Box has announced a new set of AI security and governance capabilities that help organizations securely deploy AI agents across enterprise content. The latest enhancements extend Box’s Intelligent Content Management (ICM) platform by introducing advanced controls for both native Box AI Agents and third-party AI agents, enabling enterprises to maintain security, compliance, and governance as AI adoption accelerates.
As AI agents become increasingly integrated into enterprise workflows, organizations are seeking stronger governance to protect sensitive business information. Box's latest release introduces enterprise-grade security capabilities that extend existing content protection to AI-powered workflows.
The new features apply to both Box AI Agents and external AI agents, including Claude, ChatGPT, and Gemini. This enables organizations to adopt AI without sacrificing visibility, compliance, or administrative control over enterprise content.
"83 percent of organizations are already experimenting with AI agents across their most critical tasks,” said Manoj Asnani, VP of AI Security, Privacy, Compliance & Governance Products at Box. “As these agentic workflows become more deeply embedded in the enterprise, it’s critical to create the proper security controls to ensure agents have what they need to function effectively, without accessing, modifying, or exposing content beyond the scope of its intended task. Box already provides a safe environment for organizations to apply AI to their most critical business knowledge, and with these new controls, we are creating a standard for deploying agents of any kind securely and at scale.”
According to Box's 2026 State of Enterprise AI report, security, regulatory compliance, and trust remain the biggest challenges preventing organizations from deploying AI agents at scale. The new capabilities address these concerns by embedding security directly into the enterprise content layer.
The newly introduced features include:
Together, these capabilities help ensure every AI interaction with enterprise content remains permissioned, monitored, and auditable.
The enhanced governance framework is designed for organizations operating in highly regulated industries where protecting sensitive information is essential.
Financial services firms can secure confidential merger, acquisition, and trading information with granular AI access controls. Healthcare providers can safeguard patient information and research data through classification-based policies and detailed audit logs. Legal organizations can govern AI-driven document review and discovery while maintaining policy compliance. Insurance companies can protect claims and policyholder information using prompt injection detection and classified data restrictions.
"As we rapidly advance our utilization of AI agents, we expect Box—which has consistently led the development of security management capabilities for secure collaboration—to provide the administrative features needed to safely leverage this new era of AI," said Tatsutoshi Murata, Head of IT Strategy Department at Nomura Research Institute. "In particular, we've found it extremely reassuring that Box offers multi-vendor support, allowing us to flexibly switch between AI models, while providing security management capabilities that span prevention, detection, and response. With a protective layer that appropriately manages AI agent access to content, we're confident our critical content will remain protected as we expand our use of AI."
The latest announcement builds upon Box's long-standing investment in enterprise security. Since launching Box Shield in 2019, the company has expanded its capabilities with malware deep scanning, automated classification, anomalous behavior detection, and Box Shield Pro, which extends security into AI-powered content management.
“With these new security and governance capabilities, organizations across financial services, healthcare, legal, insurance, and more can confidently deploy AI agents.”
“As organizations rapidly adopt agentic AI, securing the content layer becomes the critical foundation for deployment,” said Amy Machado, Senior Research Director, Content and Knowledge Management Strategies, IDC. “Box’s new security and governance controls address the primary barriers of privacy and unauthorized access directly where the data lives. By embedding guardrails, prompt injection detection, and human-in-the-loop oversight into the platform, Box is establishing a vital trust standard that allows enterprises to confidently scale both native and third-party AI agents across their most sensitive content.”
By embedding governance directly into enterprise content management, Box aims to help organizations confidently scale AI adoption while maintaining security, compliance, and operational oversight. The new capabilities provide a unified framework for protecting enterprise data as AI agents become a central part of modern business workflows.