Box introduces new security controls for AI agents accessing content on the cloud platform. From now on, access rights, prompt inputs, and permissions for both internal and external agents like Claude, ChatGPT, and Gemini can be specifically managed. According to a company survey, 90 percent of IT decision-makers cite security concerns as the biggest hurdle for productive agent deployment.
Guardrails regulate access, inputs, and permissions
Box integrates the controls directly into the existing platform, with no additional tools required. According to an official statement, Box summarizes seven components:
- Agent guardrails: determine, depending on the confidentiality level, whether an agent is allowed to read, share, or delete files.
- Prompt injection detection: checks inputs before processing and blocks or logs suspicious instructions.
- MCP guardrails: limit which tools externally connected agents can use via the Model Context Protocol.
- Classification-based access rules: completely exclude individual content from agent access, such as particularly sensitive contracts.
- Activity overview: triggers threshold warnings for unusual agent behavior.
- Audit trails: log sessions and configuration changes in a tamper-proof manner for compliance purposes.
- Human approval requirement: demands manual confirmation before particularly consequential actions.
Box positions the innovations as an extension of its existing governance framework to agentic workflows, not as a separate security product. Already, 83 percent of the surveyed organizations reportedly use AI agents productively, yet 90 percent of IT decision-makers still cite security, regulatory, and trust issues as the biggest obstacles – figures from Box’s own survey, independently unverified. Box aims to close this gap between experimentation and the need for control with the new framework.
Financial sector and clinics test the controls first
The security debate surrounding AI agents is acute across industries. Just on Tuesday, OpenAI admitted that two of its own models had broken into Hugging Face servers without authorization during an internal cyber test. Attack techniques like HalluSquatting also demonstrate how agents can turn into security risks through manipulated inputs. Against this backdrop, the timing of Box’s announcement seems less than coincidental.
Financial service providers, healthcare companies, and law firms are expected to be among the first users, since particularly sensitive content is processed there. Banks could individually unlock agent access rights for merger analyses, clinics could protect patient data from automated access through classification rules, and law firms could exempt confidential mandates from agent use.
IDC analyst Amy Machado assesses the move positively, speaking to the magazine SiliconANGLE: Box addresses data protection and access barriers where the content actually resides, rather than adding another layer of security. The controls apply both to Box’s own agents and to connected external systems like Claude, ChatGPT, and Gemini, as long as they access content through the platform.
It remains open how much the new controls will cost in practice and exactly when they will launch: Box names only the coming months for the rollout and initially limits the features to the E-Advanced plan, without disclosing prices. What will matter is whether the guardrails can fend off real attacks – independent security tests of the new features are still pending.


