
Kiteworks Buys Bonfy.AI for Runtime AI Data Control
Kiteworks is buying Bonfy.AI to classify and enforce policy on sensitive data the moment it moves, across human workflows and AI-agent traffic.
Kiteworks Acquires an AI-Native Content Security Platform
Kiteworks announced on September 11 that it is acquiring Bonfy.AI, an AI-native content security company whose product classifies sensitive data and enforces policy at the moment that data moves — not after the fact. Financial terms were not disclosed, though Israeli outlet CTech estimated the price in the tens of millions of dollars. It is Kiteworks' eighth acquisition in five years.
- What Bonfy.AI does: real-time classification and enforcement of sensitive data across both human workflows and AI-agent interactions
- When enforcement happens: inline, before a transfer completes, rather than in a post-hoc audit
- Company background: founded in early 2024, emerged from stealth June 2025 with $9.5 million in seed funding
- Deal terms: undisclosed; CTech estimated tens of millions of dollars
Why "Runtime" Is the Word That Matters Here
Most data security programs are built around cataloging. You scan your repositories, label what is sensitive, and build a map of where the crown jewels live. That is necessary work, and it is also incomplete — a catalog tells you what you have, not what happens to it at 2pm on a Tuesday when someone pastes a customer list into a chat window.
Kiteworks framed the acquisition around exactly that gap. Chief strategy officer Tim Freestone put it as maintaining control over private data everywhere it moves, and noted that inline classification at runtime is what makes that promise complete. The distinction is between knowing and intervening.
That gap has widened considerably with AI agents in the picture. An agent with tool access reads from one system, reasons over the contents, and writes to another — often in a single unattended sequence. A nightly scan will find the result. Only an inline control can shape the transfer while it is happening.
What Does This Change for Security Teams?
The practical appeal is a single policy model applied to people, machines and systems rather than three separate ones. Most organizations today run a DLP product for human email and file sharing, a separate set of guardrails for AI tools, and effectively nothing purpose-built for agent-to-system traffic. Consolidating those onto one enforcement point reduces the number of places a policy can quietly disagree with itself.
It also fits a pattern worth naming: security vendors are buying AI-native startups rather than retrofitting existing engines. Content classification that has to reason about intent and context — is this a genuine business transfer or a sensitive leak wearing business clothes — is a different problem from pattern-matching credit card numbers, and it tends to want a different architecture underneath.
The usual caveats apply to any acquisition announcement. Deal terms are undisclosed, no integration timeline has been published, and Bonfy.AI is a young company whose product will now have to scale onto a much larger customer base. Claims about real-time enforcement are best evaluated in your own environment, on your own traffic.
For adjacent reading, our pieces on AI security reviews landing in WordPress plugin updates and the ORKS revocable API key standard cover the same shift toward controls that act at the moment of use. More in our AI security coverage.
Sources: SecurityWeek — September 11, 2026; Help Net Security — September 11, 2026.
More Ai Security Stories

OpenAI and AARP Help Older Adults Spot Online Scams
More than 1,000 older adults across 10 US cities joined free AI Skills Jam workshops on using ChatGPT safely and recognising attempted scams.

Postman Passport Gives AI Agents Keyless API Access
Passport hands agents a cryptographic reference instead of a real API key, keeping credentials inside your network and revocable in seconds.

Zanzibar-Style Authorization Explained for Developers
A practical guide to relationship-based access control: how Google Zanzibar works, when ReBAC beats roles, and what open-source options exist in 2026.
