More than half of Middle East organisations that run a security operations centre have already deployed AI agents inside it. That figure, 55%, comes from IBM's 2026 Cost of a Data Breach Report, released in Dubai on 3 August. The same report names phishing, including voice and SMS, as the most common initial cause of breaches in 2026 at 18% of incidents, and the most expensive at an average of $10.41 million. Domestically, the UAE Cyber Security Council reported in April that more than 75% of breaches in the country begin with a phishing email or fraudulent message.
Those numbers explain what every major email security vendor shipped this year.
Agents are now reading corporate mail on behalf of staff. Attackers noticed before most security teams did. So the 2026 releases from Microsoft, Proofpoint, Mimecast and KnowBe4 are aimed at a threat model that did not exist when most of these contracts were last signed: an inbound message written to instruct a machine rather than persuade a person.
Five capabilities are worth raising before your next renewal. What each one requires, what it actually costs, and where it still falls short.
1. Filtering the message for what the AI reads, not what the user sees
Every phishing control ever built assumes a human decision point. The user clicks or they don't. Vendors optimised hard around that assumption: rewrite the URL, detonate the attachment, flag the display name mismatch, coach the user to hover over links.
Connect Copilot to a mailbox and the decision point moves. Ask it to summarise the overnight inbox and it reads every message with roughly the same trust it gives your own instruction. An attacker who gets text in front of that model does not need anybody to click anything.
In March 2026 Microsoft published CVE-2026-26133, an AI command injection affecting Copilot across multiple Microsoft applications, demonstrated through the email summarisation surfaces in Outlook and Teams. A message arrives, nobody clicks anything, and the assistant acts on instructions the recipient never saw.
Two of the vendors now filter for this before the message is delivered.
Proofpoint's AI exploit detection sits inside Prime Threat Protection and reads the language of a message rather than its payload, looking for hidden prompts aimed at assistants such as Copilot and Gemini. Microsoft's version runs in the existing Defender for Office 365 filtering pipeline with no policy change and no admin opt-in, and analyses the message the way an assistant would receive it: subject and body including HTML markup, hidden or off-screen text that renders differently from the raw source, quoted and forwarded content further down the thread, and encoded segments normalised before analysis. Detections land under the High confidence phishing verdict with a new detection technology value, Prompt injection protection, which is filterable in Threat Explorer and Advanced Hunting.
Two practical points.
Microsoft's version is Plan 2 only. Plenty of UAE organisations have rolled Copilot across the business while running Defender for Office 365 Plan 1 or plain Exchange Online Protection for mail. Those tenants have an AI assistant reading every inbox and nothing inspecting the email channel for content aimed at it.
The second is coverage. This filters email. A poisoned document sitting in SharePoint, a malicious MCP tool description, a calendar invite body, all reach the same model through a different door.
2. Extending email security into the agentic workspace
The second wave of 2026 releases is built for exactly that gap. These are agent and data security products rather than email security products, and no procurement category currently owns them cleanly. They belong in this list because the agents they govern are reading your mail.
KnowBe4 launched Agent Risk Manager in April and extended it to Anthropic's Claude in August. It governs what an agent does once deployed rather than scanning its code beforehand, inventorying agents, watching for unauthorised actions such as sharing sensitive information, and picking up indirect prompt injection in the agent's execution path. KnowBe4's own 2026 research found 52% of respondents describing their organisation's AI use as unapproved or ungoverned.
Mimecast's Agent Risk Center opened in beta on 31 July 2026, with early access in September and general availability planned for January 2027 for Incydr subscribers. It runs off the endpoint agent and browser extension most Mimecast customers already have installed, discovering AI apps, MCP server connections and generative AI activity across the business, then applying policy through what Mimecast calls the AI Rulebook. You can sanction a tool across the organisation, block it by department, or nudge users toward an approved alternative.
Proofpoint's Secure Agent Gateway takes a third approach, mediating the sensitive information flowing into and out of agentic workflows over the Model Context Protocol. It has been in phased availability through 2026.
The inventory is what earns its keep here, ahead of any policy you apply afterwards. Most organisations cannot currently say which agents are running against their mail and files, who approved them, or what they connected to last week. Mimecast puts unsanctioned AI tool usage at 98% of organisations, which is high enough that it is worth measuring in your own environment rather than accepting on faith.
3. Clearing the abuse mailbox automatically
The abuse mailbox has been the worst job in security operations for fifteen years. Users report suspicious messages because they are unsure, and somebody has to open each one, check the sender, read the headers, close it, open the next.
Proofpoint's Satori Abuse Mailbox Agent goes at the specific bottleneck in that workflow, the Needs Manual Review queue, and clears thousands of NMR cases in seconds. It sits alongside a DLP Triage Agent and a Phishing Simulation Agent, in phased availability through 2026. Satori MCP Access is the more interesting piece, because it lets other agents invoke Proofpoint agents directly, CrowdStrike Charlotte and Microsoft Copilot included.
Mimecast has come at the same queue twice this year. In March it shipped the Mihra Investigation Agent, which synthesises the events behind an incident, summarises what it found and recommends a resolution, alongside redesigned response workflows that group reported messages by campaign. Mimecast claims 78% faster resolution of reported messages from that campaign identification. Then at Black Hat in August it announced Managed Threat Response, which takes the queue off you entirely: AI triages every reported email, a Mimecast analyst confirms the verdict, and confirmed threats get remediated. Mimecast pitches that one against the finding that 42% of security alerts go entirely uninvestigated. March also brought the Mihra MCP Gateway, which pipes Mimecast investigation workflows into whatever AI platform a team already uses, Claude and Gemini included. Both vendors are making the same architectural bet from opposite ends: Proofpoint exposes its agents to other tools, Mimecast exposes its investigation data to other models.
Microsoft's Phishing Triage Agent classifies user-reported mail on its own, correlates files, URLs and threat intelligence, explains its verdict in natural language, and draws a flow diagram of every step it took to reach it. The output feeds Automated Investigation and Response, which then hunts for similar messages and surfaces remediation actions for an analyst to approve.
Two things changed this year that matter if you looked at the Microsoft agent in 2025 and walked away.
The first is permissions. The original build required Email & Collaboration content: All Emails (read), meaning read access to every mailbox in the tenant. Microsoft narrowed that in mid-2026 to Emails associated with alerts (read). If your security architect killed the deployment over that scope, the objection has gone.
The second is money, and it is the bigger change. The agent needs Security Copilot capacity, metered in Security Compute Units. Provisioned standalone capacity costs $4 per SCU per hour and bills whether anyone uses it or not, so a single SCU running around the clock is roughly $2,920 a month. Microsoft also includes Security Copilot capacity with eligible Microsoft 365 E5 and E7 licensing under its current inclusion model, documented at 400 SCUs a month for every 1,000 paid licences and capped at 10,000 SCUs a month.
If you hold E5 or E7, you may already have the capacity to run this and not know it. Confirm the current inclusion terms and your own consumption in the tenant usage dashboard before budgeting for standalone capacity, because the commercial model has changed more than once.
While you are in the portal, disable the built-in Auto-Resolve - Email reported by user as malware or phish tuning rule. Leave it running and it closes the alerts before the agent ever sees them.
4. Following the attack out of the inbox
An enterprise attack rarely stays in the mailbox. A compromised supplier sends a message, the recipient clicks, credentials go into a page that looks right, and the attacker turns up in Teams two hours later using an identity nobody has flagged. Reviewed as separate email alerts, that sequence is almost invisible.
Mimecast changed its deployment model in March. The full detection stack is now available through API-based deployment against Microsoft 365, with no MX record change required, which matters for any organisation carrying complex transport rules it does not want to unpick. Running through the API rather than in front of the mail flow also means post-delivery remediation: a message already sitting in an inbox can be pulled once it is identified as malicious. The Human Risk Command Center now correlates signal across email, endpoint, identity, data and generative AI activity, along with third-party security tools, so a click and a subsequent odd sign-in land in the same view rather than two consoles.
Proofpoint went at it through correlation rather than deployment. Prime now covers threats arriving through compromised internal accounts, SaaS accounts and supplier accounts, across mobile and collaboration channels. Threat Interaction Map, released in Q1 2026, plots a user's interaction with a threat across channels and stages, separating a clean path from one where somebody clicked the link, entered credentials, and generated a suspicious login twenty minutes later.
Supplier compromise is the case none of this fully solves. A payment instruction arriving inside an existing thread from a genuinely compromised supplier account passes SPF, passes DKIM, aligns for DMARC, and comes from a sender your finance team has emailed forty times. IBM puts supply chain compromise at 16% of breaches in 2026, at an average of $8.45 million. Out-of-band verification on any change to bank details, called back on a number you already held, is still the control that works.
5. Training that responds to what someone actually did
Awareness training has traditionally run on a separate clock from the SOC. An analyst investigates a phishing campaign in March. The awareness team builds a generic simulation about something similar in September.
Proofpoint's AI ThreatFlip closes that gap by taking a real phishing email caught in your environment, stripping the malicious elements and any sensitive content, and converting what remains into a live simulation that keeps the characteristics of the original attack.
KnowBe4's AIDA Orchestration, available since February 2026, removes campaign management entirely instead. It is the eighth agent in that suite, and it creates, schedules and adapts phishing tests and training per user against that person's risk profile rather than firing the same quarterly campaign at everyone. KnowBe4 also added simulated vishing this year, which matters because voice cloning now needs roughly 30 seconds of source audio and most executives have that much public speech online.
Mimecast turns the same Human Risk Command Center signal into policy, adjusting controls automatically against an individual user's risk score, so somebody who clicks gets tighter restrictions straight away rather than after a review. Mimecast's data puts 8% of employees behind 80% of incidents, while only 28% of organisations coordinate training with continuous monitoring.
KnowBe4's 2026 Phishing by Industry Benchmarking Report, built from 42 million simulations across 14.8 million users at 64,000 organisations, found susceptibility dropping 79% after a year of consistent training. KnowBe4 frames that against a threat environment increasingly driven by AI, which should give pause to anyone who had written off awareness training as outrun by generative tooling.
What is actually available today
Announcements and shipping products are not the same thing. As of late August 2026:
| Capability | Vendor | Status |
|---|---|---|
| Prompt injection detection in mail | Microsoft | Live in Defender for Office 365 Plan 2, on by default |
| AI exploit detection over email | Proofpoint | Available in Prime Threat Protection |
| Phishing Triage Agent | Microsoft | GA, needs Plan 2 plus Security Copilot capacity |
| Threat Interaction Map | Proofpoint | Released Q1 2026 |
| Satori Abuse Mailbox Agent | Proofpoint | Phased availability during 2026 |
| Managed Threat Response | Mimecast | Announced August 2026 |
| Mihra Investigation Agent | Mimecast | Released March 2026 |
| API-based deployment of full detection stack | Mimecast | Released March 2026 |
| Agent Risk Center | Mimecast | Beta 31 July 2026, GA planned January 2027 |
| Agent Risk Manager | KnowBe4 | Launched April 2026 |
| AI ThreatFlip | Proofpoint | Announced for 2026 rollout |
| AIDA Orchestration | KnowBe4 | Available since February 2026 |
| Secure Agent Gateway | Proofpoint | Phased availability |
Availability moves quickly and varies by region and licence tier, so confirm the specific SKU before treating an announced capability as something you already own.
The honest limits
None of this is finished technology, and the vendor material does not dwell on where it stops.
Prompt injection detection is a classifier, and classifiers degrade outside the data they were trained on. Published research on injection detection reports balanced accuracy falling from above 90% into the low 80s once ordinary benign text is mixed in, and lower again on multilanguage attacks.
Multilingual testing deserves particular attention in the Gulf. That research does not measure the vendor products described above, and no vendor publishes detection rates specifically for Arabic and English enterprise mail. What it does establish is that performance can vary by language and attack format, which is reason enough to test the capability against the languages and message formats your own environment actually uses rather than relying on vendor benchmarks alone.
Academic evaluation of the wider category is less flattering still. Independent testing of general-purpose AI guardrail classifiers, the open models used to screen prompts going into LLM applications, found detection rates between 7% and 37% on indirect injection attacks aimed at agents rather than at chat interfaces. Those are not the Microsoft, Proofpoint or Mimecast mail filters, and the figures should not be read as their detection rates. They are a useful indication of how immature this detection problem is across the field.
The email-layer filter is also a second line rather than a first. Copilot already carries its own input filtering and prompt-separation safeguards, and CVE-2026-26133 got past those. Worth turning the new layer on, and not a reason to relax anything else.
The other limit is scope. Every control described here inspects a channel. An agent holding a valid OAuth grant, reading SharePoint and calling MCP tools, sits outside all of them.
Questions for the renewal conversation
Most email security reviews still open with block rates and false positive counts. Those numbers say very little about the five capabilities above. Five better questions:
Can the platform detect content written to manipulate an AI assistant, rather than only content written to deceive an employee?
Can it investigate user-reported mail without granting an agent standing read access to every mailbox in the tenant?
Can it connect an email event to what happened afterwards in identity, browser and collaboration logs?
Can it turn a real attack caught in our environment into user training in days rather than months?
Can it tell us which AI agents currently have access to corporate email and files, and who approved them?
What to do in the next 30 days
Four checks, in order of how quickly they pay off.
Confirm your Defender for Office 365 plan. Prompt injection detection is Plan 2. If Copilot is deployed across the business and mail sits on Plan 1 or EOP, that is the gap to close first, and closing it takes a licensing conversation.
Check whether Security Copilot capacity is already available to your tenant under the E5 or E7 inclusion, and what your current consumption looks like. Plenty of organisations have the entitlement and have never opened the usage dashboard.
Run an inventory of AI agents and MCP connections touching mail and files, using whatever your incumbent vendor now offers. The answer is usually larger than expected, and it is the prerequisite for every other control in this list.
Then test the injection filter in the languages your business actually writes in. Send yourself a benign message carrying hidden instructions in Arabic, then one mixing Arabic and English in a single thread, and record what verdict comes back. No vendor publishes detection rates for that case, so the only figure you can rely on is one you generate yourself.