Box adds AI agent controls for enterprise content access
Box is adding governance features for native and third-party AI agents, aiming to reduce security and compliance risk around sensitive files.
By Dominic Okoye · Staff Writer
· 3 min read
Box Inc. announced new security and governance controls for AI agents that interact with enterprise files, with rollout planned for customers on its Enterprise Advanced plan in the coming months. The company did not disclose pricing or any new revenue target tied to the release, but the move puts Box’s content security layer closer to the center of enterprise agent deployments.
The controls apply both to agents built inside Box and to external assistants connected to Box, including Anthropic’s Claude, OpenAI’s ChatGPT and Google’s Gemini. Box said the features operate where customer content is stored, rather than through a separate standalone product, so agent activity can be checked against file-level permissions and recorded.
Box is pitching the release at customers trying to move AI agents from limited tests into production workflows. That is the right pressure point for a content management vendor: agents become more useful when they can read, create, classify or modify business documents, but that also makes permissions, audit trails and data exposure a board-level problem in regulated companies.
Box cited its 2026 State of Enterprise AI report, in which 90% of surveyed IT leaders named security, regulatory and trust concerns as the main reason they are reluctant to let AI agents access company content. Manoj Asnani, Box’s vice president of AI security, privacy, compliance and governance products, said the controls are intended to let agents complete assigned tasks without reaching, changing or exposing content beyond their approved scope. He also said 83% of organizations are already testing AI agents on their most critical work.
What Box is adding
The new features include guardrails for custom Box agents that can restrict actions based on content sensitivity. Box said administrators will be able to use label-based access controls, require approval before deletion, and turn off external sharing for certain agent workflows.
Box is also adding prompt injection detection, which reviews inputs before they reach an AI model. The company said suspicious attempts can be logged, flagged through alerts or blocked. For third-party agents connected through the Box Model Context Protocol Server, administrators can set permissions such as limiting file creation to approved folders.
Additional controls include classification-based access rules that prevent agents from reading or searching tagged content, threshold alerts for external agent activity, session-level audit records and a human approval step for higher-risk actions.
Security as the agent adoption bottleneck
Box pointed to financial services, healthcare and legal customers as likely early users. The examples it gave include protecting merger analysis and trading information, securing patient data, and applying governance to contract and discovery work.
The announcement extends Box’s longer security push around enterprise content. The company launched Box Shield in 2019 and introduced Box Shield Pro late last year with agentic AI features for classification and threat detection.
Amy Machado, senior research director for content and knowledge management strategies at International Data Corp., said Box’s new controls address privacy and unauthorized-access concerns where enterprise data resides. That is also the strategic bet for Box: if agents become another interface for enterprise content, the vendor that owns the permissioning and audit layer has leverage beyond file storage.
This story draws on original reporting from SiliconANGLE.