AWARE: Decoding Agentic AI, Command Comes First
0 分钟阅读

Lionel Menchaca
Six sessions. One argument, repeated from six angles: the enterprises that win the next decade will not be the ones that adopt AI fastest. They will be the ones that never lose command of it.
Forcepoint AWARE brought together Forcepoint leadership, an AWS architect, a working futurist and a security executive who has defended data at TikTok, ADP and EMC to decode what agentic AI actually changes. None of them agreed on every detail. All of them arrived at the same place: the model is no longer the hard problem. What you do with your data, and who can prove what happened to it, is.
If you missed the live sessions, here is what you missed, and why it is worth watching in full.
Command Beats Approval
Forcepoint CEO Ryan Windham opened the event with an argument that is uncomfortable on purpose: most security programs are still built to approve individual actions, one step at a time, when the actual exposure lives in the whole path an agent takes to get somewhere.
No agent has ever exceeded its authority. It exceeded your intent, and there's no permission for that.
Ryan's point is that approval and command are not the same discipline. Approval checks a single step. Command governs the sequence, because intent only shows up across the whole path, never in any one action alone. That reframing is the foundation for what Forcepoint calls its Know, Adapt, Protect model: know where sensitive data lives and what can reach it, adapt enforcement as risk changes in real time and protect both the data and the AI acting on it with an evidence trail that holds up when a regulator asks.
He also used the keynote to spotlight three capabilities: AI detection and response, agent visibility and governance, and the Forcepoint AI Agent Gateway, which holds autonomous agents to least privilege down to the field level, with no agent ever holding its own credentials.
The Model Is a Commodity. Your Data Isn't.
Forcepoint Chief Data Strategy Officer Ronan Murphy opened his conversation with Roland Cloutier, the former global security chief at TikTok, ADP and EMC, with a claim that reframes why any of this matters commercially, not just technically.
If your competitor wants the same model as you, they can have that probably by Thursday.
Ronan's argument: for two years, the AI conversation was about which model, how big and what benchmark. That conversation is ending, not because the model stopped mattering, but because open weight models and managed inference turned it into a procurement decision. What is left as the actual differentiator is what Murphy calls alpha: the proprietary knowledge, source code, customer intelligence and institutional judgment a company cannot buy from a vendor.
Roland's response cuts through a category error a lot of security programs are still making. Data loss used to mean an external attacker got in. AI adds a second failure mode entirely: an organization can lose control of its own information simply by handing it to a system that was never scoped to protect it.
The risk isn't just loss of custody. It's loss of purpose.
Nobody Has a Playbook, and That's the Point
Between the strategy conversation and the product demonstrations, futurist Ian Beacraft and Forcepoint's David Giambruno made a case that has nothing to do with data classification and everything to do with why the rest of the day matters. Their premise: any organization waiting for a stable best practice in agentic AI will wait forever, because the practices being built today have a shelf life measured in weeks, not years.
Beacraft calls the underlying pattern skill flux: a skill's importance can rise exponentially, then drop just as fast, not to zero, but far enough that leaning on what already worked becomes a liability rather than an asset. The implication for security and compliance leaders is direct. Waiting for a finished framework is not caution. It is a way of falling behind while feeling responsible.
What "Know Your Data First" Looks Like in Practice
Forcepoint CTO Bakshi Kohli opened the platform walkthrough with the architecture underneath it: every action resolves to an identity, and every identity's access maps back to where sensitive data actually lives. He handed the live demo to Salah Nassar, VP of Product Marketing, and Saritha Chadalavada, VP of Product Management for Forcepoint AI Data Security.
In one demonstration, an AI assistant was asked to pull a Confluence page containing sensitive information through a connected agent. The request never completed.

Fig. 1 - Claude can't access a restricted file due to Forcepoint DLP policy
A policy written to block U.S. PII and credit card data from leaving through any channel, not just email or endpoint, stopped it at the point where the agent tried to reach the page. The same policy engine that already protects that data everywhere else in the organization protected it here too, with no separate rulebook written for AI.

Fig. 2 - DLP policy restricts the request through the MCP server channel
Know your data first. You cannot protect what you have not seen and understood.
That closing line from Nassar is the practical summary of Forcepoint's approach to agentic AI security: agents never hold standing credentials to the applications they call, and every response gets inspected at the field level before it can leave.
Ownership Divides. Accountability Doesn't.
Forcepoint President of Go-to-Market Rick Hanson closed out the product portion of the day with AWS Principal Applied AI Architect Neelam Koshiya, working through what happens to the cloud shared responsibility model once agents start acting on their own. For two decades, that model split cleanly in two: the cloud provider secures the infrastructure, the customer secures what they build on it. Neelam's argument is that agents break the two-party version of that model, because they introduce an actor type the original framework was never built to cover.
The ownership divides, but the accountability does not.
In Neelam's framing, the model now has three parties instead of two: the cloud and AI provider responsible for infrastructure and platform-level guardrails, the security vendor responsible for visibility and policy enforcement across data flows, and the customer's own teams, who still own agent design, permission scoping, data classification and human oversight. A misconfigured guardrail is not a platform failure. It is a customer configuration decision with a risk consequence, and when something goes wrong, a board or regulator holds the enterprise accountable, not the cloud provider or the security vendor.
The Question Most Teams Can't Answer Yet
Rick Hanson wrapped up the event by distilling everything into three questions every security and compliance leader should be able to answer today. What data is at stake, and can you prove what policy follows it through its lifecycle. Could you produce a list of every agent running in your environment right now, and follow one end to end. And who owns the audit trail.
Most teams can answer the first two. Very few can answer the third.
That gap, more than any single product announcement, is the honest state of agentic AI security heading into next year. The organizations closing it are not the ones moving fastest. They are the ones who decided, before a regulator or a board forced the question, who owns the evidence. That is what command actually looks like in practice, not speed, but never losing track of who is responsible for what an agent just did.
Missed AWARE live? Every session, including the full platform walkthrough and the AWS shared responsibility conversation, is available on demand. Register to watch AWARE: Decoding Agentic AI Security.

Lionel Menchaca
阅读更多文章 Lionel MenchacaLionel Menchaca has covered data security at Forcepoint since 2020, writing about DLP, DSPM, insider risk and AI security for security and IT leaders. He works with Forcepoint X-Labs threat researchers to turn their findings on emerging threats, from AI-targeted supply chain attacks to prompt injection, into practical guidance, and he leads the company's editorial strategy across the blog and the X-Labs newsletter. Before Forcepoint, Lionel founded and ran Dell's corporate blog for seven years and spent two decades helping enterprise tech companies explain security, cloud and AI.
Forcepoint AWARE: Decoding Agentic AIWatch On Demand
X-Labs
直接向您的收件箱发送洞见、分析和新闻
