Netskope Enables Security Teams to Stop Risky AI Agent Actions Before They Execute
Netskope (NTSK) launched Netskope Skylight Agent Action Control, a new capability within its renamed Netskope Skylight AI Security suite, to classify AI agent actions by risk and block high-risk actions before they execute.
Rhea-AI Summary
Netskope (NTSK) launched Netskope Skylight Agent Action Control, a new capability within its renamed Netskope Skylight AI Security suite, to classify AI agent actions by risk and block high-risk actions before they execute.
The portfolio, formerly called Netskope One AI Security, now uses the Netskope Skylight family name across products such as AI Command Center, AI Guardrails, AI Gateway, Agentic Broker, and AI Red Teaming. Agent Action Control categorizes every attempted agent action into nine intent-based types, supports risk-based policy profiles by agent type, logs all actions with granular alerts, and operates on existing Netskope-inspected traffic without requiring a new console or agent. Availability is expected at the end of the current quarter.
Positive
- None.
Negative
- None.
Details
News Market Reaction – NTSK
In the Sep 15 session, NTSK gained 2.76%, reflecting a moderate positive market reaction. Argus tracked a peak move of +2.6% during that session. Our momentum scanner triggered 5 alerts that day, indicating moderate trading interest and price volatility. Trading volume was exceptionally heavy at 9.8x the daily average, suggesting very strong buying interest.
Data tracked by StockTitan Argus on the day of publication.
Key Figures
- Organizations unable to stop risky agent actions
- 91%
- Reported industry statistic
- Organizations reporting an AI agent incident
- 54%
- Confirmed or suspected incident in the past year
- Action categories
- nine
- Intent-based categories classified before execution
- Risk categories
- four
- Low, medium, high, or critical policy profiles
Previous AI Reports
-
Introduced AgentSkope with deployable agents for security and networking workflows
-
Launched unified AI discovery, risk intelligence, and coordinated response platform
-
Joined Anthropic project to detect code vulnerabilities and support AI governance
24h Move is the share-price change in the day after each event; other market factors may also have contributed.
Key Terms
data exfiltration technical
remote code execution technical
AI-generated analysis. How Rhea-AI works. Not financial advice.
Part of the newly renamed Netskope Skylight AI Security suite, Agent Action Control classifies agentic actions by risk and blocks the ones that matter before they execute
SANTA CLARA, Calif., Sept. 15, 2026 (GLOBE NEWSWIRE) -- Netskope (NASDAQ: NTSK), a leader in modern security and networking for the cloud and AI era, today announced Netskope Skylight Agent Action Control, a new capability that classifies every action an AI agent attempts, and applies granular controls to stop high-risk actions before they execute. The capability meets security teams’ need for a policy-based way to govern, rather than react to, what autonomous agents are permitted to do.
Agent Action Control arrives as Netskope renames its AI security portfolio to better communicate the company’s broad capabilities across AI security. Formerly Netskope One AI Security, Netskope Skylight is the new family name for the suite of Netskope AI security products including Netskope Skylight AI Command Center, Netskope Skylight AI Guardrails, Netskope Skylight AI Gateway, Netskope Skylight Agentic Broker, and Netskope Skylight AI Red Teaming.
Netskope Skylight Agent Action Control
Today,
- Control over nine different types of action: To enable granular policy definition, every agent action is classified into one of nine intent-based categories prior to execution. These include, access control changes, configuration changes, credential and secret manipulation, data destruction, infrastructure provisioning, potential data exfiltration, potential external communication, remote code execution, or source code change.
- Risk-based policy profiles by agent type: Block, allow or alert based on low, medium, high or critical risk categories, with the option to send a default or custom notification to the end-user for user coaching when the action is blocked. Profiles attach to specific agents, so a coding assistant and a chat application do not have to operate under the same rules.
- Granular policy alerts: Every action is logged, with security teams able to filter policy alerts by cost exposure, source code changes, infrastructure updates, or external communication to align investigation effort with organization risk prioritization.
- No new console and no new agent: Netskope Skylight Agent Action Control runs on network traffic the Netskope platform already inspects, so security teams gain enforcement over agent behavior without deploying a separate tool or standing up a second console.
The result is a policy that governs what an agent is allowed to do before it acts. When a coding agent working from a vague prompt attempts to delete a production repository, for example, the action is classified as data destruction at a critical risk level, and the call is stopped before it reaches the repository. The security team gets a record of the attempt instead of an incident report. This approach provides governance and controls over agents at risk of “authority drift”, or whose harness or instructions are too vague or permissive.
"AI agents tend to act first and explain later, and most security teams only learn what happened after it is done,” said John Martin, Chief Product Officer, Netskope. “Agent Action Control puts a decision in front of every action an agent takes, so a team can say yes to agentic AI without saying yes to the one action that could cost them a production system."
“As enterprises accelerate adoption of AI agents, we’re finding that probabilistic controls are sometimes insufficient to protect the enterprise, but even occasional failure is unacceptable,” said Dr. Grace Trinidad, Research Director for AI Security and Trust at IDC. “These hardened, policy-based, deterministic controls are the backstop that prevents AI agents from causing an enterprise incident."
Netskope Skylight Agent Action Control will be available at the end of the current quarter. To learn more about Netskope Skylight, visit netskope.com/skylight.
Head over to The Lens (Netskope’s blog) to read more about Skylight, or to take a deeper look at Netskope Skylight Agent Action Control.
About Netskope
Netskope (NASDAQ: NTSK), a leader in modern security and networking for the cloud and AI era, addresses the needs of both security and networking teams by providing optimized access and real-time, context-based security for the AI ecosystem inclusive of agents, applications, tools, LLMs, people, devices, and data. Thousands of customers, including more than
Learn more at netskope.com, on LinkedIn, and on Instagram.
Media Relations Contacts:
press@netskope.com
Investor Relations Contacts:
ir@netskope.com
________________________
1 Netskope, 2026 AI Risk and Readiness Report.
2 Gravitee, The State of AI Agent Security 2026
FAQ
AI-generated questions and answers. How Rhea-AI works. Not financial advice.
What are the nine action categories used by Netskope Skylight Agent Action Control?
Netskope Skylight Agent Action Control classifies every AI agent action into one of nine intent-based categories before execution: access control changes, configuration changes, credential and secret manipulation, data destruction, infrastructure provisioning, potential data exfiltration, potential external communication, remote code execution, and source code change.
How do risk-based policy profiles work for different AI agents?
Risk-based profiles allow teams to block, allow, or alert on actions categorized as low, medium, high, or critical risk. Profiles can attach to specific agents, so, for example, a coding assistant and a chat application can operate under different policies, and blocked actions can trigger default or custom notifications to users for coaching.
Does Netskope Skylight Agent Action Control require a new console or endpoint agent?
No. Netskope Skylight Agent Action Control runs on the network traffic the Netskope platform already inspects. Security teams gain enforcement over AI agent behavior without deploying a separate tool or operating a second console.
When will Netskope Skylight Agent Action Control be available?
Netskope Skylight Agent Action Control is expected to be available at the end of the current quarter.
What other products are included in the Netskope Skylight AI Security suite?
The Netskope Skylight AI Security suite includes Netskope Skylight AI Command Center, Netskope Skylight AI Guardrails, Netskope Skylight AI Gateway, Netskope Skylight Agentic Broker, and Netskope Skylight AI Red Teaming, alongside the new Agent Action Control capability.