Etay Maor is Vice President of Threat Intelligence for Cato Networks, a leader of advanced cloud-native cybersecurity technologies.

AI has upended thinking behind the traditional security framework in more ways than one. The conventional security framework, which is trusted by most CISOs, is rooted in the simple idea that risk travels through visible assets, including files, networks and applications. Accordingly, cybersecurity posture is underpinned by (but not limited to) firewalls inspecting traffic, data loss prevention (DLP) scanning files and email, and cloud access security brokers (CASB) governing SaaS activity.

AI is breaking this model. It doesn’t move through a file; it moves through a prompt, the model’s response to this prompt, and a chain of actions that the AI agent has agency to take on its own. The boundaries that the security arsenal had to defend earlier were very clear, but not so much now with the rise of AI. This is a whole new attack surface.

Governance Not Keeping Up With Adoption

AI agents are already widely used, with 43% of organizations reporting that more than half of their employees use them regularly. But there are significant control gaps. Fifty-three percent said agents occasionally or sometimes exceed their intended permissions, while 44% had little or no confidence in detecting agent-specific threats. Yet only 31% had formally adopted a policy governing AI agent use.

That combination of widespread adoption, limited oversight and weak threat detection makes for a scenario with serious business repercussions. AI security, therefore, cannot be seen purely from a technical prism, but has to move up the ladder and become a leadership issue.

The pressure is coming from multiple directions. Boards are looking for more accountability, and regulators want stronger controls. There is also internal pressure from business leaders who want to adopt AI but need more evidence that autonomous systems don’t disrupt operations or make unauthorized decisions.

Your customers also want clear and concrete assurance that their data remains protected in the age of AI. You therefore need to stop asking whether AI poses a risk, but whether your organization can manage AI without the associated risk.

Four Areas Where Traditional Controls Fall Short

1. Unsanctioned AI Use

You might have an AI governance policy implementation timeline in place, after which you will allow the use of authorized tools. But employees are not waiting for approval. They are already looking for AI tools to speed up tasks and improve efficiency. In fact, Gartner research reveals that 69% of enterprises already suspect or have concrete proof that staff members are using banned public AI tools.

Imagine a sales executive pasting customer data into a public chatbot or a software developer giving an AI coding assistant access to the company’s private code repository. None of these actions are either logged or approved. With one in five organizations experiencing a breach linked to shadow AI in 2025, there is no doubt that such actions increase AI risk.

2. Sensitive Data Leakage

Developers can knowingly or unknowingly share API keys and credentials while chatting with AI coding assistants. This action can put production environments in danger. AI tools can even summarize documents containing sensitive information and share them onward, without users realizing it has done so. Per reporting from TechTarget, analysis from Gartner projects that at least 80% of unauthorized AI activity will stem from internal policy violations rather than external attackers. The problem is that traditional DLP is not built to inspect the AI interaction layer.

3. AI Failing In Ways Testing Can’t Catch

AI is making its way into co-pilots, internal tools and customer-facing apps. These applications can access company systems, use sensitive data and take actions on a user’s behalf. But this means two problems rear their heads again and again:

• Prompt Injection: The model treats an attacker’s text as a trusted instruction.

• Jailbreaking: Clever framing gets the model to ignore its own safety rules.​

In a now real-world case, a car dealership’s chatbot was pranked by users who asked it to write code (it did) or agree to sell a car for one dollar (it didn’t). And while the chatbot generally handlded these requests well, it’s important to note that even without being hacked, models are trained to follow whatever instructions it receives.

4. A Lack Of A Human Safety Net

AI agents with agency do not wait for your next message. They call APIs, chain actions together and move across systems on their own to deliver an output. Zero trust verifies each request against a fixed identity and scope, but it doesn’t reason for the sequence of actions an agent takes, or what that sequence adds up to across systems. A recent study found that 91% of organizations have no way to step in before an AI agent executes a harmful action.

What You Need To Do

Traditional tools monitor data at rest or in transit. But AI risk emerges in interactions, model behavior and autonomous decisions. CASB and DLP still matter, but we must add a security layer for AI risk.

Find out where AI is used, by whom, and with what data. Then, build governance covering employee tools, custom applications and independent agents.

Crucially, we must move to AI anomaly detection. It is no longer enough to authenticate an agent or a session; security now requires assessing specific actions as high risk to allow or block them. This ensures you implement AI with confidence, reducing risk while improving ROI.

Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Share.
Leave A Reply

Exit mobile version