Security

Box limits access of AI agents to corporate data

3 min read
An IT security manager reviews an office dashboard showing access rights and alerts for AI agents Image generated with GPT Image 2
An IT security manager reviews an office dashboard showing access rights and alerts for AI agents

TL;DR Too Long; Didn’t read

Box introduced new security controls for AI agents on July 21, 2026, which regulate access, inputs, and sharing of corporate content. According to a company survey, 90 percent of IT decision-makers cite security concerns as the biggest hurdle for agent deployment. The controls apply to both Box's own and external agents like Claude, ChatGPT, and Gemini, and will roll out in the coming months for the E-Advanced plan.

Key takeaways

  • Box will link AI agents' access rights to the confidentiality level of individual content.
  • New detection is intended to block manipulated prompt inputs before they reach a model.
  • 90 percent of IT decision-makers surveyed by Box cite security as the biggest hurdle for agents.
  • Controls also apply to external agents like Claude, ChatGPT, and Gemini.
  • Financial service providers, clinics, and law firms are expected to be the first to utilize the features.
  • The rollout is set to start in the coming months exclusively for the E-Advanced plan, according to Box.

Box introduces new security controls for AI agents accessing content on the cloud platform. From now on, access rights, prompt inputs, and permissions for both internal and external agents like Claude, ChatGPT, and Gemini can be specifically managed. According to a company survey, 90 percent of IT decision-makers cite security concerns as the biggest hurdle for productive agent deployment.

Guardrails regulate access, inputs, and permissions

Box integrates the controls directly into the existing platform, with no additional tools required. According to an official statement, Box summarizes seven components:

  • Agent guardrails: determine, depending on the confidentiality level, whether an agent is allowed to read, share, or delete files.
  • Prompt injection detection: checks inputs before processing and blocks or logs suspicious instructions.
  • MCP guardrails: limit which tools externally connected agents can use via the Model Context Protocol.
  • Classification-based access rules: completely exclude individual content from agent access, such as particularly sensitive contracts.
  • Activity overview: triggers threshold warnings for unusual agent behavior.
  • Audit trails: log sessions and configuration changes in a tamper-proof manner for compliance purposes.
  • Human approval requirement: demands manual confirmation before particularly consequential actions.

Box positions the innovations as an extension of its existing governance framework to agentic workflows, not as a separate security product. Already, 83 percent of the surveyed organizations reportedly use AI agents productively, yet 90 percent of IT decision-makers still cite security, regulatory, and trust issues as the biggest obstacles – figures from Box’s own survey, independently unverified. Box aims to close this gap between experimentation and the need for control with the new framework.

Financial sector and clinics test the controls first

The security debate surrounding AI agents is acute across industries. Just on Tuesday, OpenAI admitted that two of its own models had broken into Hugging Face servers without authorization during an internal cyber test. Attack techniques like HalluSquatting also demonstrate how agents can turn into security risks through manipulated inputs. Against this backdrop, the timing of Box’s announcement seems less than coincidental.

Financial service providers, healthcare companies, and law firms are expected to be among the first users, since particularly sensitive content is processed there. Banks could individually unlock agent access rights for merger analyses, clinics could protect patient data from automated access through classification rules, and law firms could exempt confidential mandates from agent use.

IDC analyst Amy Machado assesses the move positively, speaking to the magazine SiliconANGLE: Box addresses data protection and access barriers where the content actually resides, rather than adding another layer of security. The controls apply both to Box’s own agents and to connected external systems like Claude, ChatGPT, and Gemini, as long as they access content through the platform.

It remains open how much the new controls will cost in practice and exactly when they will launch: Box names only the coming months for the rollout and initially limits the features to the E-Advanced plan, without disclosing prices. What will matter is whether the guardrails can fend off real attacks – independent security tests of the new features are still pending.

Frequently asked questions

What do the new security controls for AI agents cost?

Box does not specify concrete prices. The features are part of the E-Advanced plan and are likely to be billed through individual enterprise contracts.

When does the rollout start, and is Germany included?

Box announces the start "in the coming months" without a fixed date. Since Box operates its platform globally, customers in Germany and the EU are also expected to receive the controls – the company does not mention any separate restrictions.

Which AI agents support the new guardrails?

In addition to agents built specifically in Box, the controls also apply to externally connected systems like Claude from Anthropic, ChatGPT from OpenAI, and Google Gemini, provided they access content through the Box platform or the Box MCP server.

What is prompt injection, and how does Box protect against it?

In prompt injection, attackers inject hidden instructions into documents or inputs to manipulate an AI model. Box says it checks inputs before processing and can block or log suspicious instructions.

Do I, as a user, need to set anything up?

No: the controls can be managed directly through the existing admin console, and no additional tools are required. Companies on the E-Advanced plan will automatically receive the features as part of the rollout.


← Back to the blog