Back to blogs

September 12, 2026

The Agent That Can't Act: What Proofpoint's Bounded-Autonomy Bet Means for Enterprise AI Security

AI agentscybersecurityenterprise AIAI governanceSOC automation
The Agent That Can't Act: What Proofpoint's Bounded-Autonomy Bet Means for Enterprise AI Security

If your enterprise deploys a security agent this quarter, there’s a decent chance it will be very good at one thing and explicitly, deliberately bad at another: it will investigate faster than any analyst on your team, and it will not be allowed to touch a single system on its own. That is not a limitation vendors are apologizing for. It is the pitch.

On September 3, 2026, Proofpoint introduced its SOC Analyst Agent, an agentic AI built on OpenAI’s Daybreak cyber models that can plan an investigation, pull context from alerts, logs, DLP events, and user risk signals across Proofpoint’s products, and hand an analyst a structured, traceable finding in natural language. It is also, by design, unable to make an account change, contain a threat, or take any other consequential remediation action on its own. That gap between what the agent can figure out and what it’s allowed to do isn’t a rough edge to be smoothed over in the next release. It’s the whole design philosophy, and it tells you something important about where enterprise AI security is actually heading in late 2026.

This post looks at why vendors are placing this bet, what the data says about whether it’s justified, and whether the loudest critics — who argue human-in-the-loop is already too slow to matter — have a point your organization needs to plan around.

The Bounded Autonomy Bet

Proofpoint’s framing is unusually direct about what its agent won’t do. Daniel Rapp, the company’s Chief Data and AI Officer, has described the goal as keeping people in control of consequential security decisions, with every finding traceable back to the underlying source data so an analyst can validate a recommendation before acting on it. The agent is entering private preview with select beta customers now, with general availability targeted for the end of Q3 2026. It’s also notable as the first product to come out of Proofpoint’s membership in OpenAI’s Daybreak Defense Network, a partnership structure OpenAI built specifically to get its cyber-tuned models into working security products rather than general-purpose deployments.

This isn’t a one-vendor quirk. It’s the leading edge of a broader shift in how security-focused AI companies are structuring their products, and their partner ecosystems, around the idea that autonomy has to be earned in stages rather than granted by default.

Why the Whole Ecosystem Is Moving the Same Direction

A week earlier, on August 31, CrowdStrike launched an AI Partner Specialization inside its Accelerate Partner Program, built around what it calls securing the “agentic enterprise.” The specialization defines four distinct partner pathways: Resell, for accelerating adoption through Falcon Flex; Manage, for delivering CrowdStrike AI as a managed service; Build, for partners developing their own agents on the Falcon platform through Charlotte AI AgentWorks and Falcon Foundry; and Deliver, for systems integrators running full agentic AI transformations for customers.

What’s notable isn’t the channel mechanics — it’s the premise underneath them. CrowdStrike’s own messaging argues that security has to be “foundational” to the entire AI stack an enterprise is building, not bolted on after agents are already running in production. That’s a tacit admission that most organizations got the deployment order backwards the first time, a pattern our earlier look at why AI agents are outnumbering employees 144 to 1 covered in more detail. When the agent population outpaces the identity and access controls meant to govern it, the industry’s response isn’t to slow deployment — it’s to build products that stay useful even while those controls catch up. Bounded autonomy is that answer, productized.

The Confidence Gap Behind the Caution

The caution is justified by the numbers. Gravitee’s State of AI Agent Security 2026 report, based on a survey of more than 900 executives and technical practitioners published in February 2026, found that 88% of organizations had experienced a confirmed or suspected AI agent security incident in the prior year — a figure that climbed to 92.7% in healthcare specifically. Despite that, only 47.1% of an organization’s AI agents, on average, were being actively monitored or secured at all.

The gap that should worry security leaders most, though, is the one between perception and reality: 82% of executives told Gravitee they were confident their existing policies protected them from unauthorized agent actions, even as the same survey found only 14.4% of organizations had achieved full security and IT approval across their entire agent fleet before deployment, and just 21.9% of teams treated AI agents as independent, identity-bearing entities with their own access controls rather than sharing credentials across them. That combination — high confidence, low actual coverage — is precisely the environment our earlier piece on AI agent sprawl warned was becoming the default state of enterprise AI deployment. Against that backdrop, an agent that is architecturally incapable of taking a destructive action isn’t overly cautious product design. It’s a hedge against exactly the confidence gap the data describes.

The Counter-Argument: Is Human-in-the-Loop Already Failing?

Not everyone thinks bounded autonomy is a durable answer, and the pushback is worth taking seriously. In a recent TechTarget analysis, Forrester analyst Jess Burn questioned whether an analyst rubber-stamping hundreds of AI-generated decisions a day, often without the expertise to meaningfully evaluate each one, constitutes real oversight or what she called “accountability theater.” Nathan Hamiel of Kudelski Security made a similar point: human review can quietly become a mechanism for assigning blame after something goes wrong rather than a control that actually prevents it. Microsoft’s principal for AI red team operations, Victoria Westeroff, added that as organizations move from single agents to multi-agent systems, the volume and complexity of data a human reviewer would need to parse to catch a bad decision “gets really, really complex” — fast enough that meaningful review may not scale at all.

The scale problem underlying all of this is real: Gartner projects that the average Fortune 500 enterprise, which ran fewer than 15 agents in 2025, will be running more than 150,000 by 2028. If that trajectory holds even loosely, a model where every consequential action waits on a human reviewer becomes a bottleneck long before it becomes a security guarantee — the same operational tension our piece on the AI SRE agent shift found reshaping on-call engineering, where approvers are increasingly rubber-stamping AI-generated remediation plans they didn’t have time to independently verify.

What Good Oversight Actually Requires

The honest synthesis of these two positions isn’t “autonomy” versus “human-in-the-loop” as a binary choice — it’s that not all human review is equal. The organizations getting real value out of bounded-autonomy agents tend to share three practices: tiering autonomy by risk rather than applying one policy everywhere (letting agents act freely on low-stakes triage while gating anything touching production or accounts), building comprehensive audit trails that make a reviewer’s decision auditable after the fact rather than just logged, and treating agent identities as distinct, provisioned, and decommissionable rather than sharing credentials across a fleet — the same identity discipline gap that’s fueling the market our AI-SPM funding surge coverage tracked earlier this year. A “human-in-the-loop” checkbox without those three things in place is closer to Burn’s accountability theater than to actual security.

What This Means for Your Organization

If you’re evaluating agentic AI security tools this quarter, the Proofpoint and CrowdStrike moves suggest a practical framework rather than a marketing claim to take at face value:

  • Ask what the agent is architecturally prevented from doing, not just what it’s configured not to do by default. Configuration can be changed by a misclick or a compromised admin account; architectural limits can’t.
  • Demand traceability, not just a summary. A finding that links back to the raw source data lets a reviewer check the agent’s work instead of trusting its confidence score.
  • Tier your rollout by consequence. Investigation, triage, and reporting are reasonable places to grant autonomy quickly. Account changes, containment, and remediation are not — not until your identity and audit infrastructure can back that decision up.
  • Measure the coverage gap, not just the incident count. Gravitee’s finding that under half of deployed agents are actively monitored is the number to fix first; it’s a leading indicator, not a trailing one.

Bounded autonomy isn’t the finish line for enterprise AI security — it’s a deliberately conservative starting position while the identity, audit, and governance infrastructure catches up to what agents are already capable of doing. The vendors betting on it now aren’t being timid. They’re betting that the enterprises buying these tools aren’t ready for anything more, and the data on incident rates and identity coverage suggests they’re right, for now.

Frequently Asked Questions

What does it mean for an AI security agent to have “bounded autonomy”?

It means the agent can perform analysis, investigation, and reasoning tasks independently, but is architecturally prevented from taking consequential actions — like changing an account, quarantining a device, or blocking traffic — without explicit human approval. The restriction is built into the product, not just configured as a policy setting.

Is Proofpoint’s SOC Analyst Agent available now?

It’s in private preview with select beta customers as of September 2026, with general availability targeted for the end of Q3 2026.

Why are security vendors choosing to limit their agents’ autonomy right now?

Survey data shows a large gap between how confident executives are in their AI governance and how much of their actual agent fleet is monitored, secured, or formally approved before deployment. Limiting autonomy is a way to ship useful AI now without waiting for that identity and governance infrastructure to fully mature.

Isn’t human-in-the-loop review enough to keep AI agents safe?

Critics argue it isn’t sufficient on its own at scale — reviewing large volumes of AI-generated decisions can become a rubber stamp rather than genuine oversight, especially as enterprises move from single agents to complex multi-agent systems. Most experts recommend pairing human review with risk-based tiering, audit trails, and proper agent identity management rather than relying on review alone.

What should enterprises look for when buying an “agentic” security product?

Look for architectural limits on consequential actions (not just default settings), traceability back to source data for every finding, autonomy tiered by risk level, and vendor support for treating each agent as its own identity with its own access controls and audit trail.

How big is the AI agent security problem right now?

A February 2026 survey of over 900 security professionals found 88% of organizations had experienced a confirmed or suspected AI agent security incident in the prior year, while on average less than half of deployed agents were being actively monitored or secured.

Sources

Have a project like this in mind?

Tell us what you're building — we'll help you scope it and ship it.

Talk to us

Keep reading

Promact team

We are a family of Promactians

We are an excellence-driven company passionate about technology where people love what they do.

Get opportunities to co-create, connect and celebrate!

Join Us

Vadodara

Headquarter

B-301, Monalisa Business Center, Manjalpur, Vadodara, Gujarat, India - 390011

+91 (932)-703-1275

Pune

46 Downtown, 805+806, Pashan-Sus Link Road, Near Audi Showroom, Baner, Pune, Maharashtra, India - 411045

USA

4056, 1207 Delaware Ave, Wilmington, DE, United States America, US, 19806

+1 (765)-305-4030
Promact global office locations on world map