Why 90% of Enterprises Fear AI Agents (and the Fix)

Box's new AI security controls tackle the #1 enterprise barrier: 90% of IT leaders fear data exposure from AI agents. What CIOs need to evaluate now.

By Rajesh Beri·July 24, 2026·9 min read
Share:
THE DAILY BRIEF
AI SecurityEnterprise AIAI AgentsData GovernanceCIO Strategy
Why 90% of Enterprises Fear AI Agents (and the Fix)

Box's new AI security controls tackle the #1 enterprise barrier: 90% of IT leaders fear data exposure from AI agents. What CIOs need to evaluate now.

By Rajesh Beri·July 24, 2026·9 min read

Eighty-three percent of organizations are already experimenting with AI agents on their most critical business tasks. Yet 90% of IT leaders say security concerns are the single biggest reason they haven't given those agents real access to enterprise content. That gap — between what AI agents could do and what enterprises will actually let them do — is the defining problem of enterprise AI in 2026.

Box moved to close that gap this week. On July 22, the company unveiled a comprehensive set of security and governance controls specifically designed for AI agents accessing enterprise content — covering everything from input validation before prompts hit an AI model, to human-in-the-loop approvals before agents execute sensitive actions. The capabilities work whether the agent in question is a Box-native agent or a third-party system running Claude, ChatGPT, or Gemini.

This isn't a feature announcement. It's a response to the single question blocking enterprise AI at scale: Can we let AI agents near our most sensitive data without losing control?

The 90% Problem Is Real — and Getting Worse

Gartner issued a stark warning last year that deserves a second read: more than 40% of agentic AI projects will be canceled by the end of 2027. The reasons cited weren't model capability or cost. They were governance failures — unclear business value, inadequate risk controls, and the operational discipline gaps that show up once an agent moves from demo to production.

Box's own 2026 State of Enterprise AI report put numbers on exactly where that governance gap lives. Among IT leaders surveyed, 90% identified security, regulatory, and trust concerns as the biggest barrier to granting AI agents access to enterprise content. That's not a fringe concern. It's a supermajority of the people responsible for deploying these systems saying they are not comfortable unlocking the data access AI agents need to deliver real value.

The tension is self-reinforcing. Without access to real data, agents operate on synthetic or sanitized inputs and produce generic outputs. Leaders don't see ROI. Projects stall or get canceled. The 40% cancellation rate Gartner is projecting won't come from bad models — it'll come from organizations that couldn't build the trust infrastructure to let good models do actual work.

What Box Just Built — and Why It Matters

The seven capabilities Box announced are worth understanding in detail, because they collectively describe what enterprise-grade AI agent security actually looks like in practice.

Agent Guardrails define precisely what a custom AI agent can and cannot do, based on content sensitivity and organizational policy. This includes enforcing label-based access controls, requiring human approval before any deletion actions, and blocking external sharing by default. In practice, this means an AI agent running contract analysis can be configured to read legal files but never forward them, modify them, or route them outside the organization.

Prompt Injection Detection validates every input before it reaches the AI model. Prompt injection — where malicious instructions embedded in content attempt to hijack an agent's behavior — is one of the more technically sophisticated risks in production agentic systems. Box is detecting these patterns at the content layer, before any payload reaches the model, with the ability to log, alert, or block suspicious attempts.

MCP Guardrails address a newer attack surface: external AI agents connecting through the Model Context Protocol. As more organizations build agent ecosystems with multiple models and third-party integrations, controlling what those connected agents can access becomes critical. Box's MCP guardrails scope permissions granularly — for example, allowing file creation only in approved folders, permitting content moves only to specific destinations, and blocking all external sharing by default.

Classification-Based Access Policies let organizations exclude entire categories of sensitive content from AI access entirely. Content tagged as restricted, confidential, or regulated can be excluded from AI agent read, search, or access operations — regardless of whether the agent is native or third-party.

Agent Activity Oversight provides real-time visibility into what external AI agents are doing with enterprise content, with threshold-based alerts to flag anomalous behavior. This is the equivalent of a SIEM for agent activity — continuous monitoring rather than point-in-time review.

Audit Trails and Session Governance retain complete records of every agent session, including full context, retention policies, and legal holds. For organizations in regulated industries, this isn't optional — it's the difference between an AI agent deployment that can survive a compliance review and one that can't.

Human-in-the-Loop Controls require human approvals before agents execute sensitive or high-impact actions. This is the final backstop: for anything above a configurable risk threshold, an agent cannot proceed without a human sign-off.

What This Looks Like in Your Industry

Box's announcement specifically calls out four enterprise verticals, and the specificity is worth noting because the risks — and the required controls — vary meaningfully by industry.

Financial services firms handling M&A analysis, trading information, or client financial data operate under strict insider trading and data handling regulations. An AI agent with broad access to deal documents and real-time pricing data creates obvious exposure. Agent guardrails that enforce document-level access controls and audit trails that capture every query become table stakes.

Healthcare organizations face HIPAA requirements that extend to AI systems accessing protected health information. Classification-based access policies that exclude PHI from AI agent reach — while still allowing agents to process de-identified or operational data — create a workable path to AI productivity without regulatory exposure.

Law firms running AI on discovery or contract review workflows need demonstrable control over what the agent accessed and why. Complete session governance with legal holds maps directly to e-discovery requirements and client confidentiality obligations.

Insurance companies processing claims data and policyholder records need both prompt injection protection (claims documents are a natural target for injection attempts) and strict classification policies that prevent AI agents from accessing regulatory-sensitive records outside defined workflows.

The pattern across all four is the same: organizations can't unlock AI agent productivity on sensitive data until they can answer the question "what did the agent touch, when, and why?" Box's controls are designed to make that question answerable.

The Bigger Picture for CIOs

The strategic shift Box is making — and that enterprise AI buyers should internalize — is moving AI security from a point tool problem to an infrastructure layer problem.

The traditional approach to AI security involves adding controls on top of existing systems after deployment. You build the agent, integrate the data, get to production, and then figure out monitoring. That sequence fails at enterprise scale because the controls become afterthoughts that don't map cleanly to the data structures, permission models, or workflow states that actually govern how the agent operates.

Box's approach inverts this. Security is built into the content platform where enterprise data already lives. Because Box already knows the classification of every document, the permissions of every user, and the audit requirements of every workflow, agent controls can be applied at the layer where the data actually sits — not bolted on top of an agent framework that doesn't know any of that context.

For CIOs evaluating AI agent strategies, this distinction matters enormously. The question isn't just "which agent platform should we use?" It's "where does our agent security model live, and does it have the context to enforce meaningful policy?"

A few practical questions worth putting to any AI agent vendor or integration partner:

What happens when a prompt contains an instruction that contradicts our data access policy? A system without prompt injection detection at the content layer will pass that instruction to the model and hope the model rejects it. That's not a governance strategy.

Can our compliance team pull a complete record of every document an agent accessed during a specific workflow? If the answer requires correlating logs from three different systems, your audit posture is fragile.

How do we enforce that an agent running Gemini follows the same data access rules as an agent running Claude? The answer can't be "we trust the vendor." It has to be enforceable controls at the data layer.

The Market Moment

What Box is responding to is a specific phase in the enterprise AI adoption cycle: the moment when organizations that have been running pilots want to go to production, and discover that the governance scaffolding they need doesn't exist yet.

That transition — from pilot to production — is where Gartner's 40% cancellation rate will be minted. The projects that fail won't fail because the models weren't capable. They'll fail because security teams couldn't approve access to real data, compliance couldn't sign off on audit trails that didn't exist, and legal couldn't approve agents executing actions without human oversight.

Nomura Research Institute articulated the enterprise need directly in Box's announcement: the ability to flexibly switch between AI models while maintaining security management capabilities that span prevention, detection, and response. That framing is worth keeping. Enterprise AI buyers don't want to be locked into a single model vendor, but they do want consistent security controls regardless of which model an agent is running. That's a governance problem, not a model problem.

Organizations that solve the governance problem — that build the trust infrastructure that lets AI agents access real data under real policy controls — will unlock compounding productivity gains. Organizations that don't will keep running pilots on sanitized data and wondering why the ROI case doesn't close.

The Bottom Line

The 90% security barrier to enterprise AI agents isn't a technology problem. It's an architecture problem. Enterprises don't lack AI models capable of doing the work. They lack the control infrastructure that makes it safe to let those models near the data that makes the work valuable.

Box's new controls establish one model for what that infrastructure looks like: security enforced at the content layer, with agent-specific guardrails, prompt injection detection, classification-based policies, complete audit trails, and human-in-the-loop oversight for high-risk actions. Whether you use Box or not, this is the checklist your CISO will ask for before signing off on any production AI agent deployment.

The enterprise AI winners in 2026 won't be the ones who picked the best model. They'll be the ones who built the trust infrastructure that let a good model do real work.


What's your enterprise's biggest blocker to AI agent deployment — is it security controls, data governance, or something else? Connect on LinkedIn or X/Twitter and let's talk enterprise AI strategy.

THE DAILY BRIEF

Enterprise AI insights for technology and business leaders, twice weekly.

beri.net

Subscribe at beri.net/subscribe for twice-weekly AI insights delivered to your inbox.

LinkedIn: linkedin.com/in/rberi  |  X: x.com/rajeshberi

© 2026 Rajesh Beri. All rights reserved.

Why 90% of Enterprises Fear AI Agents (and the Fix)

Photo by Pixabay on Pexels

Eighty-three percent of organizations are already experimenting with AI agents on their most critical business tasks. Yet 90% of IT leaders say security concerns are the single biggest reason they haven't given those agents real access to enterprise content. That gap — between what AI agents could do and what enterprises will actually let them do — is the defining problem of enterprise AI in 2026.

Box moved to close that gap this week. On July 22, the company unveiled a comprehensive set of security and governance controls specifically designed for AI agents accessing enterprise content — covering everything from input validation before prompts hit an AI model, to human-in-the-loop approvals before agents execute sensitive actions. The capabilities work whether the agent in question is a Box-native agent or a third-party system running Claude, ChatGPT, or Gemini.

This isn't a feature announcement. It's a response to the single question blocking enterprise AI at scale: Can we let AI agents near our most sensitive data without losing control?

The 90% Problem Is Real — and Getting Worse

Gartner issued a stark warning last year that deserves a second read: more than 40% of agentic AI projects will be canceled by the end of 2027. The reasons cited weren't model capability or cost. They were governance failures — unclear business value, inadequate risk controls, and the operational discipline gaps that show up once an agent moves from demo to production.

Box's own 2026 State of Enterprise AI report put numbers on exactly where that governance gap lives. Among IT leaders surveyed, 90% identified security, regulatory, and trust concerns as the biggest barrier to granting AI agents access to enterprise content. That's not a fringe concern. It's a supermajority of the people responsible for deploying these systems saying they are not comfortable unlocking the data access AI agents need to deliver real value.

The tension is self-reinforcing. Without access to real data, agents operate on synthetic or sanitized inputs and produce generic outputs. Leaders don't see ROI. Projects stall or get canceled. The 40% cancellation rate Gartner is projecting won't come from bad models — it'll come from organizations that couldn't build the trust infrastructure to let good models do actual work.

What Box Just Built — and Why It Matters

The seven capabilities Box announced are worth understanding in detail, because they collectively describe what enterprise-grade AI agent security actually looks like in practice.

Agent Guardrails define precisely what a custom AI agent can and cannot do, based on content sensitivity and organizational policy. This includes enforcing label-based access controls, requiring human approval before any deletion actions, and blocking external sharing by default. In practice, this means an AI agent running contract analysis can be configured to read legal files but never forward them, modify them, or route them outside the organization.

Prompt Injection Detection validates every input before it reaches the AI model. Prompt injection — where malicious instructions embedded in content attempt to hijack an agent's behavior — is one of the more technically sophisticated risks in production agentic systems. Box is detecting these patterns at the content layer, before any payload reaches the model, with the ability to log, alert, or block suspicious attempts.

MCP Guardrails address a newer attack surface: external AI agents connecting through the Model Context Protocol. As more organizations build agent ecosystems with multiple models and third-party integrations, controlling what those connected agents can access becomes critical. Box's MCP guardrails scope permissions granularly — for example, allowing file creation only in approved folders, permitting content moves only to specific destinations, and blocking all external sharing by default.

Classification-Based Access Policies let organizations exclude entire categories of sensitive content from AI access entirely. Content tagged as restricted, confidential, or regulated can be excluded from AI agent read, search, or access operations — regardless of whether the agent is native or third-party.

Agent Activity Oversight provides real-time visibility into what external AI agents are doing with enterprise content, with threshold-based alerts to flag anomalous behavior. This is the equivalent of a SIEM for agent activity — continuous monitoring rather than point-in-time review.

Audit Trails and Session Governance retain complete records of every agent session, including full context, retention policies, and legal holds. For organizations in regulated industries, this isn't optional — it's the difference between an AI agent deployment that can survive a compliance review and one that can't.

Human-in-the-Loop Controls require human approvals before agents execute sensitive or high-impact actions. This is the final backstop: for anything above a configurable risk threshold, an agent cannot proceed without a human sign-off.

What This Looks Like in Your Industry

Box's announcement specifically calls out four enterprise verticals, and the specificity is worth noting because the risks — and the required controls — vary meaningfully by industry.

Financial services firms handling M&A analysis, trading information, or client financial data operate under strict insider trading and data handling regulations. An AI agent with broad access to deal documents and real-time pricing data creates obvious exposure. Agent guardrails that enforce document-level access controls and audit trails that capture every query become table stakes.

Healthcare organizations face HIPAA requirements that extend to AI systems accessing protected health information. Classification-based access policies that exclude PHI from AI agent reach — while still allowing agents to process de-identified or operational data — create a workable path to AI productivity without regulatory exposure.

Law firms running AI on discovery or contract review workflows need demonstrable control over what the agent accessed and why. Complete session governance with legal holds maps directly to e-discovery requirements and client confidentiality obligations.

Insurance companies processing claims data and policyholder records need both prompt injection protection (claims documents are a natural target for injection attempts) and strict classification policies that prevent AI agents from accessing regulatory-sensitive records outside defined workflows.

The pattern across all four is the same: organizations can't unlock AI agent productivity on sensitive data until they can answer the question "what did the agent touch, when, and why?" Box's controls are designed to make that question answerable.

The Bigger Picture for CIOs

The strategic shift Box is making — and that enterprise AI buyers should internalize — is moving AI security from a point tool problem to an infrastructure layer problem.

The traditional approach to AI security involves adding controls on top of existing systems after deployment. You build the agent, integrate the data, get to production, and then figure out monitoring. That sequence fails at enterprise scale because the controls become afterthoughts that don't map cleanly to the data structures, permission models, or workflow states that actually govern how the agent operates.

Box's approach inverts this. Security is built into the content platform where enterprise data already lives. Because Box already knows the classification of every document, the permissions of every user, and the audit requirements of every workflow, agent controls can be applied at the layer where the data actually sits — not bolted on top of an agent framework that doesn't know any of that context.

For CIOs evaluating AI agent strategies, this distinction matters enormously. The question isn't just "which agent platform should we use?" It's "where does our agent security model live, and does it have the context to enforce meaningful policy?"

A few practical questions worth putting to any AI agent vendor or integration partner:

What happens when a prompt contains an instruction that contradicts our data access policy? A system without prompt injection detection at the content layer will pass that instruction to the model and hope the model rejects it. That's not a governance strategy.

Can our compliance team pull a complete record of every document an agent accessed during a specific workflow? If the answer requires correlating logs from three different systems, your audit posture is fragile.

How do we enforce that an agent running Gemini follows the same data access rules as an agent running Claude? The answer can't be "we trust the vendor." It has to be enforceable controls at the data layer.

The Market Moment

What Box is responding to is a specific phase in the enterprise AI adoption cycle: the moment when organizations that have been running pilots want to go to production, and discover that the governance scaffolding they need doesn't exist yet.

That transition — from pilot to production — is where Gartner's 40% cancellation rate will be minted. The projects that fail won't fail because the models weren't capable. They'll fail because security teams couldn't approve access to real data, compliance couldn't sign off on audit trails that didn't exist, and legal couldn't approve agents executing actions without human oversight.

Nomura Research Institute articulated the enterprise need directly in Box's announcement: the ability to flexibly switch between AI models while maintaining security management capabilities that span prevention, detection, and response. That framing is worth keeping. Enterprise AI buyers don't want to be locked into a single model vendor, but they do want consistent security controls regardless of which model an agent is running. That's a governance problem, not a model problem.

Organizations that solve the governance problem — that build the trust infrastructure that lets AI agents access real data under real policy controls — will unlock compounding productivity gains. Organizations that don't will keep running pilots on sanitized data and wondering why the ROI case doesn't close.

The Bottom Line

The 90% security barrier to enterprise AI agents isn't a technology problem. It's an architecture problem. Enterprises don't lack AI models capable of doing the work. They lack the control infrastructure that makes it safe to let those models near the data that makes the work valuable.

Box's new controls establish one model for what that infrastructure looks like: security enforced at the content layer, with agent-specific guardrails, prompt injection detection, classification-based policies, complete audit trails, and human-in-the-loop oversight for high-risk actions. Whether you use Box or not, this is the checklist your CISO will ask for before signing off on any production AI agent deployment.

The enterprise AI winners in 2026 won't be the ones who picked the best model. They'll be the ones who built the trust infrastructure that let a good model do real work.


What's your enterprise's biggest blocker to AI agent deployment — is it security controls, data governance, or something else? Connect on LinkedIn or X/Twitter and let's talk enterprise AI strategy.

Share:
THE DAILY BRIEF
AI SecurityEnterprise AIAI AgentsData GovernanceCIO Strategy
Why 90% of Enterprises Fear AI Agents (and the Fix)

Box's new AI security controls tackle the #1 enterprise barrier: 90% of IT leaders fear data exposure from AI agents. What CIOs need to evaluate now.

By Rajesh Beri·July 24, 2026·9 min read

Eighty-three percent of organizations are already experimenting with AI agents on their most critical business tasks. Yet 90% of IT leaders say security concerns are the single biggest reason they haven't given those agents real access to enterprise content. That gap — between what AI agents could do and what enterprises will actually let them do — is the defining problem of enterprise AI in 2026.

Box moved to close that gap this week. On July 22, the company unveiled a comprehensive set of security and governance controls specifically designed for AI agents accessing enterprise content — covering everything from input validation before prompts hit an AI model, to human-in-the-loop approvals before agents execute sensitive actions. The capabilities work whether the agent in question is a Box-native agent or a third-party system running Claude, ChatGPT, or Gemini.

This isn't a feature announcement. It's a response to the single question blocking enterprise AI at scale: Can we let AI agents near our most sensitive data without losing control?

The 90% Problem Is Real — and Getting Worse

Gartner issued a stark warning last year that deserves a second read: more than 40% of agentic AI projects will be canceled by the end of 2027. The reasons cited weren't model capability or cost. They were governance failures — unclear business value, inadequate risk controls, and the operational discipline gaps that show up once an agent moves from demo to production.

Box's own 2026 State of Enterprise AI report put numbers on exactly where that governance gap lives. Among IT leaders surveyed, 90% identified security, regulatory, and trust concerns as the biggest barrier to granting AI agents access to enterprise content. That's not a fringe concern. It's a supermajority of the people responsible for deploying these systems saying they are not comfortable unlocking the data access AI agents need to deliver real value.

The tension is self-reinforcing. Without access to real data, agents operate on synthetic or sanitized inputs and produce generic outputs. Leaders don't see ROI. Projects stall or get canceled. The 40% cancellation rate Gartner is projecting won't come from bad models — it'll come from organizations that couldn't build the trust infrastructure to let good models do actual work.

What Box Just Built — and Why It Matters

The seven capabilities Box announced are worth understanding in detail, because they collectively describe what enterprise-grade AI agent security actually looks like in practice.

Agent Guardrails define precisely what a custom AI agent can and cannot do, based on content sensitivity and organizational policy. This includes enforcing label-based access controls, requiring human approval before any deletion actions, and blocking external sharing by default. In practice, this means an AI agent running contract analysis can be configured to read legal files but never forward them, modify them, or route them outside the organization.

Prompt Injection Detection validates every input before it reaches the AI model. Prompt injection — where malicious instructions embedded in content attempt to hijack an agent's behavior — is one of the more technically sophisticated risks in production agentic systems. Box is detecting these patterns at the content layer, before any payload reaches the model, with the ability to log, alert, or block suspicious attempts.

MCP Guardrails address a newer attack surface: external AI agents connecting through the Model Context Protocol. As more organizations build agent ecosystems with multiple models and third-party integrations, controlling what those connected agents can access becomes critical. Box's MCP guardrails scope permissions granularly — for example, allowing file creation only in approved folders, permitting content moves only to specific destinations, and blocking all external sharing by default.

Classification-Based Access Policies let organizations exclude entire categories of sensitive content from AI access entirely. Content tagged as restricted, confidential, or regulated can be excluded from AI agent read, search, or access operations — regardless of whether the agent is native or third-party.

Agent Activity Oversight provides real-time visibility into what external AI agents are doing with enterprise content, with threshold-based alerts to flag anomalous behavior. This is the equivalent of a SIEM for agent activity — continuous monitoring rather than point-in-time review.

Audit Trails and Session Governance retain complete records of every agent session, including full context, retention policies, and legal holds. For organizations in regulated industries, this isn't optional — it's the difference between an AI agent deployment that can survive a compliance review and one that can't.

Human-in-the-Loop Controls require human approvals before agents execute sensitive or high-impact actions. This is the final backstop: for anything above a configurable risk threshold, an agent cannot proceed without a human sign-off.

What This Looks Like in Your Industry

Box's announcement specifically calls out four enterprise verticals, and the specificity is worth noting because the risks — and the required controls — vary meaningfully by industry.

Financial services firms handling M&A analysis, trading information, or client financial data operate under strict insider trading and data handling regulations. An AI agent with broad access to deal documents and real-time pricing data creates obvious exposure. Agent guardrails that enforce document-level access controls and audit trails that capture every query become table stakes.

Healthcare organizations face HIPAA requirements that extend to AI systems accessing protected health information. Classification-based access policies that exclude PHI from AI agent reach — while still allowing agents to process de-identified or operational data — create a workable path to AI productivity without regulatory exposure.

Law firms running AI on discovery or contract review workflows need demonstrable control over what the agent accessed and why. Complete session governance with legal holds maps directly to e-discovery requirements and client confidentiality obligations.

Insurance companies processing claims data and policyholder records need both prompt injection protection (claims documents are a natural target for injection attempts) and strict classification policies that prevent AI agents from accessing regulatory-sensitive records outside defined workflows.

The pattern across all four is the same: organizations can't unlock AI agent productivity on sensitive data until they can answer the question "what did the agent touch, when, and why?" Box's controls are designed to make that question answerable.

The Bigger Picture for CIOs

The strategic shift Box is making — and that enterprise AI buyers should internalize — is moving AI security from a point tool problem to an infrastructure layer problem.

The traditional approach to AI security involves adding controls on top of existing systems after deployment. You build the agent, integrate the data, get to production, and then figure out monitoring. That sequence fails at enterprise scale because the controls become afterthoughts that don't map cleanly to the data structures, permission models, or workflow states that actually govern how the agent operates.

Box's approach inverts this. Security is built into the content platform where enterprise data already lives. Because Box already knows the classification of every document, the permissions of every user, and the audit requirements of every workflow, agent controls can be applied at the layer where the data actually sits — not bolted on top of an agent framework that doesn't know any of that context.

For CIOs evaluating AI agent strategies, this distinction matters enormously. The question isn't just "which agent platform should we use?" It's "where does our agent security model live, and does it have the context to enforce meaningful policy?"

A few practical questions worth putting to any AI agent vendor or integration partner:

What happens when a prompt contains an instruction that contradicts our data access policy? A system without prompt injection detection at the content layer will pass that instruction to the model and hope the model rejects it. That's not a governance strategy.

Can our compliance team pull a complete record of every document an agent accessed during a specific workflow? If the answer requires correlating logs from three different systems, your audit posture is fragile.

How do we enforce that an agent running Gemini follows the same data access rules as an agent running Claude? The answer can't be "we trust the vendor." It has to be enforceable controls at the data layer.

The Market Moment

What Box is responding to is a specific phase in the enterprise AI adoption cycle: the moment when organizations that have been running pilots want to go to production, and discover that the governance scaffolding they need doesn't exist yet.

That transition — from pilot to production — is where Gartner's 40% cancellation rate will be minted. The projects that fail won't fail because the models weren't capable. They'll fail because security teams couldn't approve access to real data, compliance couldn't sign off on audit trails that didn't exist, and legal couldn't approve agents executing actions without human oversight.

Nomura Research Institute articulated the enterprise need directly in Box's announcement: the ability to flexibly switch between AI models while maintaining security management capabilities that span prevention, detection, and response. That framing is worth keeping. Enterprise AI buyers don't want to be locked into a single model vendor, but they do want consistent security controls regardless of which model an agent is running. That's a governance problem, not a model problem.

Organizations that solve the governance problem — that build the trust infrastructure that lets AI agents access real data under real policy controls — will unlock compounding productivity gains. Organizations that don't will keep running pilots on sanitized data and wondering why the ROI case doesn't close.

The Bottom Line

The 90% security barrier to enterprise AI agents isn't a technology problem. It's an architecture problem. Enterprises don't lack AI models capable of doing the work. They lack the control infrastructure that makes it safe to let those models near the data that makes the work valuable.

Box's new controls establish one model for what that infrastructure looks like: security enforced at the content layer, with agent-specific guardrails, prompt injection detection, classification-based policies, complete audit trails, and human-in-the-loop oversight for high-risk actions. Whether you use Box or not, this is the checklist your CISO will ask for before signing off on any production AI agent deployment.

The enterprise AI winners in 2026 won't be the ones who picked the best model. They'll be the ones who built the trust infrastructure that let a good model do real work.


What's your enterprise's biggest blocker to AI agent deployment — is it security controls, data governance, or something else? Connect on LinkedIn or X/Twitter and let's talk enterprise AI strategy.

THE DAILY BRIEF

Enterprise AI insights for technology and business leaders, twice weekly.

beri.net

Subscribe at beri.net/subscribe for twice-weekly AI insights delivered to your inbox.

LinkedIn: linkedin.com/in/rberi  |  X: x.com/rajeshberi

© 2026 Rajesh Beri. All rights reserved.

Newsletter

Stay Ahead of the Curve

Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.

Subscribe