On Thursday, Box launched its developer convention Boxworks by announcing a caller group of AI features, building agentic AI models into nan backbone of nan company’s products.
It’s much merchandise announcements than accustomed for nan conference, reflecting nan progressively accelerated gait of AI improvement astatine nan company: Box launched its AI workplace past year, followed by a caller group of data-extraction agents in February, and others for hunt and heavy investigation in May.
Now, nan institution is rolling retired a caller strategy called Box Automate that useful arsenic a benignant of operating strategy for AI agents, breaking workflows into different segments that tin beryllium augmented pinch AI arsenic necessary.
I said pinch CEO Aaron Levie astir nan company’s attack to AI, and nan perilous activity of competing pinch instauration exemplary companies. Unsurprisingly, he was very bullish astir nan possibilities for AI agents successful nan modern workplace, but he was besides clear-eyed astir nan limitations of existent models and really to negociate those limitations pinch existing technology.
This question and reply has been edited for magnitude and clarity.
TechCrunch: You’re announcing a bunch of AI products today, truthful I want to commencement by asking astir nan big-picture vision. Why build AI agents into a unreality content-management service?
Aaron Levie: So nan point that we deliberation astir each time agelong – and what our attraction is astatine Box – is really overmuch activity is changing owed to AI. And nan immense mostly of nan effect correct now is connected workflows involving unstructured data. We’ve already been capable to automate thing that deals pinch system information that goes into a database. If you deliberation astir CRM systems, ERP systems, HR systems, we’ve already had years of automation successful that space. But wherever we’ve ne'er had automation is thing that touches unstructured data.
Techcrunch event
San Francisco | October 27-29, 2025
Think astir immoderate benignant of ineligible reappraisal process, immoderate benignant of trading plus guidance process, immoderate benignant of M&A woody reappraisal — each of those workflows woody pinch tons of unstructured data. People person to reappraisal that data, make updates to it, make decisions and truthful on. We’ve ne'er been capable to bring overmuch automation to those workflows. We’ve been capable to benignant of picture them successful software, but computers conscionable haven’t been bully capable astatine reference a archive aliases looking astatine a trading asset.
So for us, AI agents mean that, for nan first clip ever, we tin really pat into each of this unstructured data.
TC: What astir nan risks of deploying agents successful a business context? Some of your customers must beryllium tense astir deploying thing for illustration this connected delicate data.
Levie: What we’ve been seeing from customers is they want to cognize that each azygous clip they tally that workflow, nan supplier is going to execute much aliases little nan aforesaid way, astatine nan aforesaid constituent successful nan workflow, and not person things benignant of spell disconnected nan rails. You don’t want to person an supplier make immoderate compounding correction where, aft they do nan first mates 100 submissions, they commencement to benignant of tally wild.
It becomes really important to person nan correct demarcation points, wherever nan supplier starts and nan different parts of nan strategy end. For each workflow, there’s this mobility of what needs to person deterministic guardrails, and what tin beryllium afloat agentic and non-deterministic.
What you tin do pinch Box Automate is determine really overmuch activity you want each individual supplier to do earlier it hands disconnected to a different agent. So you mightiness person a submission supplier that’s abstracted from nan reappraisal agent, and truthful on. It’s allowing you to fundamentally deploy AI agents astatine standard successful immoderate benignant of workflow aliases business process successful nan organization.

TC: What benignant of problems do you defender against by splitting up nan workflow?
Levie: We’ve already seen immoderate of nan limitations moreover successful nan astir precocious afloat agentic systems for illustration Claude Code. At immoderate constituent successful nan task, nan exemplary runs retired of context-window room to proceed making bully decisions. There’s nary free luncheon correct now successful AI. You can’t conscionable person a long-running supplier pinch unlimited discourse model spell aft immoderate task successful your business. So you person to break up nan workflow and usage sub-agents.
I deliberation we’re successful nan era of discourse wrong AI. What AI models and agents request is context, and nan discourse that they request to activity disconnected is sitting wrong your unstructured data. So our full strategy is really designed to fig retired what discourse you tin springiness nan AI supplier to guarantee that they execute arsenic efficaciously arsenic possible.
TC: There is simply a bigger statement successful nan manufacture astir nan benefits of big, powerful frontier models compared to models that are smaller and much reliable. Does this put you connected nan broadside of nan smaller models?
Levie: I should astir apt clarify: Nothing astir our strategy prevents nan task from being arbitrarily agelong aliases complex. What we’re trying to do is create nan correct guardrails truthful that you get to determine really agentic you want that task to be.
We don’t person a peculiar accuracy arsenic to wherever group should beryllium connected that continuum. We’re conscionable trying to creation a future-proof architecture. We’ve designed this successful specified a measurement where, arsenic nan models amended and arsenic agentic capabilities improve, you will conscionable get each of those benefits straight successful our platform.
TC: The different interest is information control. Because models are trained connected truthful overmuch data, there’s a existent fearfulness that delicate information will get regurgitated aliases misused. How does that facet in?
Levie: It’s wherever a batch of AI deployments spell wrong. People think, “Hey, this is easy. I’ll springiness an AI exemplary entree to each of my unstructured data, and it’ll reply questions for people.” And past it starts to springiness you answers connected information that you don’t person entree to aliases you shouldn’t person entree to. You request a very powerful furniture that handles entree controls, information security, permissions, information governance, compliance, everything.
So we’re benefiting from nan mates decades that we’ve spent building up a strategy that fundamentally handles that nonstop problem: How do you guarantee only nan correct personification has entree to each portion of information successful nan enterprise? So erstwhile an supplier answers a question, you cognize deterministically that it can’t tie connected immoderate information that that personification shouldn’t person entree to. That is conscionable thing fundamentally built into our system.
TC: Earlier this week, Anthropic released a caller characteristic for straight uploading files to Claude.ai. It’s a agelong measurement from nan benignant of record guidance that Box does, but you must beryllium reasoning astir imaginable title from nan instauration exemplary companies. How do you attack that strategically?
Levie: So if you deliberation astir what enterprises request erstwhile they deploy AI astatine scale, they request security, permissions and control. They request nan personification interface, they request powerful APIs, they want their prime of AI models, because 1 day, 1 AI exemplary powers immoderate usage lawsuit for them that is amended than another, but past that mightiness change, and they don’t want to beryllium locked into 1 peculiar platform.
So what we’ve built is simply a strategy that lets you person efficaciously each of those capabilities. We’re doing nan storage, nan security, nan permissions, nan vector embedding, and we link to each starring AI exemplary that’s retired there.