[Interview] “AI Agent Security Is About Reading Intent”
IT DAILY ·
✦ AI Summary
JP Yu, Executive Vice President and General Manager of Proofpoint for Southeast Asia and Korea (SAK), said that even as AI agents spread, data still requires human or AI agent intervention to move outside the organization.
He presented “intent” as the standard for security, explaining that normal work and risky activity can be distinguished only by looking at the context, meaning, and purpose of behavior, not just access rights.
Proofpoint said it is extending people-centered security to AI agents and expanding its business beyond email security into data security and AI governance.
IT Daily reported, in an interview format, that JP Yu, Executive Vice President and General Manager of Proofpoint for Southeast Asia and Korea (SAK), identified
JP Yu explained that even as AI agents spread, data still needs either a human or an AI agent to intervene in order to move outside the organization. In that sense, he said, the basics of security do not change.
As evidence, he pointed to the fact that AI agents can access data and can also act in ways different from their original purpose. Accordingly, he said, the issue comes down to how to distinguish normal work from risky activity.
Yu presented “intent” as that standard. He said security can only be achieved by looking not just at access rights, but also at the context, meaning, and purpose of the behavior in question. He explained AI agent security through the example of hotel staff.
A hotel employee’s access to guest rooms is granted for morning cleaning and evening turndown service. But room entry at unusual times unrelated to that purpose should be seen as abnormal behavior. He said security solutions must quickly detect and respond to such anomalies.
In line with that concern, Proofpoint proposed extending people-centered security to AI agents. The background for that expansion was a growing awareness of the security risks tied to AI agents performing work on behalf of humans. Proofpoint said there is little difference between people and AI agents from a security standpoint.
Proofpoint’s business scope has also changed, following a path from email security to data security and AI governance. That point came up while explaining what the biggest cybersecurity change has been since the AI era began.
Proofpoint said phishing and social engineering attacks have become more sophisticated since generative AI spread. The company has provided email security for more than 20 years and has accumulated data on the scale of analyzing one-third of global email traffic. One change identified in that accumulated data was a sharp recent increase in attacks targeting non-English-speaking countries.
While there are fewer hackers capable of using Korean or Japanese than English, AI has made translation easier and faster, he said. As a result, Proofpoint said phishing attacks continue to rise across various language regions.
Even with new threats targeting AI, email remains the main attack path both in the past and now, the speaker said. He explained that a significant share of attacks are found in email.
Still, the speaker said email remains central, but attack paths beyond email are increasing. He also said attempts are being made to insert malicious prompts into AI services, and that attempts to hack or abuse AI agents are also occurring.
The speaker said Microsoft (MS) Teams and Slack are also becoming new targets, showing how attack patterns are changing. He added that methods for inserting malicious prompts into email are being used.
Specifically, he said attackers are using tactics such as inserting hidden prompts by setting font size to 0 and using white text so that humans cannot see it but AI can still read it. He explained that if AI reads commands that people do not notice, it will act according to the attacker’s intent.
Proofpoint does not view AI agents as exceptional entities separate from people, but rather as the same kind of subject under the same lens as people. AI agents support humans and carry out work on their behalf, and by design can perform tasks such as DB access and document creation just like people. At the same time, they can be attacked like people and may move in directions not instructed, so they are viewed as security management targets.
For that reason, Proofpoint focuses on intent more than on the access target itself. The criterion is whether the behavior aligns with the work purpose and policy, and the company believes that the mere fact of having normal authorization cannot determine the legitimacy of every action. In the end, whether it is an AI agent or a person, the explanation is that behavior must be judged against the same standard and filtered through intent to see whether it fits the assigned work and policy.
The gist of his remarks was that data does not leave on its own; if it moved outside, then a person or an AI agent must have done something. However, he said that risk is difficult to judge from the result of data movement alone or from an individual action alone. Therefore, one must examine the circumstances and context together to uncover hidden intent, and that intent analysis is the premise for detecting problems.
Proofpoint said it detects risk signals through internal activity monitoring and notifies organizations. One real-world example involved identifying an internal employee at a global pharmaceutical company who was suspected of attempting to remove confidential data related to vaccine development. The identification was made using Proofpoint’s solution, which captured abnormal activity involving attempts to move hundreds of files and provided evidence.
Asked whether AI agents, as non-human entities, can be judged for abnormal behavior in the same way as people, he answered that AI agents also need a similar approach. He cited visibility as a prerequisite.
Visibility refers to understanding who is using which AI, what information was entered, and whether sensitive data was included. He also said a system is needed to capture and control every interaction among people, AI agents, and data. Only then can one understand what is happening inside the system and detect hidden intent.
Traditional DLP solutions operate on rules. Their strength lies in validating data characteristics and checking whether users comply with policy. However, rule-based controls have a limitation in that they make it difficult to understand the context of behavior.
Agents enter systems with legitimate authorization. For that reason, determining whether something is abnormal requires combining multiple pieces of information. He said not only authorization but also context and intent outside that authorization must be checked.
When asked about what distinguishes Korea from other Asian countries, the speaker said Korea has a highly educated workforce, has long maintained excellent broadband internet penetration, and is a market with a high level of digital maturity. He also said Korean companies have strong interest in new technologies and adopt them quickly.
He also said Korea is an important part of the global AI supply chain and, considering the geopolitical environment, is a strategically important market from a national security perspective. With a high share of knowledge workers, it is a market that enterprise software companies are watching closely. Based on that, Proofpoint sees Korea as a key growth pillar following the Asia-Pacific region, and he described Korea as a key growth pillar in APAC that needs a brake to support innovation.
Asked about the Korean market, where AI adoption is rapid, he said innovation and security must advance in parallel. Security, he explained, is not an obstacle to innovation but its foundation.
He compared this to a racing car, saying that high speed is possible only when the brakes can be trusted. To race at 300 kilometers per hour (KM), you need brakes that can match that speed, and the same principle applies to AI innovation.
He also said companies pursue rapid change and results, but cannot overlook data sovereignty and privacy. Security is essential, he explained, both for protecting data and for maintaining innovation speed.
On future investment plans in Korea, he said Korea is already a large market. At the same time, he said the market has strong growth potential and requires continued investment.
As investment directions, he pointed to expanding headcount and strengthening the partner ecosystem. He also said the company plans to invest in language support and localization to improve the fit of Proofpoint solutions for the Korean market.
The question asked where Proofpoint is headed next after its starting point in people-centered security. In response, he said the protection scope has expanded as AI has been adopted more deeply into work environments.
He said Proofpoint is advancing the expansion of its accumulated email security capabilities into data and AI agent domains. He added that the company aims to protect employees wherever they work, citing email, collaboration environments, and AI environments as examples of protected spaces. He also said its role is to protect people and data.
Source: IT DAILY · Kim Ho-jun
Original: https://www.itdaily.kr/news/articleView.html?idxno=241314
References
This article was produced with the help of an automated content generation algorithm.
Source: IT DAILY
View originalThis article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.