Box announced seven new security and governance capabilities for AI agents operating on enterprise content, targeting both Box-native agents and third-party agents including Claude, ChatGPT, and Gemini. The controls ship as part of Box Shield Pro and will roll out to E-Advanced plan customers in the coming months.
The announcement lands as Box’s own 2026 State of Enterprise AI report found that 90% of IT leaders surveyed identified security, regulatory, and trust concerns as the biggest barrier to granting AI agents access to enterprise content.
What Ships
The seven capabilities cover three layers of agent governance: prevention, detection, and response.
Prevention controls include agent guardrails that restrict what custom Box AI agents can do based on content sensitivity and policy. Administrators can enforce label-based access controls, require approval for deletion actions, and disable external sharing for sensitive content. Classification-based access policies let organizations exclude content with specified labels from being read, searched, or accessed by any agent.
MCP-specific controls let administrators scope what external AI agents connected through the Box MCP Server are allowed to do. Permissions can be set to allow file creation only in approved folders, block external sharing, and permit content moves only to specific directories.
Detection capabilities include prompt injection detection that validates every input before it reaches the model. The system detects known prompt injection patterns at the content layer, and organizations can configure responses to log, alert on, or block suspicious attempts. Agent activity oversight provides visibility into external AI agent behavior on customer content with threshold-based alerting.
Audit and human oversight features include agent audit trails and session governance with full session context, retention policies, and legal holds. Human-in-the-loop controls require approvals before agents execute sensitive or high-impact actions.
The Enterprise Bet
“83 percent of organizations are already experimenting with AI agents across their most critical tasks,” said Manoj Asnani, VP of AI Security, Privacy, Compliance & Governance Products at Box. “As these agentic workflows become more deeply embedded in the enterprise, it’s critical to create the proper security controls to ensure agents have what they need to function effectively, without accessing, modifying, or exposing content beyond the scope of its intended task.”
Amy Machado, Senior Research Director for Content and Knowledge Management Strategies at IDC, said Box’s approach addresses “the primary barriers of privacy and unauthorized access directly where the data lives,” according to the press release.
Nomura Research Institute, an early adopter, cited Box’s multi-vendor AI model support as a deciding factor. “We’ve found it extremely reassuring that Box offers multi-vendor support, allowing us to flexibly switch between AI models, while providing security management capabilities that span prevention, detection, and response,” said Tatsutoshi Murata, Head of IT Strategy at Nomura Research Institute.
Content Layer as Security Boundary
Box’s approach embeds agent governance at the content layer rather than at the model or application layer. Every agent action, whether from a Box-native agent or a third-party agent connected via MCP, passes through the same security controls that already govern human access to enterprise content. The controls do not require additional tools to deploy or manage.
The announcement extends Box Shield Pro, which launched earlier in 2026 to bring AI-powered security to enterprise content management. Shield Pro itself built on Box Shield, which debuted in 2019 with threat protection and data loss prevention.
Crowded Governance Market
Box enters an agent governance market that attracted significant capital in July 2026 alone. Israeli startup Neo emerged from stealth with $100M from Andreessen Horowitz and Bessemer Venture Partners to inventory and govern AI agents in enterprise environments. Google’s Gemini Enterprise Agent Platform introduced cryptographic agent identity at the hardware layer. Microsoft and Anthropic are also building competing agent governance stacks.
The differentiator for Box is positioning: it controls the content layer where enterprise documents, contracts, and records already live. Rather than building a standalone governance product, Box is extending existing access controls to cover agent interactions with the same content.
For enterprises running agents across content repositories, the question is whether governance should live at the content layer, the model layer, or the network layer. Box is betting on the first option.