As enterprises race from pilot copilots to production-grade autonomous agents, the security conversation is shifting fast — and according to Bonfy co-founder and CEO Gidi Cohen, most of the industry is still asking the wrong question. While competitors focus on agent configuration and access control, Bonfy is staking its identity on a harder problem: tracking what sensitive data an AI agent actually reads, transforms, and sends once it’s already inside the system. With Gartner projecting that more than half of successful attacks on AI agents through 2029 will exploit access-control gaps, and roughly 22% of cyberattacks and data leaks tied to generative AI by 2028, that runtime blind spot is quickly becoming one of the defining risks heading into Black Hat USA 2026.
Ahead of the show, VMblog caught up with Cohen to dig into how Bonfy’s entity-aware approach fits alongside tools enterprises already run — Microsoft Purview, DLP, and DSPM — without becoming just another overlapping layer; what’s actually driving the company’s claim of eliminating false positives in a category notorious for alert fatigue; and why he believes the industry’s next reckoning won’t be about whether to deploy agents, but who’s accountable when one inevitably gets it wrong. Read on for the full Q&A, and if Cohen’s take on shadow AI, agent-to-agent data flows, and the runtime governance gap resonates, stop by the Bonfy booth at Black Hat to see how they’re putting it into practice.
++
VMblog: For readers who may not be familiar, give us the elevator pitch — who you are, what you do, and what genuinely sets you apart in today’s crowded cybersecurity market.
Gidi Cohen: Bonfy is an AI data security company. We protect unstructured data everywhere it moves, email, SaaS apps, collaboration tools, browsers, copilots, and increasingly, autonomous AI agents. Legacy DLP and DSPM were built for a world of users and static repositories. We built Bonfy for a world where AI agents read, write, transform, and share sensitive data across dozens of systems on their own. Our entity-aware engine understands the people and customers behind the data, so we catch real risk with very few false positives, and we treat AI agents as first-class entities, not just an extension of someone’s login.
VMblog: If a CISO walks away from your booth remembering exactly one thing about your company, what do you want that to be?
Cohen: That Bonfy secures the data flowing through AI agents, not just the agents themselves. Everyone else is asking “what agents do we have and how are they configured?” We answer the harder question: what data did that agent actually touch, how did it transform it, and where did the output land?
VMblog: Most enterprises already run Microsoft Purview and a DLP stack, and many have a DSPM tool too. Be honest — where does Bonfy actually fit, and how do you answer the CISO who assumes you’re just another overlapping layer?
Cohen: It’s a fair challenge, and the honest answer is that we’re not trying to replace those tools, we make them more useful. Purview is strong at governing Microsoft; the problem is your data doesn’t stay inside Microsoft. It moves through Slack, Salesforce, browsers, third-party SaaS, and now copilots and agents that span all of it. The way we put it internally is that Purview governs Microsoft while Bonfy governs the whole enterprise, we complement Purview with high-accuracy, entity-aware labeling and cross-SaaS enforcement. The overlap question usually answers itself in a proof of concept: legacy DLP and DSPM were built around users and static repositories, and they simply can’t see what an agent reads to ground a response or where it sends the output. We sit on that data layer the existing stack was never designed to watch. So the integration story is the point, we plug into Entra, Google Directory, and SIEM/SOAR tools teams already own, and add the AI-and-agent data visibility they’re missing.
VMblog: “Eliminating false positives” is a bold claim in a category famous for alert fatigue. What’s actually under the hood that lets Bonfy do this where legacy tools can’t?
Cohen: Two things legacy tools don’t have: business context and entity awareness. Old DLP matches patterns, a regex sees a string that looks like an account number and fires, whether or not sending it was actually a problem. Our engine starts from the entities involved: who the sender is, who the recipient is, what customer or matter the content relates to, and what the legitimate business relationship is. That entity-aware understanding of the people and customers behind the data is what lets us tell a routine, authorized disclosure apart from a genuine leak. On top of that we layer business logic, out-of-the-box policies like GDPR, PCI, HIPAA, and CCPA plus customer-defined rules, so detection reflects how the organization actually operates, not a generic dictionary. The payoff isn’t just cleaner dashboards; it’s that analysts spend their time on real risk instead of triaging noise, which is exactly the headcount relief security leaders need right now. In regulated verticals like insurance, that same context catches subtle problems legacy tools miss entirely, like cross-contamination of information between clients that’s technically “allowed” data movement but a real exposure.
VMblog: The threat landscape heading into Black Hat 2026 looks very different from even 18 months ago. Which specific threat vectors — whether that’s agentic AI attacks, identity-based intrusions, critical infrastructure targeting, or something else — is your solution most directly built to address?
Cohen: Agentic AI and the data exposure it creates. As enterprises deploy copilots and autonomous agents, those systems become the biggest new attack surface in a decade. Gartner projects that through 2029, more than half of successful attacks against AI agents will exploit access-control issues, and by 2028 around 22% of cyberattacks and data leaks will involve generative AI. We’re built for exactly those moments, a copilot grounding on the wrong document, an agent routing sensitive output to the wrong recipient, or shadow AI quietly exfiltrating IP.
VMblog: Agentic AI is reshaping both offense and defense. How is your company building security for — and with — autonomous AI systems, and what risks are you most concerned enterprises are underestimating right now?
Cohen: We treat agents as first-class entities. That means we can see which agent accessed which data, how it used that data, and where the output ended up, across the whole lifecycle, not just the configuration layer. The risk enterprises most underestimate: they’re securing how agents are set up, but not the data those agents actually move at runtime. An agent with perfectly legitimate access can still combine, transform, and send sensitive data in ways no static policy anticipated. That runtime data layer is the blind spot.
VMblog: “AI-native security” is quickly becoming the new “next-gen.” What does that phrase actually mean at your company, and how do you demonstrate real differentiation beyond the marketing language?
Cohen: For us it’s literal, not a label. Bonfy uses AI to understand content in business context, who the entities are, what the relationship is, whether this communication or this grounding is appropriate. That’s what lets us eliminate the false positives that drown legacy DLP. The real test for “AI-native”: can you secure the AI systems and agents themselves, and can your engine reason about context the way a human reviewer would? If the “AI-native” story is just a classifier bolted onto a 2010-era DLP architecture, that’s marketing.
VMblog: Identity has become the new perimeter — and attackers know it. How has your approach to identity security, authentication, or access management evolved, and what are organizations still getting dangerously wrong?
Cohen: Identity is necessary but not sufficient. You can get authentication and access perfectly right and still leak data, because the question isn’t only “who or what gets in,” it’s “what happens to the data once they’re in.” That gap widens with AI agents, which often inherit broad access and then move data across systems autonomously. We integrate with the identity layer, Entra, Google Directory — but our job starts where identity ends: governing the data itself as it moves. The thing organizations still get dangerously wrong is assuming access control equals data protection.
VMblog: What’s the most significant cybersecurity blind spot you’re seeing across your customer base right now, and how does your technology address it?
Cohen: Shadow AI and agent data movement. Teams have decent visibility into users and repositories, but almost none into what copilots and agents are doing with sensitive data in real time, what they read to ground a response, what they generate, where it goes. Many existing DLP and DSPM tools focus on users and static repositories, and AI agents break that model by operating across multiple systems and generating new outputs. We close that by monitoring the content itself across every channel an agent touches.
VMblog: Security teams are being asked to do more with tighter budgets and leaner headcounts. How does your solution help security leaders justify ROI and actually reduce operational burden rather than add to it?
Cohen: Two ways. First, false positives, legacy DLP buries analysts in noise; our business-context engine means teams act on real risk instead of triaging thousands of false alerts, which is direct headcount relief. Second, we let organizations safely turn on AI initiatives they’d otherwise stall, so security becomes the enabler of a board-level priority instead of the blocker. And we’re additive, not rip-and-replace, we complement Microsoft Purview and M365 DLP and plug into SIEM/SOAR tools like Splunk, Sentinel, and Rapid7, so it layers onto what teams already own.
VMblog: What should be sitting at the very top of every security leader’s priority list in the second half of 2026?
Cohen: Governing the data layer of your AI deployments before they outrun your visibility. Most organizations went from “should we use copilots?” to “we have agents in production” faster than their controls did. The priority is getting eyes on what those systems read, generate, and share now, while the footprint is still small enough to instrument.
VMblog: Looking toward 2027 and beyond, what emerging threat or technology inflection point do you think the industry is still not taking seriously enough?
Cohen: Autonomous agent-to-agent data flows. We’re heading toward agents that call other agents, hand off tasks, and move data between systems with no human in the loop at any step. The industry is still mostly securing single agents in isolation. The real exposure is the chain — sensitive data passing through five systems where no single owner can tell you where it ended up. That accountability gap is what gets too little attention today.
VMblog: Beyond the product pitch, what’s one piece of hard-won, actionable security wisdom you’d hand to every practitioner who stops by your booth?
Cohen: Stop trying to block your way to safety with AI. The teams that win aren’t the ones saying no to copilots and agents, they’re the ones who got visibility first and built guardrails that let the business move. Start by instrumenting what your AI systems actually touch. You can’t govern what you can’t see.
VMblog: When the industry gathers again at Black Hat 2027, what do you think will be the defining cybersecurity conversation that dominated the year?
Cohen: Accountability for autonomous AI. By 2027 the question won’t be “should we deploy agents,” it’ll be “when an agent leaks data or makes a costly mistake, who’s responsible, and can you even reconstruct what happened?” Data lineage and provenance through agentic workflows will be the conversation.
##






