Nidhi Jain is CEO & Founder of CloudEagle.ai, a platform helping enterprises govern SaaS, identities, and AI agents at scale.
Every SaaS app in your stack shipped an AI feature in the past 18 months. Microsoft 365 got Copilot. Salesforce got Einstein and Agentforce. Slack got Slack AI. Zoom got AI Companion. Notion, GitHub, ServiceNow, HubSpot and Atlassian each added their own.
None of them appeared in vendor security reviews, and most SaaS security posture management (SSPM) tools were not built to detect them.
The consequences are no longer hypothetical. In February 2026, Microsoft admin advisory CW1226324 confirmed that Copilot Chat had been reading and summarizing emails marked “confidential” from users’ Sent Items and Drafts for weeks, bypassing the DLP policies configured to block exactly that.
Eight months earlier, researchers disclosed EchoLeak (CVE-2025-32711), a zero-click Copilot vulnerability rated CVSS 9.3 that exfiltrated enterprise data through a single crafted email. Neither incident involved a compromised credential or a misconfigured permission. Both originated inside an AI feature the vendor shipped into a sanctioned app.
Gartner predicts that 40% of enterprise applications will feature task-specific AI agents by the end of 2026, up from less than 5% in 2025. Every one of those features touches data your existing SSPM was never configured to govern.
The AI Inside Your SaaS Is A Different Threat Model
In almost every conversation I have with a CISO, the assumption is the same: Their SSPM covers SaaS security. It covers configuration drift, over-permissioned users and third-party OAuth grants. It does not cover AI features shipping into the tools they already approved.
An AI feature inside a sanctioned SaaS app:
• Reads across data sources you did not authorize: Microsoft 365 Copilot pulls from SharePoint, OneDrive, Outlook and Teams in a single query, often surfacing files the user could not previously find.
• Generates new data outside your classification framework: Slack AI summarizes channels an employee has access to, but the summary becomes new content with no source-level classification.
• Writes back to production systems: Salesforce Einstein and Agentforce can create records, update opportunities and send emails. These are nonhuman identity actions inside your CRM.
• Uses a model provider your DPA never mentioned: Many SaaS vendors route data through OpenAI, Anthropic or Google models under the hood. Your existing contract likely does not cover this.
Your SSPM catches misconfigured permissions. It does not catch a co-pilot summarizing a customer contract into a Slack thread.
How To Discover Every AI Feature In Your Stack
Most CISOs I speak with assume they have an AI inventory. Here’s how to build the one they actually need.
1. Audit your top 20 SaaS vendors for AI features shipped in the last 12 months: Focus on Microsoft 365, Salesforce, Slack, Zoom, Google Workspace, Notion, GitHub, HubSpot, ServiceNow and Atlassian. Every one of them has released AI capabilities that likely were not reviewed.
2. Pull admin console reports for AI feature usage: Microsoft 365 admin center, Salesforce Setup, Slack admin analytics and Google Workspace admin all expose AI usage data. Most security teams have not enabled these.
3. Cross-reference with OAuth grants and API activity: AI features often authenticate through OAuth. Grants to unfamiliar app IDs, especially those tied to model providers, are a signal.
4. Interview business function leaders: Marketing, sales and product teams tend to enable AI features first. A 20-minute conversation surfaces more than a network scan.
How To Govern AI Features Without Blocking Adoption
Discovery is useless without a governance layer, and blocking AI features backfires just as blocking ChatGPT did.
1. Classify AI features by data sensitivity rather than tool brand. An AI meeting summarizer is a different risk than an AI feature that writes to your CRM or ERP.
2. Turn off features that write back to production systems by default. Enable them only for defined use cases with named human owners. Salesforce Agentforce, ServiceNow Now Assist and Atlassian Rovo all default to write-enabled in many tenants.
3. Configure data boundaries at the tenant level. Microsoft Purview, Google DLP and Salesforce Shield offer AI-aware data controls. Most enterprises have the licenses but have not enabled the AI-specific configurations.
4. Require vendor disclosure of model providers. Every renewal should include a clause requiring the vendor to disclose which models process your data and whether that data is used for training.
The Concerns That Slow Programs Down
Three objections come up in almost every conversation I have with a security leader starting this work.
• “We cannot renegotiate 200 vendor contracts.” Nobody has to. Prioritize the top 20 by data sensitivity; that covers 80% of your exposure.
• “Turning off AI features will kill business adoption.” Default write-back features to off, keep read-only on. Business teams keep the productivity, security keeps the guardrails.
• “Nobody owns this internally.” AI feature governance stalls when it falls between security, legal or procurement. The companies moving fastest appoint a cross-functional AI lead who reports to the CISO.
What The Industry Owes Enterprises
The pace of AI feature releases has outrun what enterprises can review, and vendors have benefited from that gap.
SSPM providers need to make AI feature discovery a native capability instead of a road map item. SaaS vendors need to notify customers in plain language when AI features ship, before enablement rather than after.
Model provider disclosure needs to become standard in every DPA and MSA. Frameworks like the Cloud Security Alliance’s Cloud Controls Matrix need to add AI feature governance as an explicit control domain instead of an implementation detail.
Right now, the enterprises leading on AI feature security are doing the vendors’ work for them. That will not scale.
You Cannot Govern What Your Vendors Just Shipped
The next SaaS breach will not look like a misconfiguration. It will look like an AI feature summarizing a contract, drafting an email or writing to a record, using credentials your team never provisioned for that purpose.
Discovery, classification and governance of AI features is now a continuous control instead of a quarterly checkbox. The AI is already inside your SaaS stack. Whether it is secured this quarter is the only question worth answering.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

