By NHI Mgmt Group Editorial TeamDomain: AI SecuritySource: CyberhavenPublished April 14, 2026

TL;DR: AI is changing how sensitive data moves through prompts, agents, summarisation tools, and third-party models, creating structural gaps in legacy DLP and DSPM programs, according to Cyberhaven. Security teams now have to treat AI risk as a design input, because point-in-time controls cannot keep pace with data that is copied, transformed, and re-entered through AI sessions.


At a glance

What this is: This is a data security argument that says AI risk must be built into the stack from the start, because AI changes how sensitive data moves and where existing controls fail.

Why it matters: It matters because IAM-adjacent data controls, governance workflows, and identity-aware enforcement increasingly need to account for shadow AI, agentic AI workflows, and data movement across sessions rather than static locations.

By the numbers:

👉 Read Cyberhaven's analysis of making AI security foundational to the data stack


Context

AI security is becoming a data governance problem, not just a tooling category. Traditional DLP and DSPM assume that sensitive data stays within identifiable repositories and flows through channels that can be inspected after the fact. AI breaks that assumption because prompts, summarisation layers, browser sessions, and agentic workflows move data in ways legacy controls were not designed to observe.

The identity intersection is real even in a data security article. AI agents, shadow AI tools, and third-party models create new runtime surfaces where access, data lineage, and policy enforcement have to travel together. That is why the most useful question for practitioners is not whether AI should be added to the stack, but whether the stack can govern AI-mediated data movement at all.


Key questions

Q: How should security teams govern sensitive data used by AI systems?

A: Security teams should treat AI as a data consumer that needs policy boundaries, not just authentication. Classify sensitive data, define which datasets may enter AI workflows, and monitor outputs, logs, and downstream reuse. If governance stops at login, the organisation can approve access while still losing control of the data itself.

Q: Why do legacy DLP tools struggle with AI workflows?

A: Legacy DLP was built for files, email, and pattern matching, not for free-form prompts, embedded copilots, or agentic connections. Sensitive data in AI often appears inside natural language or code, where regex rules miss context. The result is a coverage gap, especially outside browsers and classic transfer channels.

Q: What breaks when organisations add AI security after DLP and DSPM are already deployed?

A: The stack ends up with isolated visibility. DSPM can find data at rest, DLP can watch some transfers, but neither can reliably govern what happens when data is copied into an AI tool and returned in a different form. The result is a control gap at the moment of highest exposure, not a minor coverage issue.

Q: Should organisations prioritise AI data governance before scaling AI adoption?

A: Yes. Organisations that scale AI before establishing discovery, classification, monitoring, and policy enforcement are effectively expanding the attack surface faster than they can govern it. AI adoption should be matched with controls that follow the data lifecycle, otherwise compliance, exposure, and misuse risks compound as usage grows.


Technical breakdown

Why legacy DLP fails inside AI sessions

Legacy DLP was built to inspect known formats moving through known channels, such as files, email, and web uploads. AI sessions break that model because data is copied into prompts, transformed by a model, and returned in new forms that no longer match the original fingerprint. Network controls often miss browser-based AI activity, while pattern matching cannot reliably follow semantically changed content. The architectural gap is not a tuning problem. It is a mismatch between static inspection and dynamic data transformation.

Practical implication: extend enforcement to AI interaction points, not just file and email gateways.

How DSPM and data lineage change AI governance

DSPM identifies where sensitive data lives, but AI governance needs lineage, meaning the ability to track where data came from, how it moved, and what sensitivity it carries as it enters AI tools. Without lineage, policy decisions are disconnected from actual data movement. With lineage, controls can be tied to the source and classification of the data rather than the location of the tool receiving it. That is what makes enforcement precise enough for AI-driven workflows.

Practical implication: configure DSPM to discover data flowing into AI pipelines, not only data at rest.

Why agentic AI needs endpoint-level control

Agentic AI changes the operating model because software systems can access data, take actions, and continue workflows with limited human review. That means the control point shifts toward the endpoint and browser, where users and agents interact with content before it is submitted into an AI system. If controls only sit in cloud repositories or network layers, they miss the moment of delegation and composition. In practice, agentic risk is a runtime governance problem, not a policy-document problem.

Practical implication: put AI-native endpoint controls in place before scaling agentic workflows.


Threat narrative

Attacker objective: The attacker or risky workflow achieves unobserved movement of sensitive data through AI tools and downstream exposure outside governed channels.

  1. Entry occurs when employees or agents paste sensitive content into sanctioned or shadow AI tools outside the traditional perimeter.
  2. Escalation happens when the model transforms the content, spreads it across sessions, or returns it in a form that bypasses legacy DLP and monitoring.
  3. Impact is data exposure or exfiltration through AI-mediated workflows that the security stack cannot see end to end.

NHI Mgmt Group analysis

AI security has moved from a category decision to an architectural decision. The article’s core point is correct: organisations that bolt AI controls on after DLP and DSPM are already deployed will inherit blind spots. That matters because AI changes the data path, not just the tooling. For practitioners, the lesson is to design governance around AI-mediated data movement from the start.

Data lineage is becoming the control plane for AI-era data governance. In practice, the issue is not whether data can be found somewhere in the stack, but whether its origin, movement, and sensitivity remain intelligible once it enters prompts or agentic workflows. That is a stronger governance model than location-based enforcement, and it aligns more closely with how modern data exposure actually happens. Practitioners should treat lineage as a prerequisite for enforceable policy.

Shadow AI is now a governance discovery problem as much as a usage problem. Unsanctioned AI tools do not just create compliance risk, they defeat the assumption that approved tooling represents the full attack surface. That is a named concept worth carrying forward: AI exposure drift: the gap that opens when data security controls lag behind the speed at which users, agents, and tools change the actual data path. Practitioners should measure this drift continuously.

Agentic AI forces data security teams to think like identity teams. When software can initiate actions and move data with limited human review, the security model starts to resemble non-human identity governance, even in a data security context. That does not mean every AI tool is an identity problem, but it does mean runtime authority, delegated access, and control boundaries now matter to data security architecture. Practitioners should expect the AI and identity control planes to converge.

Security teams that unify DSPM, DLP, and AI controls will be able to govern AI adoption instead of merely blocking it. The article is strongest where it frames security as an enabler of safe usage, not a brake. The practical implication is that policy, discovery, and enforcement have to operate from the same understanding of the data. Practitioners should use this moment to re-baseline stack design rather than add another isolated point tool.

What this signals

AI security is increasingly a control-plane issue for data teams, but it also exposes where identity governance has been too static. When agents, prompts, and third-party models can move sensitive information outside the original perimeter, the programme needs lineage-aware enforcement and identity-aware policy boundaries. The adjacent risk is that shadow AI creates access paths no reviewer ever approved.

AI exposure drift: this is the gap between where data security policies assume information moves and where users, agents, and model outputs actually move it. Practitioners should expect this drift to widen as agentic workflows expand, which makes continuous discovery and runtime enforcement more valuable than periodic policy refreshes.

If your programme already tracks service accounts, tokens, and other non-human identities, apply the same discipline to AI-mediated workflows. That is where the operating model begins to converge with The 52 NHI breaches Report, because the practical problem is still uncontrolled authority moving data where it should not go.


For practitioners

  • Implement AI-aware data lineage Track where sensitive data originates, how it moves, and where it enters prompts or agentic workflows so policy can follow the data instead of the app. Use this to separate sanctioned AI use from exposures that arise in shadow AI sessions.
  • Extend DLP to the endpoint and browser Move enforcement closer to the point of interaction, because the critical exposure moment often happens when users copy, paste, or compose content into AI tools. Cloud-only and network-only controls will not see those interactions.
  • Inventory the full AI tool surface continuously Maintain an automatically updated inventory of sanctioned and unsanctioned AI tools so governance reflects real usage rather than approved lists. Link that inventory to classification policy and routing rules for high-risk data.
  • Treat agentic workflows as runtime governance cases Define which AI agents may access which datasets, what actions they may take, and which events require step-up review or blocking. This is especially important where agentic tools can continue tasks without direct human approval.
  • Re-baseline DLP and DSPM together Test whether discovery, enforcement, and governance are working against the same data model across AI sessions, cloud repositories, and collaboration tools. If the three layers disagree, the gap is architectural, not operational.

Key takeaways

  • AI security fails when it is added after the data stack is already fixed, because the control model no longer matches how information actually moves.
  • The biggest operational gap is not visibility alone, but whether discovery, enforcement, and governance share the same data lineage view.
  • For practitioners, the near-term priority is to extend controls to the AI interaction layer and the endpoint before agentic workflows scale further.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST AI RMF, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 and GDPR define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST AI RMFGOVERNThe post is about embedding AI risk into governance and decision-making.
NIST CSF 2.0PR.AC-4AI data access and enforcement depend on least-privilege access controls.
NIST SP 800-53 Rev 5AC-6Least privilege is central to controlling who and what can move data into AI systems.
ISO/IEC 27001:2022A.5.15Access control policy is directly relevant to governing AI-mediated data movement.
GDPRArt.32AI data processing can involve personal data security and processing safeguards.

Assess whether AI tools introduce security measures that are adequate for personal data processing.


Key terms

  • Data Lineage: The record of how data moves across systems, applications, and workflows. In security operations, lineage shows where sensitive data propagates, which identities touch it, and how a compromise could spread across connected environments.
  • Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
  • AI-Native Endpoint DLP: AI-native endpoint DLP is data loss prevention that can inspect and control data at the point where users interact with AI tools, including browsers and desktop applications. It is designed to understand context, origin, and movement, not only static content patterns.
  • Agentic workflow: An agentic workflow is a sequence of tasks executed by an AI agent with some level of tool access and decision authority. In security terms, the workflow matters because it can span multiple systems, identities, and permissions, which makes attribution and revocation harder than with ordinary automation.

What's in the full article

Cyberhaven's full post covers the operational detail this post intentionally leaves for the source:

  • How its AI-native endpoint DLP approach handles copy, paste, and browser-based AI sessions in practice
  • How its data lineage model is used to connect discovery, classification, and enforcement across the stack
  • How the vendor frames the relationship between DSPM, IRM, and AI security in a unified operating model
  • How organisations can translate policy decisions into technical controls for AI workflows

👉 Cyberhaven's full post covers the AI-native DLP, DSPM, and governance details behind the stack design.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and related control concepts that support modern identity-led security design. It is a practical fit for teams aligning data security, access governance, and non-human identity oversight.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org