TL;DR: Data growth is accelerating toward 395ZB by 2028, while AI, SaaS sprawl and hybrid cloud expansion are multiplying the places sensitive information can reside, according to Ground Labs' analysis of IDC, Okta and Flexera data. The governance challenge is no longer just storage volume, but continuous discovery, classification and access control across fragmented estates.
At a glance
What this is: This blog post argues that DSPM has become the operating model for governing sensitive data across AI, SaaS and hybrid cloud sprawl.
Why it matters: It matters because IAM, data security and GRC teams now need shared visibility into where sensitive data lives, who can access it, and how AI systems are using it.
By the numbers:
- 2028, 028, worldwide data created, captured, replicated and consumed is expected to reach almost 395ZB.
- 2, ompanies with 2,000 or more employees deploy an average of 247 apps, increasing the number of data locations to govern.
- More than half of enterprise and SMB workloads now run in the cloud, and 70% operate hybrid cloud environments.
- 42% of organizations lack confidence in identifying their sensitive data.
👉 Read Ground Labs' full analysis of data-centric governance in the age of AI
Context
Data security posture management, or DSPM, is a governance approach for discovering, classifying and monitoring sensitive data across modern estates. The problem it addresses is not a lack of storage controls in isolation, but the fact that data now moves across cloud services, SaaS, AI tools and hybrid workforce environments faster than traditional perimeter models can track.
For identity and security teams, the real gap is visibility and control at the data layer. Access reviews, least privilege and policy enforcement all matter, but they are harder to govern when sensitive data is spread across hundreds of applications, unmanaged AI usage and third-party systems.
The article frames this as a data governance issue, but it also touches identity governance because access controls remain the primary security layer for sensitive data in cloud and SaaS environments. That makes the starting position typical for modern enterprises, not exceptional.
Key questions
Q: How should security teams govern sensitive data across fragmented cloud and SaaS estates?
A: Security teams should use a combined discovery and entitlement model. Classification tells you what the data is, but access review tells you who can reach it and through which identities or connectors. Without both, fragmented estates create blind spots that can survive even mature privacy reporting.
Q: Why do AI and SaaS environments make PII governance harder?
A: Because the data is no longer confined to a database or a controlled application boundary. Sensitive information now appears in chats, documents, prompts, attachments, and integrations, which expands both the number of places to scan and the number of identities that can reach it.
Q: What breaks when data discovery is incomplete?
A: Risk assessment becomes guesswork because teams cannot reliably identify what sensitive data exists, where it lives or which systems can reach it. Without that baseline, classification, policy enforcement and regulatory evidence all become partial and reactive.
Q: How can teams prove DSPM is working?
A: Track whether exposure is falling in priority datasets, whether classification is accurate enough to support policy decisions, and whether audit evidence can be produced without manual scrambling. Coverage alone is not sufficient. A working programme reduces risk, shortens response time, and makes compliance evidence repeatable.
Technical breakdown
How DSPM discovers and classifies sensitive data across fragmented estates
DSPM starts by locating data wherever it sits, including databases, file stores, logs, SaaS repositories and cloud platforms. Discovery is followed by classification, which adds context such as sensitivity, owner, purpose and retention. The point is to move from unknown data sprawl to a governed inventory that security and compliance teams can actually work from. Without that step, risk treatment becomes reactive and incomplete, especially when AI tools can ingest data faster than manual processes can map it.
Practical implication: build a discovery and classification baseline before trying to enforce policy across cloud and AI environments.
Why access controls are the central governance layer for data risk
Once data is classified, the next question is who can reach it and through which systems. In cloud and SaaS environments, access control becomes the main safeguard because data is often replicated across multiple services and copied into collaboration tools, analytics platforms and AI workflows. DSPM uses that context to assess exposure to privacy, security and AI-usage risks. That is where identity governance intersects directly with data governance, because overbroad entitlements and shared accounts can silently widen the blast radius.
Practical implication: tie data risk reviews to entitlement reviews, especially for SaaS, cloud and AI-connected applications.
How continuous monitoring changes the control model for AI-era data sprawl
Static assessments cannot keep pace with new data stores, new apps and new AI usage patterns. Continuous monitoring is the control pattern that keeps DSPM aligned with live changes in the environment, including shadow data, shadow IT and unauthorized AI use. In practice, the model treats data risk as dynamic rather than periodic. That matters because the estate changes faster than quarterly review cycles, and exposure often appears in the gaps between onboarding, migration and offboarding processes.
Practical implication: make monitoring continuous so newly created or newly exposed data is discovered before it becomes a governance failure.
Threat narrative
Attacker objective: The attacker’s objective is to locate, access and misuse sensitive data across environments that the organisation cannot fully see or govern.
- Entry occurs when sensitive data is copied into SaaS, cloud services or AI tools outside central governance, creating shadow data and unauthorized exposure pathways.
- Escalation follows when overbroad access, unmanaged integrations or insecure plugins let more users and systems reach the data than intended.
- Impact is realised through privacy breach, AI misuse, data leakage, ransomware amplification or supply chain exposure across fragmented environments.
NHI Mgmt Group analysis
DSPM is becoming the control plane for data governance, not just a point solution for discovery. The article shows that discovery, classification, risk assessment and monitoring are now part of one operating model rather than separate workflows. That matters because data security failures increasingly emerge from fragmentation, not from a single missing control. Practitioners should treat DSPM as a governance layer that connects security, compliance and access management.
Data sprawl has turned identity governance into a data exposure problem. When sensitive information moves through SaaS, cloud platforms and AI tools, entitlement decisions become data-risk decisions. That creates a direct bridge between IAM and DSPM because overprovisioned access can expose regulated and business-critical data even when the storage layer is technically configured. Practitioners should align access review with data classification.
AI adoption is amplifying governance debt faster than traditional controls can absorb it. The article’s core warning is that AI systems do not just consume data, they expand the number of places data can be replicated, transformed and exposed. That creates a named concept we can call AI data sprawl: the rapid, distributed spread of sensitive data across tools, models and workflows that makes static governance incomplete. Practitioners should assume this sprawl is now a persistent condition.
Continuous monitoring is now a resilience requirement, not a maturity enhancement. The article links DSPM to continuous discovery because the control problem is dynamic. Once shadow data, shadow IT and unauthorized AI use become normal conditions, periodic audits lag behind reality. Practitioners should measure whether their monitoring can detect new stores and new exposures in near real time, not just at review points.
What this signals
The practical signal for security leaders is that data governance can no longer sit apart from identity governance. When access entitlements, SaaS sprawl and AI usage all shape exposure, the programme needs a shared view of who and what can touch sensitive data across the estate.
AI data sprawl: the fastest-growing governance risk is not a single breach vector but the accumulation of data copies, unmanaged integrations and shadow usage across tools. That makes discovery speed, not just control design, the differentiator for mature programmes.
For teams working from NIST Cybersecurity Framework 2.0, the lesson is to connect identify, protect and detect functions around data exposure rather than treating them as separate reporting streams.
For practitioners
- Map sensitive data to identity controls Connect DSPM findings to access review, least privilege and multifactor authentication so data classification directly informs who can reach the information and through which apps.
- Prioritise shadow data and shadow AI discovery Focus first on data stores and AI usage that sit outside central security oversight, because those are the places where exposure grows fastest and visibility is weakest.
- Automate policy enforcement for high-risk data Use automated controls for encryption, tokenization, localization and deduplication where sensitive data is replicated across SaaS and cloud environments.
- Tie monitoring to change events Reassess data exposure whenever new apps, integrations, migrations or AI workflows are introduced, rather than waiting for periodic review cycles.
Key takeaways
- DSPM is emerging as the governance model that connects data discovery, classification and exposure management across fragmented estates.
- AI, SaaS and hybrid cloud growth are multiplying data locations faster than traditional perimeter controls or periodic audits can keep up.
- Identity teams should align access reviews and least privilege with data classification, because entitlement decisions now shape data risk directly.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the technical controls, while ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | ID.AM-1 | DSPM starts with discovering and mapping data assets across fragmented environments. |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege is the core access control principle referenced in DSPM mitigation. |
| ISO/IEC 27001:2022 | A.5.12 | Data classification and handling are directly relevant to the article's governance model. |
| NIST AI RMF | MAP | The article addresses AI usage risk and the need to understand where data is exposed to AI systems. |
Use inventory and exposure findings to keep sensitive data maps current across cloud, SaaS and AI tools.
Key terms
- Data Security Posture Management: Data Security Posture Management, or DSPM, is the continuous discovery and monitoring of where sensitive data lives, how it is exposed, and where policy gaps exist. Its value rises when it feeds remediation rather than generating findings alone, especially in environments where AI expands the number of data paths.
- Shadow Data: Shadow data is sensitive information that exists outside the places security teams expect to find it. It often appears in testing copies, ad hoc exports, SaaS tools, or AI workflows, which makes it hard to govern with inventory-based controls alone.
- Data classification: Data classification is the process of labelling information according to sensitivity, regulatory impact, or business value so controls can be applied consistently. For AI governance, it allows policy to follow the data into prompts, sessions, and destinations rather than relying on brittle text matching.
- Access Review: A formal process for confirming whether access is still needed and justified. In IAM programs, the review becomes an evidence-bearing control when decisions are recorded, scoped correctly, and traceable to the right reviewer, application owner, or auditor.
What's in the full article
Ground Labs' full blog post covers the operational detail this post intentionally leaves for the source:
- The article’s six-step DSPM operating model for discovery, classification, risk assessment and continuous monitoring.
- Ground Labs' interpretation of how DSPM aligns with governance and compliance frameworks across cloud and SaaS estates.
- The specific control examples for mitigation, including least privilege, multifactor authentication, tokenization and deduplication.
- The source discussion of how DSPM supports privacy legislation and information security standards in practice.
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security and secrets management. It helps practitioners connect identity controls to the wider access and lifecycle decisions that modern security programmes rely on.
Published by the NHIMG editorial team on August 25, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org