By NHI Mgmt Group Editorial TeamBased on Cyera: “AI-Native Security Leader Cyera Doubles Customer Base in Six Months, Reaching $6 Billion Valuation” (June 11, 2025)

TL;DR: AI adoption is pushing data security and governance closer together, and blind spots around sensitive data now carry identity and access consequences as well as data risk, according to Cyera, which says it raised $540 million in Series E funding, lifted total funding above $1.3 billion, and reached a $6 billion valuation in six months, while also reporting 353% year-over-year growth among F500 customers and operations in 10 countries.


At a glance

What this is: Cyera's latest funding round is a signal that AI-era data security is moving from adjacent concern to core enterprise control, with the company framing sensitive data discovery and protection as the key governance gap.

Why it matters: For IAM and security teams, the message is that AI initiatives amplify the impact of weak data visibility, so identity governance and data security now need to be planned together rather than sequenced separately.

By the numbers:

  • Cyera says it raised $540 million in Series E funding, bringing total funding above $1.3 billion.
  • Cyera reported 353% year-over-year growth among F500 customers.
  • Cyera says it expanded operations to 10 countries and counting.

Context

AI-native data security is the discipline of discovering, classifying, and protecting sensitive data across cloud, SaaS, databases, AI systems, and on-premise environments. In this article, the underlying governance gap is not a lack of storage encryption or point controls, but a lack of reliable visibility into where sensitive data lives and how it is used.

That gap matters because AI systems amplify the consequence of poor data discovery. When copilots, foundation models, and generative workflows consume enterprise data, access control, data classification, and usage governance become one operating problem rather than separate programmes.

Cyera's funding announcement uses that shift to frame data security as an enterprise scaling issue, not just a tooling category. For identity leaders, the practical takeaway is that data control boundaries now influence who or what can safely be trusted to act on enterprise information.


Key questions

Q: How can teams reduce risk when AI tools are connected to enterprise workflows?

A: Start by narrowing what the AI tool can see and do, then add monitoring for unusual access patterns and action chains. Put ownership on a named team, enforce expiry or revocation rules, and include the AI connection in privileged access reviews. That makes exposure visible before it becomes operational loss.

Q: Why do AI initiatives expose gaps in data security governance?

A: AI compresses storage, retrieval, and use into one workflow, so any data blind spot becomes easier to amplify and harder to contain. If teams do not know where sensitive data lives and who or what can reach it, they cannot govern AI use with confidence.

Q: What breaks when sensitive data classification is too weak for AI adoption?

A: Security teams lose the ability to set meaningful access boundaries, apply consistent controls, and explain why some data should never enter a model-driven workflow. The result is broader exposure, more exceptions, and less defensible governance across the AI stack.

Q: How do identity teams and data security teams share accountability for on-prem exposure?

A: Identity teams need to supply the effective permission model, while data security teams need to identify which files and datasets are truly sensitive. The shared accountability point is the overlap between the two. When both teams work from the same exposure view, they can explain access, prioritise remediation, and defend decisions during audit or incident response.


Technical breakdown

Sensitive data discovery as the first control plane

Data security for AI starts with knowing where sensitive data resides, because classification cannot protect what it cannot find. Discovery engines scan clouds, databases, SaaS repositories, and on-premise stores to map data location, type, and exposure. In AI-heavy environments, that inventory becomes the foundation for downstream controls such as masking, policy enforcement, and workflow restrictions. Without it, organisations are forced to govern based on incomplete assumptions, which is especially dangerous when AI systems can ingest data from multiple repositories in a single workflow.

Practical implication: treat data discovery coverage as a prerequisite control for AI governance, not a reporting exercise.

Why AI increases the blast radius of data blind spots

AI models and copilots do not create the original data problem, but they magnify it. Once sensitive information is spread across clouds and applications, any weakly governed access path can surface that data to users, tools, or models at scale. The risk is not just exfiltration; it is also overexposure, accidental inclusion in prompts, and loss of context about what data should remain constrained. This makes the boundary between data security and access governance much tighter than in traditional analytics environments.

Practical implication: review where AI systems can read enterprise data and classify those pathways as high-risk access surfaces.

AI-native classification versus rules-based data control

The article contrasts AI-native classification with the older rules-based paradigm. In practice, rules-based approaches depend on fixed patterns, labels, or manually maintained policies, which struggle when data is distributed, duplicated, and constantly reused by AI-enabled workflows. An AI-native approach aims to infer context from usage patterns and data relationships, which is more suitable when the same data object moves across platforms and applications. That does not remove governance needs, but it changes how classification keeps pace with operational reality.

Practical implication: assess whether your classification model can follow data as it moves across AI and non-AI systems.


NHI Mgmt Group analysis

Data security has become an AI enablement control, not a downstream cleanup function. The article's central signal is that enterprises are funding security for the data layer because AI depends on data quality, data location awareness, and data governance all at once. That makes sensitive data discovery a prerequisite for responsible AI adoption, not a parallel compliance workstream. Practitioners should treat the data layer as part of AI architecture design, not an afterthought.

Identity and access teams cannot separate who can access data from what the data can do once AI consumes it. AI systems collapse the distance between storage, retrieval, and operational use, so traditional perimeter thinking does not hold. This does not make identity controls obsolete; it makes them more dependent on accurate data classification and policy enforcement. The implication is that IAM and data security programmes now need shared governance language, shared inventory, and shared exception handling.

Blind spots are now an operational risk multiplier, not merely a visibility problem. When sensitive information is scattered across cloud, SaaS, databases, and AI ecosystems, the organisation does not just lose oversight, it loses the ability to decide where trust should be granted. That is why the article's framing matters to security leadership: the governance failure sits upstream of almost every AI risk discussion. Practitioners should measure programme maturity by how quickly they can find, classify, and constrain the data that AI can reach.

AI-native data security is pushing the market toward continuous control, not periodic review. The funding signal suggests buyers are prioritising systems that can keep up with fast-changing data flows, rather than tools that only support retrospective audits. That aligns with the direction of modern identity programmes, where static access snapshots are no longer enough to describe real exposure. Security teams should assume the category is moving toward runtime governance of data use, not point-in-time reporting.

From our research library:

What this signals

AI-native data security becomes a governance dependency once models consume enterprise information. Teams can no longer treat discovery, classification, and access control as separate layers when AI systems are using the same data estate that human users depend on. The practical consequence is that identity programmes need to account for data sensitivity before access is granted, not after exposure is detected.

Sensitive data blind spots create trust debt for AI programmes. If an organisation cannot reliably locate and classify its data, every AI use case inherits that uncertainty. That makes control effectiveness measurable in terms of how quickly the enterprise can prove which repositories hold sensitive data and which systems can reach them.

Data security and identity governance are converging on the same operational question: what should be trusted to act on enterprise information? The answer now depends on both who has access and what data that access can touch. Security teams should expect future governance models to require shared review of data scope, AI usage scope, and entitlement scope.


For practitioners

  • Map AI data access paths Inventory which copilots, foundation models, and automation flows can reach sensitive data stores, then identify the permissions and repositories that make those paths possible.
  • Align data classification with IAM policy Use a shared data classification model to drive access decisions, exception handling, and policy scope across cloud, SaaS, and on-premise environments.
  • Prioritise blind-spot remediation Focus first on the repositories where the organisation cannot currently prove where sensitive data lives or how it is used, especially when those repositories feed AI systems.
  • Test whether AI workflows inherit excessive access Review whether AI-enabled workflows are reading broader data sets than the underlying business task requires, then narrow the entitlement boundary around those workflows.

Key takeaways

  • AI adoption is turning data discovery and classification into core governance controls rather than back-office security tasks.
  • The main risk is not only sensitive data exposure, but also uncontrolled reuse of enterprise data inside AI-enabled workflows.
  • Identity and data security teams now need shared policy boundaries if they want AI adoption to remain governable.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while CSA Cloud Controls Matrix, NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CSA Cloud Controls MatrixIAM — Identity and Access ManagementThe article ties AI data security to access boundaries across cloud and SaaS environments.
Recommendation — Apply IAM governance to ensure AI workflows only reach authorised data and repositories.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is fundamentally about entitlement scope for AI-consuming systems.
Recommendation — Review AI-related entitlements against PR.AA-05 to narrow access to the minimum data scope.
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIAI systems that consume enterprise data can inherit excessive permissions if access boundaries are too broad.
Recommendation — Audit AI-connected identities for overprivileged access and trim permissions to task scope.
NIST AI RMFGOVERN — AI Governance and AccountabilityThe announcement frames AI adoption as a governance issue requiring accountability over data use.
Recommendation — Use GOVERN to assign clear accountability for data security decisions in AI programmes.

Key terms

  • AI-Native Data Security Platform: An AI-native data security platform is a security system built to understand, classify, monitor, and protect data using AI-driven analysis from the start. It combines data discovery, sensitivity labeling, access control, anomaly detection, and policy enforcement across cloud and on-premises environments, with machine learning helping identify risky behavior and data exposure patterns.
  • Sensitive Data Discovery: Sensitive data discovery is the process of locating where protected or regulated information exists across systems, storage, and workflows. In cloud environments, it must be continuous because assets appear, move, and replicate quickly, making one-off inventories unreliable for governance or incident response.
  • Data Blind Spot: An area of the data estate where the organisation cannot reliably determine what sensitive information exists, where it resides, or how it is being used. In AI-heavy environments, blind spots become governance liabilities because unknown data can be pulled into prompts, workflows, or downstream use.
  • Entitlement Scope: Entitlement Scope is the exact set of actions, resources, or permissions attached to an identity during a session. In cloud and NHI governance, scope is as important as duration because broad permissions can turn a short-lived grant into a high-impact access event. Narrow scope is a core control objective.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org