Box launches enterprise AI security and governance controls
Box announced a suite of security and governance features that give organizations tighter control over AI agents accessing corporate content. The controls apply to Box‑native agents and third‑party models such as Claude, ChatGPT and Gemini, and include: - Defining agent security boundaries based on content sensitivity and policy; - Detecting and blocking prompt‑injection attacks before they reach AI models; - Enforcing granular, classification‑based access policies and approval workflows for actions like file deletion or external sharing; - Monitoring agent activity with logs, alerts and audit trails to ensure visibility and compliance; - Supporting "human‑in‑the‑loop" checks for critical operations. Box cited its 2026 State of Enterprise AI report, which found 90 % of IT leaders view security, compliance and trust as the main obstacles to AI agent deployment, and said the new tools require no additional products. The announcement was made from Box’s Redwood City headquarters and its Munich office.