Box unveils new controls to secure AI agents across enterprise content
Box announced new security capabilities for AI agents, including guardrails, prompt injection detection, and classification-based access policies, to secure enterprise content. The features address the 90% of IT leaders who cite security as a barrier to AI adoption, offering controls for both Box and third-party agents.

*this image is generated using AI for illustrative purposes only.
Box, Inc. announced new security capabilities designed to give organizations greater control over AI agents working with enterprise content. The new features, including agent guardrails, prompt injection detection, and classification-based access policies, extend Box's enterprise-grade security controls to both Box Agents and third-party agents such as Claude, ChatGPT, and Gemini. These capabilities aim to address the primary barriers to scaling AI, as 90% of IT leaders surveyed identified security, regulatory, and trust concerns as the biggest obstacle to granting AI agents access to enterprise content.
Addressing Enterprise Security Challenges
Box's 2026 State of Enterprise AI report highlights that security and privacy are the leading obstacles to deploying AI agents at scale. To mitigate these risks, Box has integrated protections directly at the content layer. This ensures that every agent action is intentional, permissioned, and auditable, allowing organizations to move from limited pilots to production-scale AI deployments without compromising governance. The controls are built to manage agents whether they are built in Box or connected through third-party platforms.
Key Security and Governance Capabilities
The new security and governance features do not require additional tools to deploy. They include several specific controls designed to manage agent behavior and data access:
| Capability | Function |
|---|---|
| Agent guardrails | Define what custom Box AI agents can do based on content sensitivity, enforcing label-based access controls and requiring approval for deletion actions. |
| Prompt injection detection | Validates every input before it reaches the model by detecting known prompt injection patterns at the content layer. |
| MCP guardrails | Allow admins to control external AI agents connected via the Box MCP Server with scoped permissions, such as blocking external sharing. |
| Classification-based access policies | Enable organizations to exclude content with specified classifications from being read or accessed by external or custom AI agents. |
| Agent activity oversight | Provide visibility into external AI agent activity and configure threshold-based alerts to detect suspicious behavior. |
| Agent audit trails | Retain compliance-ready records for every agent session with full session context, including retention policies. |
| Human-in-the-loop control | Require human approvals before agents execute sensitive or high-impact actions. |
Industry Adoption and Strategic Vision
The release of these controls aligns with a broader industry shift toward agentic AI. Manoj Asnani, VP of AI Security, Privacy, Compliance & Governance Products at Box, noted that 83% of organizations are already experimenting with AI agents. The new capabilities are intended to create a standard for deploying agents securely by ensuring they access only the data necessary for their specific tasks.
This focus on security complements the evolving technical landscape of AI deployment. Box CEO Aaron Levie has previously emphasized the efficiency of multi-model agent systems, where a frontier model acts as a planner and orchestrator alongside cheaper workhorse models. This strategy, which can result in significant cost improvements by reducing total token usage, relies on routing different models based on the stage of the task. By securing the content layer, Box's new controls provide the foundation necessary for enterprises to confidently adopt these complex, multi-model workflows.
Availability
Box's new security and governance capabilities for AI agents will be rolling out to customers on the E-Advanced plan in the coming months.
How will competitors in the content management space respond to Box's move to standardize security for third-party AI agents?
Will the requirement for an E-Advanced plan slow down the adoption of these security features among small-to-medium enterprises?
To what extent will these new guardrails influence regulatory frameworks regarding AI agent usage in highly regulated industries?


























