Box launches AI agent security controls for enterprises
Box has introduced security controls designed to govern AI agents operating across enterprise content, applying to both native Box agents and third-party tools including Claude, ChatGPT and Gemini. The controls sit at the content layer, vetting and recording each agent action while blocking anything outside set permissions.
Key features include prompt injection detection, label-based access controls, Model Context Protocol guardrails, classification-based access policies and human-in-the-loop approval for high-impact actions. The move targets a critical barrier identified in Box's own research, where 90% of IT leaders cited security and trust concerns as the main obstacle to deploying AI agents at scale.
