In Brief
Box added seven new security and governance controls for AI agents working with enterprise content.
The controls apply to Box-native agents and third-party agents, with no extra tooling required.
The move responds to Box's own research: 90% of IT leaders cite security and trust as the top barrier to letting AI agents near company files.
Box announced new security and governance capabilities to give organizations greater control over AI agents working with enterprise content on July 21. The features apply to both Box-native agents and third-party agents such as Claude, ChatGPT and Gemini.
The controls are built into the platform at the content layer, requiring no additional tools. The company said the release address concerns raised in its 2026 State of Enterprise AI report, which found that 90% of IT leaders surveyed identified security, regulatory and trust concerns as the biggest barrier to granting AI agents access to enterprise content.
AI agents are only useful if they can reach real company data. But that same reach is the risk: an agent with broad, unreviewed access isn't really "software" in the traditional sense — it's closer to a new hire handed a master key on day one, with nobody checking back on what that key still opens six months later.
Box Just Built 7 New Guardrails Into Its AI Agents
Box detailed seven new security and governance capabilities:
| Capability | What It Does |
|---|---|
| Agent guardrails | Admins set rules for what a Box-built AI agent can do, based on how sensitive the content is (e.g., enforcing label-based access, requiring approval for deletions, disabling external sharing) |
| Prompt injection detection | Validates inputs at the content layer; flags, logs, alerts on, or blocks attempts to manipulate an agent into ignoring its instructions |
| MCP guardrails | Lets admins scope exactly what outside agents can reach through Box's MCP server — e.g., file creation only in approved folders, no external sharing, moves only to specific folders |
| Classification-based access | Content with specified classifications is excluded from AI read, search, or access — applies to both external and custom Box AI agents |
| Agent activity oversight | Provides visibility into external agent activity on customer content, with threshold-based alerts to detect and respond to suspicious behavior |
| Agent audit trails & session governance | Retains compliance-ready records of every agent session with full context, including retention policies and legal holds |
| Human-in-the-loop approval | Sensitive or high-impact actions require a person to sign off before the agent proceeds |
The new agent controls will roll out to customers on the E-Advanced plan over the coming months.
Why the Access Gap Is the Real Story
The risk Box is aiming to address isn't hypothetical. NIST's National Cybersecurity Center of Excellence flagged this exact problem, arguing that AI agents need to be treated as identifiable entities inside enterprise identity systems — not anonymous processes running on shared credentials that nobody revisits.
The architecture matters more than the policy sitting on top of it. A read-only agent limits the damage even in a worst-case breach. A write-enabled agent operating under permissions nobody's reviewed since onboarding is a different risk category entirely — and no amount of after-the-fact policy fixes that if the access itself was never scoped correctly.
Box Isn't Alone in Taking on the Access Problem
Every major enterprise content platform is racing to solve the same problem, with noticeably different approaches. A few recent examples include:
Laserfiche designed its AI agents to inherit whatever permissions the person who launched them already has — the security travels with the agent automatically, rather than being configured separately.
Hyland unveiled an Agent Lifecycle Management suite and Control Tower at CommunityLIVE 2026, aimed squarely at regulated industries that need to prove, after the fact, exactly what an agent did.
Cisco introduced Zero Trust Access for agents at RSA 2026, treating agents as their own attack surface with dedicated identity management and red-teaming built specifically for them.
Whatever platform an organization uses, the underlying question is the same: can you tell, at any moment, exactly what an AI agent has permission to see and do — and can you prove it after the fact?
Have a tip to share with our editorial team? Drop us a line: