Singapore – Netskope has launched Skylight Agent Action Control, a new capability that blocks high-risk AI agent actions before they can execute. The launch responds to a stark gap: 91% of organisations cannot currently stop a risky agent action in time, according to a research.
The announcement, made in Singapore, arrives alongside a broader rebrand of Netskope’s AI security portfolio. Formerly known as Netskope One AI Security, the suite has been renamed Netskope Skylight, a family that now includes Netskope Skylight AI Command Center, AI Guardrails, AI Gateway, Agentic Broker, and AI Red Teaming.
Behind the launch sits a stark set of figures. Alongside the finding that 91% of organisations cannot halt a risky agent action pre-execution, Netskope also reports that 54% experienced a confirmed or suspected AI agent security incident within the past year.
Agent Action Control is designed to address that exposure through policy-based governance rather than after-the-fact incident response. Every action an AI agent attempts is classified into one of nine intent-based categories before it executes, covering access control changes, configuration changes, credential and secret manipulation, data destruction, infrastructure provisioning, potential data exfiltration, potential external communication, remote code execution, and source code change.
From there, security teams can apply risk-based policy profiles tailored to individual agent types. Actions can be blocked, allowed or flagged for alert according to low, medium, high or critical risk levels, with the option of a default or custom notification sent to the end-user when an action is blocked. Crucially, profiles attach to specific agents, meaning a coding assistant and a chat application need not operate under identical rules.
Every action is also logged, and security teams can filter alerts by cost exposure, source code changes, infrastructure updates, or external communication, allowing investigation effort to be aligned with organisational risk priorities. Notably, the capability runs on network traffic that the Netskope platform already inspects, meaning it requires no additional console and no separate agent deployment.
In practice, Netskope points to a scenario in which a coding agent, acting on a vague prompt, attempts to delete a production repository. Under Agent Action Control, that action would be classified as data destruction at a critical risk level and stopped before it reaches the repository, leaving security teams with a record of the attempt rather than an incident to clean up. Netskope frames this as a safeguard against “authority drift,” where an agent’s harness or instructions are too vague or too permissive.
“AI agents tend to act first and explain later, and most security teams only learn what happened after it is done,” said John Martin, Chief Product Officer, Netskope.
“Agent Action Control puts a decision in front of every action an agent takes, so a team can say yes to agentic AI without saying yes to the one action that could cost them a production system,” Martin added.
Industry analysts have also weighed in on the shift towards deterministic controls. “As enterprises accelerate adoption of AI agents, we’re finding that probabilistic controls are sometimes insufficient to protect the enterprise, but even occasional failure is unacceptable,” said Dr Grace Trinidad, Research Director for AI Security and Trust at IDC.
“These hardened, policy-based, deterministic controls are the backstop that prevents AI agents from causing an enterprise incident,” Trinidad further stated.

