 2027.
Palo Alto Networks Turns Frontier Models on Its Own Customers
The same day, Palo Alto Networks launched Unit 42 Continuous Frontier AI Defense, an agentic offensive security service that uses gated frontier models β Anthropic's Claude Mythos 5, OpenAI's GPT-5.6-Cyber and open-weight models β behind a proprietary multi-model harness that routes each testing task to whichever model suits it best.
The company's justification is a timeline argument: it says AI-assisted attackers have compressed the gap between vulnerability discovery and working exploit by as much as 97% in some cases, turning weeks into hours. Point-in-time penetration testing cannot keep pace with that, so the service replaces it with a full-estate baseline scan followed by always-on testing as environments change, plus adversary simulation across web apps, APIs, cloud infrastructure, source repositories and network assets.
Palo Alto Networks reports validating the service internally and across more than 100 customer engagements, claiming its harness surfaced 3.2 times more high and critical vulnerabilities per product than legacy testing and cut mean time to remediate by 51%. Internally, it says continuous Mythos-based scanning delivered more than a year of traditional penetration testing output in three weeks. Zero Data Retention architectures are used so customer code and telemetry are not retained or used to train public models. The service sells worldwide on an annual subscription, with no published list price.
Akamai Shifts the Question From Identity to Behaviour
Akamai's contribution this week was conceptual rather than a product launch, and it may prove the most consequential. Its security guidance argues that enterprises should stop treating agent risk as primarily an identity problem and instead prioritise edge-level mitigations that block risky agent actions while back-end fixes are deployed.
That reframing lands on a genuine weak point. Identity tells you which agent is acting; it says very little about whether the action itself is reasonable. As agents chain tool calls across systems, a correctly authenticated agent doing something catastrophic looks, to an identity-centric control plane, entirely normal.
Why It Matters
The governance backdrop hardened this week too. A UN-backed scientific panel concluded that conventional safeguards for AI agents are deteriorating following a July breach of Hugging Face involving evaluation agents, cautioning that preventing a repeat of that specific incident does not establish that humans can reliably keep increasingly capable agents under control.
For operators, three practical consequences follow. First, agents need their own monitoring, containment and incident-response plans β they cannot be treated as one more interface in front of a model. Second, logging alone is no longer sufficient; all three vendors are converging on runtime intervention, because an audit trail only tells you what already went wrong. Third, buyers should read availability dates carefully: much of what was announced this week ships late in 2026 or in 2027, while the agents themselves are already in production today.
The category is forming because the alternative β hoping least-privilege access and identity controls are enough β is being tested in public, and not always passing.
