Netskope launched Netskope Skylight Agent Action Control, a capability that classifies AI agent actions and applies granular policy controls to stop high-risk activities before execution. With 91% of organizations unable to prevent risky agent actions and 54% reporting AI agent security incidents, the tool addresses critical governance gaps in autonomous AI deployment.

Netskope Unveils New AI Security Capability to Address Growing Agent Risks

Netskope announced Netskope Skylight Agent Action Control, a capability designed to classify every action an AI agent attempts and apply granular controls to stop high-risk actions before they execute

1

2

. The launch addresses a critical gap in AI security governance, with 91% of organizations currently unable to stop a risky AI agent action before it executes

1

. More concerning, 54% of organizations reported a confirmed or suspected AI agent security incident in the past year

1

. The capability provides security teams with a policy-based approach to govern what autonomous agents are permitted to do, rather than simply reacting to their actions after the fact.

Netskope's AI Security Portfolio Gets a New Identity

Alongside the Agent Action Control announcement, Netskope renamed its AI security portfolio from Netskope One AI Security to Netskope Skylight

1

2

. The rebranding aims to better communicate the company's broad capabilities across AI security. Netskope Skylight now serves as the family name for the suite of AI security products including Netskope Skylight AI Command Center, AI Guardrails, AI Gateway, Agentic Broker, and AI Red Teaming

1

. This consolidation under a single brand reflects the company's commitment to providing comprehensive AI security governance tools as enterprises accelerate their adoption of AI agents.

How Agent Action Control Classifies and Blocks Risky Activities

Netskope Skylight Agent Action Control operates by classifying every agent action into one of nine intent-based categories prior to execution

1

2

. These categories include access control changes, configuration changes, credential and secret manipulation, data destruction, infrastructure provisioning, potential data exfiltration, potential external communication, remote code execution, and source code change

1

. Security teams can then apply risk-based profiles by agent type, choosing to block, allow, or alert based on low, medium, high, or critical risk categories

1

2

. When an action is blocked, teams have the option to send default or custom notifications to end-users for coaching purposes. Crucially, profiles attach to specific agents, allowing a coding assistant and a chat application to operate under different rules

1

.

Granular Policy Controls Without Additional Infrastructure

One of the key advantages of Netskope Skylight Agent Action Control is its seamless integration with existing infrastructure. The capability runs on network traffic the Netskope platform already inspects, meaning security teams gain enforcement over agent behavior without deploying a separate tool or standing up a second console

1

2

. Every action is logged, and security teams can filter granular policy alerts by cost exposure, source code changes, infrastructure updates, or external communication to align investigation efforts with organization risk prioritization

1

. This approach enables teams to prevent high-risk activities while maintaining visibility into agent behavior patterns across their environment.

Preventing Authority Drift in AI Agents

The capability specifically targets the problem of "authority drift" in AI agents—situations where agents work from vague prompts or have overly permissive instructions

1

. John Martin, Chief Product Officer at Netskope, explained the urgency: "AI agents tend to act first and explain later, and most security teams only learn what happened after it is done. Agent Action Control puts a decision in front of every action an AI agent takes, so a team can say yes to agentic AI without saying yes to the one action that could cost them a production system"

1

. When a coding agent working from a vague prompt attempts to delete a production repository, for example, the action is classified as data destruction at a critical risk level, and the call is stopped before it reaches the repository

1

. Security teams receive a record of the attempt instead of an incident report, fundamentally shifting from reactive to proactive AI security governance.

Industry Recognition of Deterministic Controls for AI Security

Dr. Grace Trinidad, Research Director for AI Security and Trust at IDC, highlighted the importance of policy-based controls in enterprise AI adoption: "As enterprises accelerate adoption of AI agents, we're finding that probabilistic controls are sometimes insufficient to protect the enterprise, but even occasional failure is unacceptable. These hardened, policy-based, deterministic controls are the backstop that prevents AI agents from causing an enterprise incident"

1

. This recognition underscores a shift in AI security thinking—from relying solely on probabilistic safeguards to implementing deterministic, policy-based controls that provide absolute enforcement. Netskope Skylight Agent Action Control will be available at the end of the current quarter

1

2

.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved