By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: Ground LabsPublished December 24, 2025

TL;DR: 2025 saw record-setting breaches, widespread AI-related leakage and repeated supply chain compromise, according to Ground Labs, while 155 countries now have enacted data protection and privacy laws, underscoring the gap between regulatory ambition and operational control. Data security is shifting from point-in-time compliance to continuous visibility, containment and governance across data, AI and third-party ecosystems.


At a glance

What this is: This retrospective argues that 2025 was defined by large-scale breaches, AI-driven leakage and supply chain failure, with data security controls still lagging operational risk.

Why it matters: For IAM and security teams, the lesson is that identity, access and secrets governance sit inside a wider data control problem that now spans AI tools, third parties and regulatory pressure.

By the numbers:

👉 Read Ground Labs’ retrospective on data security breaches, AI leakage and supply chain risk


Context

Data security now extends well beyond classic perimeter protection. The problem in 2025 was not only breach volume, but the spread of exposure across AI tools, third-party services, malicious packages and regulated data flows. That matters to IAM and NHI teams because access control failures increasingly show up as data loss, not just account compromise.

The article’s central claim is that most organisations still lack the visibility and control needed to secure data consistently across modern workflows. In identity terms, that includes human users, service accounts, software supply chains and AI systems that can move sensitive information beyond intended boundaries.


Key questions

Q: How can organisations reduce data exposure in AI tools?

A: Start with data classification, then map where sensitive information can flow into prompts, connectors, and logs. Limit AI systems to the minimum data they need, require owner approval for higher-risk datasets, and monitor for unsanctioned sharing. Data controls work best when paired with identity controls and usage visibility.

Q: Why do third-party services create such a large data security risk?

A: Third parties often sit inside trusted workflows with broad permissions, so a compromise can expose data at scale without needing direct user compromise. Risk rises when organisations cannot see supplier secrets, processing locations or offboarding gaps. Visibility into every trusted data path matters as much as the strength of the primary system.

Q: What do organisations get wrong about AI data retention?

A: They often assume retention is an operational setting rather than a security decision. In AI systems, prompts, embeddings, and conversation histories can preserve sensitive material long after the original interaction, creating repeated exposure opportunities. Security teams should align retention with classification, disposal, and recovery requirements, not developer convenience.

Q: Who is accountable when AI supply chain exposure leaks customer data or source code?

A: Accountability usually spans product security, application owners, cloud teams, and identity owners because the failure crosses code, dependency, and access boundaries. In regulated environments, the organisation must be able to show that releases, secrets, and third-party dependencies were governed before exposure occurred. Shared responsibility does not remove responsibility.


Technical breakdown

Why AI access controls failed to contain data leakage

Generative AI systems often ingest user prompts, files and context with broad runtime permissions, which means access control has to operate at the point of data use, not only at the point of login. When permissions are coarse, data can be exposed through prompts, outputs, plugins or connected applications even if the account itself is valid. The issue is less about model intelligence than about governance around what the model can see and reuse. In practical terms, AI access control must be treated as a data security control, not just an application setting.

Practical implication: classify and restrict the data AI tools can reach, then validate those controls against real user workflows.

How supply chain compromise becomes a data exposure problem

Supply chain attacks succeed when a trusted service, package or managed file transfer platform is allowed to process data with more privilege than it should have. Attackers then use the legitimate trust relationship to reach records, credentials or internal data stores. In many cases the breach is not a single exploit but a chain of weak supplier visibility, delayed patching and overbroad integration rights. That makes third-party access governance and secrets management part of data protection, not a separate concern.

Practical implication: inventory third-party data paths, then limit the secrets and permissions each supplier can use.

Why data sovereignty and regulation are now operational controls

Privacy law increasingly affects where data is processed, who can access it and how long it may be retained. The article shows that regulation is no longer just a legal overlay, because AI services and cross-border workflows can create compliance exposure in real time. For identity teams, this means access decisions must be tied to data location, purpose and retention context, especially when humans or machines invoke external services. Governance now has to prove that access is both authorised and jurisdictionally acceptable.

Practical implication: map data flows to jurisdictional rules and bake those constraints into access policy.


Threat narrative

Attacker objective: The attacker’s objective is to convert trusted data-processing paths into high-volume exposure, monetisation or operational leverage.

  1. Entry occurs through a trusted channel such as a compromised third-party service, malicious package or over-permissioned AI workflow that can ingest sensitive data.
  2. Escalation follows when the attacker or tool gains access to broader records, secrets or connected systems than the original use case required.
  3. Impact is realised through mass leakage, extortion, regulatory exposure or operational disruption affecting customers and downstream partners.

NHI Mgmt Group analysis

Data security has become an identity problem as much as a storage problem. The article repeatedly shows that breaches now flow through users, service accounts, AI tools and supplier integrations rather than isolated databases. That means governance must extend across IAM, secrets management and workload identity, not stop at the data layer. Practitioners should treat access pathways as part of the data estate.

AI access control is the new data loss boundary. When almost 70% of organisations report AI-related leakage and 97% of model breaches tie back to poor access control, the failure is not model capability but governance scope. This is where NHI and agentic AI concerns intersect with data security, because machine-mediated access can replicate human mistakes at much higher scale. Practitioners should assume AI tools are data users that require explicit policy, not ambient trust.

Supply chain visibility remains a named control gap: third-party data exposure blind spots. Organisations continue to overestimate their control over trusted packages, managed services and file-transfer tools. That creates a false boundary around data that is already moving through vendor-owned systems, integrations and runtime secrets. Practitioners should map every third-party data path and remove standing trust where it is not essential.

Regulatory pressure is shifting from policy language to provable control operation. With 155 countries now having privacy legislation, the real challenge is evidencing who can access what data, from where and for what purpose. The governance question is no longer whether a policy exists, but whether access enforcement, logging and retention rules are actually operating. Practitioners should align data controls to jurisdictional obligations and make evidence collection continuous.

Continuous visibility is the differentiator between compliance theatre and resilience. The article’s core message is that reactive remediation after breaches is too slow for modern data movement patterns. Continuous monitoring of data access, AI usage and supplier connectivity is now the practical control that unifies cyber, identity and compliance objectives. Practitioners should build for ongoing detection, not periodic reassurance.

What this signals

Data-security programmes are converging with identity governance because the most damaging failures now involve authorised access moving data into the wrong place. That makes access review, secrets rotation and supplier offboarding relevant to privacy outcomes, not just infrastructure hygiene.

Third-party data exposure blind spots: the organisations most at risk are those that treat supplier access as static once the contract is signed. The control gap is lifecycle management, because access that is never reviewed becomes a persistent channel for leakage. The practical response is continuous mapping of data paths and a tighter link between access policy and jurisdictional rules.

AI governance teams should expect more scrutiny on who can query, export and retain sensitive information through genAI tools. The operational signal to watch is not just whether the model is safe, but whether the surrounding identity controls can prove data stayed within approved boundaries.


For practitioners

  • Map data access across human, machine and AI users Inventory who and what can reach sensitive datasets, including service accounts, API keys, AI tools and external integrations. Then remove standing access that is not directly tied to a business purpose.
  • Treat AI prompts and outputs as governed data flows Apply classification, logging and policy controls to prompt content, retrieved context and model outputs so that sensitive information cannot move into unmanaged tools or jurisdictions.
  • Shrink third-party trust to minimum necessary privilege Review supplier accounts, file-transfer platforms and package dependencies for excess permissions, then rotate or revoke secrets that are broader than the service function requires. Use the NHI Lifecycle Management Guide to align offboarding and rotation with actual exposure windows.
  • Build jurisdiction-aware access policy Link data location, retention and purpose limitations to access decisions so that users and systems cannot process information in prohibited regions or outside approved use cases. Align this with privacy obligations and audit evidence.

Key takeaways

  • 2025 showed that data breaches now emerge from AI tools, suppliers and secret exposure as often as from direct compromise.
  • The strongest evidence points to a governance gap, not a single technology failure, with access controls still lagging modern data flows.
  • Practitioners need continuous visibility across identity, data and jurisdiction if they want resilience rather than retrospective cleanup.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack surface, NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the technical controls, and GDPR define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.DS-1Data exposure and AI leakage map directly to protection of data at rest and in use.
NIST SP 800-53 Rev 5AC-6Excessive permissions across users, tools and suppliers are the core control failure.
OWASP Non-Human Identity Top 10NHI-03Secret sprawl and unmanaged service access underpin the supply chain and AI leakage risks.
NIST AI RMFMANAGEAI leakage and sovereignty issues require operational risk controls, not just policy statements.
GDPRArt.32The article’s privacy and jurisdiction concerns make security of processing directly relevant.

Align data access, retention and logging with Art.32 and test that controls work in practice.


Key terms

  • Data Sovereignty: Data sovereignty is the principle that information remains subject to the control, governance, and legal expectations of the organisation or jurisdiction that owns it. In identity programmes, it becomes a control question about who can authorise, revoke, and evidence access as systems cross borders.
  • Frontier AI access control: The policy layer that decides who can use a highly capable AI system, under what conditions, and with what assurance. In practice it combines authentication, eligibility checks, jurisdiction rules, and revocation so access can be granted or removed without treating every user the same.
  • Third-party data path: A third-party data path is any route through which external vendors, services or software dependencies can process or transmit organisational data. These paths matter because they often carry inherited trust, making visibility, permission scope and offboarding controls central to security.
  • Secrets Sprawl: The uncontrolled proliferation of sensitive credentials — API keys, tokens, passwords, certificates — across codebases, cloud environments, CI/CD pipelines, and configuration files. In 2024, over 50 million leaked secrets were found on the dark web.

What's in the full article

Ground Labs' full blog post covers the operational detail this post intentionally leaves for the source:

  • Per-incident analysis of the biggest 2025 breaches, including the downstream effects on customers, suppliers and recovery costs.
  • Discussion of how AI leakage, sovereignty concerns and regulatory changes interacted across the year.
  • Context on specific supply chain attacks involving Oracle EBS, MOVEit and malicious package repositories.
  • The article’s retrospective framing on how these trends shaped the year-end data security agenda.

👉 Ground Labs’ full post adds the year’s breach examples, regulatory shifts and AI governance lessons in one place.

Deepen your knowledge

NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, secrets management and workload identity. It is designed for practitioners who need stronger lifecycle control across human and machine access paths.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 18, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org