Bonfy has announced Contextual Data Enforcement, a new capability in the Bonfy platform that introduces a control layer between AI clients and enterprise data, enabling organizations to govern what content AI systems can retrieve and use in real time—beyond native user permissions, and without new infrastructure.
The problem is simple and dangerous: AI agents, assistants and coding tools such as Claude, Copilot, and ChatGPT are being adopted at an accelerated rate across the enterprise. Very quickly, organizations are discovering a sharp mismatch: AI clients can connect to SharePoint, Google Drive, and other data stores instantly, but the underlying security tooling has no way to enforce content-level policies on what those AI systems retrieve. Native permissions determine what users can access. They do not determine what AI should be allowed to retrieve, use, or expose. The result is a significant and growing security blind spot with long-term implications.
A Missing Layer — Now Filled
Bonfy provides a governed connector path that intercepts and controls data retrieval performed through AI clients. As content flows back from Microsoft 365 or Google Workspace, Bonfy inspects it in real time, applying entity-aware, context-rich analysis, and blocks content that violates policy before it reaches the AI clients.
What the Platform Delivers
- Control what AI can retrieve and use — enforce policies beyond user permissions
- Protect sensitive and customer data — even when users have access
- No infrastructure changes — no gateways or architectural overhaul
- Preserve identity context — never expands user access
- Works across AI clients — compatible with Claude, Copilot, ChatGPT and others
Why This Matters Now
Security teams are being asked to enable AI agents and assistants across enterprise workflows—often before they have visibility into what data those systems will retrieve and use.
Once AI clients connect to Microsoft 365, SharePoint, or Google Drive, they inherit the user’s access and can retrieve large volumes of enterprise data. But native permissions do not determine what an AI system should be allowed to retrieve, ground on, or expose.
This creates a critical gap between access control and data protection—one that is already impacting real enterprise workflows.
Bonfy’s approach is different: built on the existing Bonfy engine that today protects email, browser flows, and file sharing, and extends it to AI data access and usage with a lightweight connector swap. No new analytics. No new architecture. Just a missing layer finally put in place.
Bonfy’s new capability pairs with Bonfy’s MCP inspection server, announced earlier this year, to cover both data in use (AI reasoning loops) and data access (AI retrieval). Together, they form the first comprehensive data security model for modern AI workflows.Availability: Bonfy’s Contextual Data Enforcement is available today with support for Microsoft 365 and Google Workspace, supporting Anthropic Claude and Microsoft Copilot Studio, and OpenAI ChatGPT. Additional enterprise data sources will be added continuously.
Guest Post: Pressing political topics reduce people’s vigilance against bots
Posted in Commentary with tags Surfshark on May 19, 2026 by itnerdMore than 700 participants took part in a week-long experiment conducted by Surfshark and MSc students from Malmö University. Of them, 53% correctly identified more bots than they wrongly flagged humans as bots on the simulated social platforms. However, nearly half (47%) failed the task. A cybersecurity expert warns that the number of people unable to tell bots from real humans on social media will continue to grow rapidly.
“The ‘Bot or Not’ game and experiment help us keep connecting the dots and better understand the influence bad bots have on us, real social media users. Earlier this year, we found that major platforms remove over 6.3 billion fake accounts every year — roughly 47 times the annual number of babies born worldwide (around 135 million). Bots are being generated by the billions, and our latest experiment shows that half of the participants can no longer tell them apart from real people. This trend will accelerate, as the technology lets bots blend in seamlessly with real human profiles,” says Justas Pukys, Senior Product Manager at Surfshark.
When our emotions take over, bots thrive
The results of the recent social media bot experiment were eye-opening. The data suggests that engaging with sensitive political or social topics may reduce people’s ability to spot bots and make them more likely to falsely accuse real people.
The moment the “Bot or Not” simulation shifted to a more emotional tone, our participants’ bot-detection skills dropped. When the debate turned political and focused on immigration, participants’ bot-detection rate dropped to 54%, meaning that nearly half the social media bots slipped right past the players. Participants’ accuracy rate also declined to 63%, showing a spike in internet paranoia when participants accused humans of being bots.
The women’s rights topic presented the biggest bot-spotting challenges. The bot-detection rate crashed to 49%, meaning users missed more bots than they found. Worse, their accuracy rate fell to 61%, showing players most often accused real human content of being bot-generated.
“In comparison, while engaging in the data centers, a more technical debate for many, users performed the largest bot-detection rate of 71% (finding the majority of the bots), and a high (76%) accuracy rate. This suggests that when not directly emotionally triggered, we could detect more AI bots and are less likely to falsely accuse real humans,” explains Luís Costa, Research Lead at Surfshark.
The “Bot or Not” game is now online for everyone to play and take part.
Can we distinguish who is who on social platforms in the future?
“The experiment’s results are novel and significant. They suggest we can’t simply ‘read’ our way out of ‘botted’ social media. Bot-detection skills appear to be shaped by age, preferred platforms, and time spent on them. But the most striking finding was that our biggest blind spot is emotion: when debates get heated, it hijacks our digital radar.
To fight back against automated deception, we don’t need better textual analysis. We need a cooler head and a deeper awareness of our own vulnerabilities,” claims Luís Costa.
Justas Pukys, a cybersecurity expert at Surfshark, shares practical recommendations.
“Don’t forget to double-check the information you find on social media. Also, don’t take everything random users post at face value. Be careful when accepting and interacting with private messages that offer you prizes, invite you to click on strange links, or try to grab your attention with lines like ‘Your family member has been in an accident!’,” he advises.
The expert also highlights the importance of digital security hygiene, such as using anti-scam tools daily. They will help you analyze the content of emails, text messages, and websites and assess whether it has been generated by bots or other attackers.
This “Bot or Not” experiment inspired the launch of Surfshark’s Cybersecurity Advocacy Fund, which provides up to €100,000 in annual financial support distributed among students, researchers, and creative cybersecurity awareness initiatives worldwide. The upcoming application process will open in September 2026 — more information will follow.
METHODOLOGY
This bot-detection study analyzed data from 710 participants who played the interactive simulation “Bot or Not.” This machine and gameplay were created by Interaction Design students from Malmö University for the UNFOLD exhibition — a design competition for universities around the world during Milan Design Week, the world’s largest trade fair. Throughout the week-long public exhibition, visitors were invited to take part in the experiment.
Please find the full research methodology here.
Leave a comment »