By NHI Mgmt Group Editorial TeamBased on Cyera: “Are You Ready for Web 3.0? How DSPM helps you move at the speed of AI” (June 11, 2025)

TL;DR: As AI adoption grows, data integrity becomes the critical control point and DSPM becomes the mechanism for classifying, discovering, and enforcing policy across cloud and on-prem data estates, according to Cyera. The governance break is that security teams can no longer rely on perimeter-era controls to keep pace with AI-generated and AI-consumed data.


At a glance

What this is: This is Cyera’s analysis of why AI shifts the security focus from perimeter controls to data integrity, with DSPM positioned as the mechanism for classification, discovery, and policy enforcement across modern data estates.

Why it matters: It matters because IAM, NHI, and AI governance teams now need a control model that can see human users, AI agents, and unmanaged applications touching data in motion and at rest.


Context

AI changes the security problem from protecting a perimeter to governing the integrity of the data that models consume, generate, and redistribute. In this article, DSPM is framed as the control layer that lets security teams classify, discover, and enforce policy across cloud and on-prem data estates when manual review and legacy DLP no longer scale.

The broader governance gap is that AI creates and consumes data continuously, so access, classification, and protection can no longer be treated as periodic hygiene tasks. For identity and access teams, that means the relevant question is no longer only who can reach the data, but which human users, AI agents, and shadow applications can influence it.


Key questions

Q: How should security teams govern AI and automation access to on-prem data?

A: Security teams should govern AI and automation access to on-prem data with the same discipline used for privileged human access: explicit approval, least privilege, short-lived credentials, and continuous review. The key is to connect data sensitivity to identity type and access path, so service accounts and agents are not treated as permanent exceptions. Use the OWASP Non-Human Identity Top 10 as a control checklist.

Q: Why do traditional DLP controls struggle in cloud and AI workflows?

A: They rely too heavily on static rules, shallow content inspection, and limited context. In cloud and AI workflows, the same data can be safe in one destination and risky in another, so controls that ignore role, classification, and usage patterns either overblock or miss the real problem.

Q: What are the signs that data and AI governance is not working as intended?

A: Common warning signs include poor data classification coverage, unidentified cookies or trackers, duplicate files that remain unaddressed, and difficulty mapping AI system components and dependencies. If teams cannot centrally track third-party AI use or automate evidence collection for compliance, governance is fragmented. Those gaps usually mean risk decisions are slow, inconsistent, and hard to defend.

Q: How do identity teams and data security teams share accountability for on-prem exposure?

A: Identity teams need to supply the effective permission model, while data security teams need to identify which files and datasets are truly sensitive. The shared accountability point is the overlap between the two. When both teams work from the same exposure view, they can explain access, prioritise remediation, and defend decisions during audit or incident response.


Technical breakdown

Why data integrity becomes the AI security control point

Data integrity means the data remains trustworthy, uncorrupted, and fit for the purpose a model or workflow depends on. In an AI environment, that matters as much as confidentiality because model behaviour, outputs, and downstream decisions inherit the quality of the inputs they consume. The article’s core claim is that Web 3.0 adds AI-generated and AI-consumed data at a pace that makes network-centric controls insufficient on their own. Security has to move closer to the data layer, where classification, context, and policy enforcement can track how information is actually used.

Practical implication: shift governance focus from perimeter containment to continuous control over the data AI depends on.

Why traditional DLP and regex fail in AI data environments

Traditional DLP often relies on pattern matching, keywords, and rules that work reasonably well for structured leakage but struggle with meaning, context, and unstructured content. The article argues that false positives have pushed many teams to weaken or disable those controls, which leaves policy enforcement blunt and unreliable. By contrast, DSPM is presented as using large language models and natural language processing to classify data by semantic context, including unstructured files spread across SaaS, PaaS, DBaaS, IaaS, and on-prem repositories. That architectural difference matters because AI training and inference workflows depend heavily on documents and mixed-format content, not just neat records.

Practical implication: evaluate whether your current DLP rules can still support unstructured AI data use without collapsing under false positives.

How DSPM changes identity visibility for humans, AI agents, and Shadow AI

DSPM is not only about finding data. The article also frames it as a way to discover which users and applications can reach that data, including human users, AI agents, and unmanaged applications the vendor describes as Shadow AI. That makes the control relevant to identity governance because access is part of the data-risk picture, not a separate concern. When data visibility and access visibility are combined, security teams can identify risky privilege, stale access, and unexpected application sharing paths in the same control plane. The practical value is less about static inventory and more about seeing which identities can influence the integrity of data used by AI systems.

Practical implication: connect data discovery to access discovery so AI governance includes both content risk and identity risk.


NHI Mgmt Group analysis

AI makes data integrity the governing security objective, not a side effect of confidentiality controls. The article’s strongest signal is that AI changes what needs protecting from data location to data trustworthiness. In practice, model quality, output reliability, and downstream decision confidence all depend on whether the underlying data can be discovered, classified, and governed continuously. The practitioner conclusion is that AI governance starts at the data layer, not the model layer.

Legacy DLP is increasingly a policy signal, not a policy control, in AI-heavy environments. The article is right to highlight false positives as the reason many organisations soften or disable DLP. Once that happens, the control stops enforcing intent and starts documenting aspiration. The practitioner conclusion is that security teams should treat brittle content rules as a governance liability when AI depends on unstructured data.

Shadow AI turns data governance into an identity problem as well as a classification problem. Cyera’s framing is important because it ties access, users, and applications together instead of treating them as separate disciplines. If unmanaged AI applications can reach sensitive data, the issue is not just where data lives but which identities and systems can influence it. The practitioner conclusion is that AI governance has to include access discovery and entitlement review, not only data discovery.

Data security posture management is becoming the operational layer for AI trust, risk, and security programmes. The article’s alignment with Gartner’s TRiSM framing shows where the market is moving: toward continuous discovery, classification, policy enforcement, and monitoring rather than one-time assessments. That does not replace IAM, SASE, or DLP, but it changes their role in the stack. The practitioner conclusion is to treat DSPM as a governance control plane for AI-era data use.

Standard perimeter-era assumptions no longer hold once AI systems both consume and generate governed data. Web 2.0 controls were built around protecting access to stored information. AI introduces a more dynamic cycle in which data is ingested, transformed, reproduced, and reused at speed. The practitioner conclusion is that programmes built only for access restriction will miss the integrity dimension that now defines AI security.

What this signals

AI governance will increasingly be measured by data trust, not just model oversight. As organisations move from static repositories to continuously generated content, the governance question shifts to whether sensitive information can be classified and controlled fast enough to influence AI safely. That means security leaders should expect data-layer controls to become part of the AI operating baseline, not an add-on.

Shadow AI turns access visibility into a first-class governance requirement. If unmanaged AI applications can reach sensitive data, then identity review has to include machine and application actors alongside human users. Teams that still separate data governance from entitlement governance will miss the paths that matter most in AI-driven environments.


For practitioners

  • Map AI data flows across the full estate Inventory where AI models and AI agents source training and inference data across cloud and on-prem environments, then identify which repositories actually influence outputs.
  • Replace brittle pattern matching with semantic classification Review whether current DLP and regex rules can classify unstructured content accurately enough for AI use cases, then test them against mixed-format documents and conversational data.
  • Connect data discovery to entitlement review Correlate sensitive data locations with the human users, AI agents, and applications that can access them, and recertify stale or excessive access paths.
  • Enforce policy at the data layer Apply encryption, access revocation, and policy-based protections where sensitive data is discovered, rather than relying only on network or endpoint controls.

Key takeaways

  • AI changes the security problem by making data integrity a primary control objective rather than a secondary concern.
  • Legacy DLP and regex-based controls are too brittle for the unstructured, fast-moving data patterns that AI relies on.
  • Security teams need governance that combines data discovery, semantic classification, entitlement visibility, and policy enforcement in one operating model.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and CSA Cloud Controls Matrix set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-10 — Human Use of NHIAI agents and Shadow AI accessing data create non-human access paths that must be governed explicitly.
Recommendation — Review non-human access paths under NHI-10 where AI agents or unmanaged applications can reach sensitive data.
NIST AI RMFGOVERN — AI Governance and AccountabilityThe article frames DSPM as part of AI governance and trustworthy data management.
Recommendation — Use GOVERN to assign accountability for data integrity, access visibility, and policy enforcement in AI programmes.
NIST CSF 2.0PR.DS-01 — Data-at-RestDSPM is presented as a control for discovering and protecting data across the estate.
Recommendation — Apply PR.DS-01 to classify and protect sensitive data where AI systems ingest or store it.
CSA Cloud Controls MatrixDSP — Data Security & PrivacyCloud data discovery and protection are central to the article’s DSPM discussion.
Recommendation — Use DSP controls to continuously discover, classify, and protect AI-relevant cloud data.

Key terms

  • Data Integrity: Data integrity is the assurance that information remains accurate, complete, and trustworthy as it moves through systems and is used by people or machines. For AI governance, integrity matters because corrupted, incomplete, or exposed data can shape model behaviour and security outcomes.
  • DSPM: Data Security Posture Management is the discipline of finding, classifying, and protecting sensitive data across storage systems and workflows. In AI environments, DSPM helps teams understand what data exists, where it lives, and whether AI systems can access it appropriately.
  • Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
  • Semantic classification: Semantic classification uses model-based understanding to identify what content means rather than relying only on exact patterns or keywords. It is useful for material such as source code, legal drafts, and HR documents that are sensitive by context and may not trigger traditional detector rules.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org