metal guardrails on a highway
News

Box Adds Security Controls for AI Agents Accessing Enterprise Content

2 MINUTE READ|Information ManagementInformation Management|Jul 22, 2026
Sheryl Hodge avatar
By
SAVED
New guardrails govern how Box-native and third-party agents like ChatGPT and Gemini interact with sensitive files.

In Brief

  • Box added seven new security and governance controls for AI agents working with enterprise content.

  • The controls apply to Box-native agents and third-party agents, with no extra tooling required.

  • The move responds to Box's own research: 90% of IT leaders cite security and trust as the top barrier to letting AI agents near company files.

Box announced new security and governance capabilities to give organizations greater control over AI agents working with enterprise content on July 21. The features apply to both Box-native agents and third-party agents such as Claude, ChatGPT and Gemini.

The controls are built into the platform at the content layer, requiring no additional tools. The company said the release address concerns raised in its 2026 State of Enterprise AI report, which found that 90% of IT leaders surveyed identified security, regulatory and trust concerns as the biggest barrier to granting AI agents access to enterprise content.

AI agents are only useful if they can reach real company data. But that same reach is the risk: an agent with broad, unreviewed access isn't really "software" in the traditional sense — it's closer to a new hire handed a master key on day one, with nobody checking back on what that key still opens six months later.

Box Just Built 7 New Guardrails Into Its AI Agents

Box detailed seven new security and governance capabilities:

CapabilityWhat It Does
Agent guardrailsAdmins set rules for what a Box-built AI agent can do, based on how sensitive the content is (e.g., enforcing label-based access, requiring approval for deletions, disabling external sharing)
Prompt injection detectionValidates inputs at the content layer; flags, logs, alerts on, or blocks attempts to manipulate an agent into ignoring its instructions
MCP guardrailsLets admins scope exactly what outside agents can reach through Box's MCP server — e.g., file creation only in approved folders, no external sharing, moves only to specific folders
Classification-based accessContent with specified classifications is excluded from AI read, search, or access — applies to both external and custom Box AI agents
Agent activity oversightProvides visibility into external agent activity on customer content, with threshold-based alerts to detect and respond to suspicious behavior
Agent audit trails & session governanceRetains compliance-ready records of every agent session with full context, including retention policies and legal holds
Human-in-the-loop approvalSensitive or high-impact actions require a person to sign off before the agent proceeds

The new agent controls will roll out to customers on the E-Advanced plan over the coming months.

Why the Access Gap Is the Real Story

The risk Box is aiming to address isn't hypothetical. NIST's National Cybersecurity Center of Excellence flagged this exact problem, arguing that AI agents need to be treated as identifiable entities inside enterprise identity systems — not anonymous processes running on shared credentials that nobody revisits.

The architecture matters more than the policy sitting on top of it. A read-only agent limits the damage even in a worst-case breach. A write-enabled agent operating under permissions nobody's reviewed since onboarding is a different risk category entirely — and no amount of after-the-fact policy fixes that if the access itself was never scoped correctly.

Box Isn't Alone in Taking on the Access Problem

Every major enterprise content platform is racing to solve the same problem, with noticeably different approaches. A few recent examples include:

Whatever platform an organization uses, the underlying question is the same: can you tell, at any moment, exactly what an AI agent has permission to see and do — and can you prove it after the fact?

fa-regular fa-lightbulb Have a tip to share with our editorial team? Drop us a line:

Main image: adobe stock

About the Author

Sheryl Hodge is assistant managing editor at Simpler Media Group, where she plays a vital role in keeping the editorial operations running smoothly across the company’s three sites: CMSWire, Reworked and VKTR. Known for her organizational skills and attention to detail, Sheryl acts as the glue that binds the publications together, ensuring that workflows remain seamless and deadlines are met.

Featured Research