TechNewsReel
Live

Kiteworks Acquires Bonfy.AI to Enable Runtime Governance for AI Agents

The acquisition integrates real-time inline data classification to stop sensitive leaks during active data exchanges.

TechNewsReel Newsroom · September 12, 2026

Kiteworks has acquired Bonfy.AI, an Israeli cybersecurity startup, to integrate real-time inline data classification and policy enforcement into its security platform. The move allows organizations to govern sensitive data exchanges as they happen across email, SaaS applications, and AI workflows.

By incorporating Bonfy.AI’s technology into the Kiteworks control plane, the company now provides runtime data governance for both human users and AI agents. This capability extends to AI assistants including ChatGPT, Claude, and Microsoft 365 Copilot, as well as traditional file sharing and email. The shift moves data security away from retrospective reporting—often referred to as posture management—toward active runtime policy decisions. These decisions evaluate the full context of an exchange, including the sender, recipient, and business purpose, before the data transfer is completed.

The Shift to Data in Motion

Historically, enterprise security has focused on data discovery and posture management, which primarily address data at rest. However, Kiteworks argues that the primary risk emerges when data is in motion. Gidi Cohen, CEO and Founder of Bonfy.AI, noted that risk is created when data moves rather than when it sits, requiring the ability to read the full context of an exchange at runtime.

This acquisition marks the eighth purchase by Kiteworks in under five years as it works to build a comprehensive data security and compliance platform. Bonfy.AI previously emerged from stealth with a $9.5 million seed round to address these specific gaps in inline governance.

Implications for AI Governance

As enterprises increasingly deploy autonomous AI agents and Large Language Models (LLMs), traditional pattern-matching security tools have become insufficient. Runtime governance enables a unified policy model that treats AI agents and humans identically, ensuring sensitive information does not leak through automated workflows or AI-generated responses.

Beyond immediate prevention, the integration focuses on auditable compliance for strict regulatory frameworks such as GDPR, HIPAA, and CMMC 2.0. Tim Freestone, Chief Strategy Officer at Kiteworks, stated that while knowing where sensitive data lives is important, the ability to decide in the instant data leaves whether it should be allowed—and proving that decision to a regulator months later—represents a critical gap the company is now closing.

Future Outlook

Industry observers will be watching how Kiteworks scales these runtime controls across diverse SaaS ecosystems. While the technical integration into the control plane is the immediate priority, the broader challenge remains the seamless enforcement of policies across a fragmented landscape of third-party AI tools and legacy enterprise software.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.