Box, which has evolved from a cloud storage business into an Intelligent Content Management (ICM) platform, is targeting the legal – and other regulated sectors – with a new agentic AI control system.
A spokesperson for Box told Artificial Lawyer: ‘As organisations like law firms look to deploy agents across sensitive business processes, Box is introducing a new set of security and governance capabilities designed specifically for AI agents working with enterprise content.
‘For the legal industry, this addresses the challenge of how to safely use AI for workflows like contract reviews, discovery workflows, and case preparation without compromising confidential information. With these new capabilities, firms can govern AI agents by enforcing policy-driven controls on what agents can access and act on.’
The move matters as more and more law firms and legal teams are making use of agentic tools, and the general model makers are also providing such capabilities. For example, Anthropic has a dedicated capability for agent development via Claude Managed Agents. However, how are they being controlled? What does compliance look like for them? What is the security set-up around them? Enter Box.
Under its E-Advanced plan they are rolling out:
- new agent guardrails,
- third-party agent activity oversight,
- prompt injection detection,
- agent classification-based access policies,
- enterprise-grade security controls to Box Agents,
- and third-party agents, such as Claude, ChatGPT, and Gemini.
It’s not the first time that Box has sought to pick up business in the legal world – it’s been working with a handful of law firms, as well as inhouse legal teams for a while. But, this is a deeper and more complex move.
They are also pitching this as useful for financial services, healthcare, and insurance – in short, where there are high levels of regulatory oversight.
Manoj Asnani, VP of AI Security, Privacy, Compliance & Governance Products at Box, commented: ‘83% of organizations are already experimenting with AI agents across their most critical tasks.
‘As these agentic workflows become more deeply embedded in the enterprise, it is critical to create the proper security controls to ensure agents have what they need to function effectively, without accessing, modifying, or exposing content beyond the scope of its intended task.
‘Box already provides a safe environment for organizations to apply AI to their most critical business knowledge, and with these new controls, we are creating a standard for deploying agents of any kind securely and at scale.’
And here’s a more detailed overview of what they will offer:
- ‘Agent guardrails that define exactly what custom Box AI agents can and cannot do based on content sensitivity and policy, including enforcing label-based access controls, requiring approval for deletion actions, and disabling external sharing to help protect sensitive information
- Prompt injection detection capabilities that validate every input before it reaches the model by detecting known prompt injection patterns at the content layer and enabling organizations to log, alert on, or block suspicious attempts
- MCP guardrails that let admins control what external AI agents connected through the Box MCP Server are allowed to do, with scoped permissions such as allowing file creation only in approved folders, blocking external sharing, and permitting content moves only to specific folders
- Classification-based access policies for both external and custom Box AI agents that enables organizations to exclude content with specified classifications from being read, searched, or accessed
- Agent activity oversight capabilities that provide visibility into external AI agent activity on customer content and configure threshold-based alerts, enabling organizations to quickly detect and respond to suspicious behaviour
- Agent audit trails and session governance that retain, audit, and provide compliance-ready records for every agent session with full session context, including retention policies and legal holds
- Human-in-the-loop control features that require human approvals before agents execute sensitive or high-impact actions.’
Is this a big deal?
First, is this another sign of ‘Big Tech doing Legal Tech’ ? Well, yes. Box has revenues of around $1.2 billion, is publicly listed, and no doubt would like to see their numbers keep rising. It would be unusual if they had not noticed what a range of large tech companies are doing in the legal world now since the arrival of genAI and agents.
In this case, Box has already worked for some years in the legal sector, albeit without having a major profile yet. But, this takes their offering up a notch into far more than file storage and into actively managing agentic tools operating in a legal environment. In short, a more sophisticated pitch.
So, a second point is whether inhouse teams and law firms will look to Box for help here? They may, especially those that have developed their own agents with third parties – and that may in turn mean more interest from the inhouse world, especially if other parts of the business are already using Box.
It’s also interesting to note that Norm, which has now evolved into a NewMod law firm, started out with the goal of policing agents inside corporates and banks.
Last point; the field of AI and agentic compliance is only likely to grow. Few would disagree that usage has rapidly risen across the economy, while more and more sensitive tasks are seeing agentic systems engage in those workflows. So, lawyers may see this Box offering as both useful for their own needs, and perhaps the needs of external and internal clients.
More about Box here.
—
Two Major Legal Innovators Conferences this November
Come and join us in New York and London this November at Legal Innovators!
Legal Innovators UK – London, Nov 4 and 5

And, then Legal Innovators New York – Nov 17 and 18.

After another fantastic Legal Innovators California, where we had speakers from OpenAI, Y Combinator, Google, Meta, and many more pioneering organisations; and our stellar inaugural event in Paris this June, we are now looking forward to the landmark conferences in London and New York, both in November, and both across two days: Law Firm Day, and Inhouse Day.
Discover more from Artificial Lawyer
Subscribe to get the latest posts sent to your email.