Proofpoint has launched a groundbreaking security model that analyses the purpose behind user interactions beyond surface-level behaviour, aiming to identify malicious intent in trusted communication channels and combat sophisticated AI-enabled attacks.
Proofpoint has unveiled a new security model aimed at spotting attacks that look like normal work. Announced at its Protect 2026 event in San Diego, the system is called Agentic Collaboration Security and is designed to protect email, collaboration tools and web browsers by analysing the purpose behind each interaction rather than relying only on surface-level behaviour. According to Proofpoint, the approach is intended to recognise malicious intent even when a message or request appears routine.
The pitch reflects a wider problem in enterprise security: some of the hardest intrusions now arrive through trusted business relationships. Proofpoint said a compromised supplier can abuse an existing email thread, fraudulent payment instructions can closely mirror established processes, and targeted attacks on senior staff may never repeat in an obvious pattern. In that environment, the company argues that anomaly detection alone is no longer enough, because an attack can be highly convincing while still being harmful.
At the centre of the platform is the Proofpoint Knowledge Graph, which combines threat intelligence with an organisation’s own working relationships, communication patterns, data access and user risk profile. Proofpoint said its new Nexus intent-based detection model then evaluates that context in stages, resolving many cases quickly while sending ambiguous ones for deeper analysis. The company is also extending the system across secure email gateway and API-based deployments, which it presents as a single architecture rather than separate products.
Proofpoint is also adding more automation around response and investigation. The company said the platform can reconstruct attack paths, identify related messages, measure exposure and assemble evidence for remediation, reducing the amount of manual work required from security teams. For executives and other privileged users, it is introducing tailored protection intended to detect highly targeted attacks aimed at people with authority to approve transactions or access sensitive information.
Another new layer is Advanced Browser Protection, developed with Push Security, which extends controls beyond the inbox and into the browser. Proofpoint said this is meant to reduce risk from post-click phishing, malicious browser extensions, OAuth-based phishing, credential theft and session hijacking. The browser telemetry is fed back into Proofpoint’s security workbench and investigation tools, giving defenders a single view across the full chain of collaboration attacks. The company said the new capabilities are due in the first quarter of 2027, with availability varying in jurisdictions that require local data residency.
The launch fits into a broader effort by Proofpoint to connect collaboration security, data security and AI risk management. In separate announcements, the company has described a move towards agentic data and AI security, with controls that govern how humans and AI agents access information and with policies that can be enforced at runtime. It has also outlined wider data-security updates that include AI-driven access governance and data discovery across hybrid environments, suggesting that the company is trying to build a more unified security stack around the way people and AI systems now work together.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





