AI Agent News Today

Wednesday, September 23, 2026

Proofpoint launches an "agentic" data + AI security system

What changed: Proofpoint announced the Proofpoint Agentic Data and AI Security system — a single product that links agent intent with data access and runs three autonomous security agents (detection, investigation, remediation) to spot and act on risky agent behaviour in real time.

Why it matters: Security teams and buyers should treat agents as active system participants that need continuous, intent-aware controls rather than simple logging — this productized approach shows vendors are moving from model-only controls to run-time enforcement that can block or remediate agent actions before data or transactions are misused.

Try/watch: If you run or plan to allow agents that can access internal systems, add an agent-focused threat scenario to your tabletop exercises and ask vendors how their controls map policy (business rules) to enforced runtime blocks or approvals.

Palo Alto Networks adds continuous, agentic offensive testing via Unit 42

What changed: Palo Alto’s Unit 42 launched Continuous Frontier AI Defense, a subscription that uses gated frontier models (the release names Anthropic’s and OpenAI’s capability models) to run continuous offensive testing — finding, validating and accelerating remediation of exposures at machine speed.

Why it matters: Operators should expect adversary-style agent testing (agents that probe environments continuously) to become an enterprise service — that compresses vulnerability-to-exploit cycles and makes continuous validation part of a security maturity plan rather than a quarterly exercise. Buyers should ask how vendors separate human review from automated offensive actions and how findings integrate into ticketing and rollback workflows.

Try/watch: Pilot continuous offensive testing in a restricted environment first, define safe scopes and automated rollback rules, and insist on clear SLAs for false positives and human escalation paths.

Akamai warns CISOs to shift from identity to behavioural governance for nonhuman actors

What changed: Akamai published a State of the Internet security brief arguing enterprise risk is shifting toward governing autonomous nonhuman identities (agents), calling for adaptive edge governance, browser locking, and matching autonomy to verifiability. The report highlights model-driven exploit acceleration and recommends runtime edge controls.

Why it matters: Risk owners should update controls so the governance decision is based on how verifiable and reversible an agent’s action is — not just who initiated it — and prioritize edge-level mitigations that block risky agent actions while back-end fixes are deployed.

Try/watch: Add a nonhuman identity inventory to your asset register (which agents can act where) and pilot an edge filter that can throttle or sandbox agent traffic before full backend fixes are in place.

More News
Put an agent to work

Stop reading agent demos. Give one a job you repeat every week.

Describe the work, test the first result, and keep the agent available without running your own server.

Runs without your laptopBrowser + messaging appsCredits, keys, or subscriptionsMemory survives restarts

Plans start at $29/month. Cancel anytime.

Hosted agent

OpenClaw or Hermes

saved state
Browser
WhatsApp
Telegram
Slack
“I checked the inbox, handled the routine messages, and sent you the one question that needs a decision.”
Create an AI worker that keeps running after this tab closes.
Open Agent Teams