By NHI Mgmt Group Editorial TeamBased on Cyera: “Navigating the World of DSPM for AI and Why It is Mission Critical for Enterprise Organizations” (October 7, 2025)

TL;DR: AI adoption is outpacing AI security and governance, with IBM reporting that 97% of businesses suffering an AI-related breach had no proper AI access controls in place, while Cyera argues that extending DSPM into AI workflows is the practical way to restore visibility over data, access, and usage. The underlying issue is not just data sprawl, but governance built for static environments now being asked to control dynamic AI workflows.


At a glance

What this is: This is Cyera’s analysis of DSPM for AI, arguing that conventional data security tools and governance models do not adequately cover AI workflows, shadow AI, or model training data.

Why it matters: It matters because IAM, IGA, and data security teams now have to govern who and what can access sensitive data inside AI workflows, not just in static cloud repositories.

By the numbers:

  • 97% of businesses that suffered an AI-related breach reported they had no proper AI access controls in place.
  • 72% of data breaches involved data stored in cloud environments.
  • 30% of breached data spanned multiple computing environments.
  • 63% of breached organisations either had no AI governance policy or were developing one.

Context

AI security is no longer only a model-risk or cloud-security issue. The governance gap appears when data controls built for static repositories are asked to govern AI systems that ingest, transform, and expose data continuously across training and inference workflows.

Cyera frames DSPM for AI as a way to extend data discovery, classification, access visibility, and compliance reporting into those workflows. That matters for NHI, agentic AI, and human access alike because the control problem is the same: knowing what data exists, who can reach it, and how it is being used.

The article’s strongest point is that AI security failures are often governance failures first. Shadow AI, over-permissioned access, and weak policy enforcement create blind spots that conventional tools miss until data has already moved into places the business cannot easily audit or undo.


Key questions

Q: What breaks when data access governance is too static for AI-driven workflows?

A: Static governance breaks when access decisions assume the data path is predictable, because AI-enabled workflows can reuse or expand entitlements faster than review cycles can track. The result is permission drift, unclear accountability, and difficulty proving that access still matches business need. Teams should test whether their controls follow actual data use rather than original approval records.

Q: Why do shadow AI tools create such a compliance problem?

A: Shadow AI creates a compliance problem because it bypasses the visibility controls that ISO 42001 depends on. If teams cannot see where the tool connects, what data it can reach, or what it outputs, they cannot prove governance. That makes unsanctioned AI a control gap, not just an acceptable-use issue.

Q: How should teams decide whether DSPM is enough for AI governance?

A: DSPM is enough only if it can see the organisation’s real AI footprint, including training data, inference flows, third-party tools, and shadow AI usage. If visibility stops at one cloud or one suite, governance gaps remain. Teams should test coverage against actual data movement, not vendor scope assumptions.

Q: What should security teams do when AI agents need access to tools and data?

A: Security teams should treat AI agents as runtime access actors and separate them from static machine identities. Limit tool scope, define approval gates, and require explicit revocation triggers for sessions and delegated access. The goal is to prevent broad runtime behaviour from inheriting static privileges.


Technical breakdown

Why static data security breaks in AI workflows

Traditional data security tools were designed around stable storage locations, clearer perimeters, and predictable access patterns. AI workflows change that model because data is consumed, transformed, and re-used across training, inference, prompts, outputs, and integrations. DSPM for AI adds continuous discovery and classification so security teams can understand data context rather than only file location. The key technical issue is not simply volume. It is the mismatch between static controls and dynamic AI data paths that cross cloud, SaaS, and third-party environments.

Practical implication: Treat AI data paths as continuously changing governance surfaces, not as fixed repositories that can be reviewed once and left alone.

Shadow AI creates an unmanaged data access layer

Shadow AI is risky because the control plane disappears when employees use unsanctioned tools or unauthorised connectors. Sensitive data can be typed into prompts, copied into external services, or exposed through outputs without ever passing through the organisation’s normal approval and monitoring path. DSPM for AI tries to close that blind spot by correlating data sensitivity with access activity and exposure signals. That makes the problem visible, but only if the organisation can discover where AI use is happening across sanctioned and unsanctioned channels.

Practical implication: Inventory AI usage as part of data governance, because unapproved AI tools often become the first uncontrolled data exfiltration path.

AI governance depends on data minimisation and policy enforcement

AI systems often need broad access, but broad access is not the same as justified access. The article ties DSPM for AI to least-privilege enforcement, retention rules, and compliance mapping because training data, prompts, and outputs can all contain regulated information. Once personal data or confidential business data is pulled into an AI workflow, governance must control purpose, retention, and downstream reuse. Without those controls, the organisation cannot prove that data collection is necessary, bounded, or defensible under policy.

Practical implication: Use data minimisation and access scoping as core AI governance controls, not as after-the-fact compliance checks.


Threat narrative

Attacker objective: The objective is to obtain or weaponise sensitive enterprise data through AI workflows in ways that evade normal data security and governance controls.

  1. Entry occurs when users place sensitive or regulated data into sanctioned or shadow AI workflows that are not fully governed.
  2. Credential or access abuse follows when those workflows have over-permissioned dataset access or weak policy boundaries, allowing data to move farther than intended.
  3. Escalation happens when prompts, training sets, or outputs combine previously separate data sources and expose higher-value information or create compliance violations.
  4. Impact is data leakage, model misuse, or regulatory exposure across cloud and hybrid environments where the organisation cannot easily reconstruct what was accessed.
  • DeepSeek database exposure 2025: An unauthenticated DeepSeek ClickHouse database exposed over a million log lines with plaintext chat history and API keys in 2025.
  • 12,000 secrets in LLM training data: Truffle Security found 11,908 live API keys and passwords hard-coded in web pages captured by Common Crawl, a dataset used to train LLMs.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

DSPM for AI is really about governance continuity, not just better discovery. The article’s core lesson is that AI changes the shape of the data security problem, but not the governance duty behind it. Discovery, classification, access visibility, and compliance reporting have to follow the data into training and inference paths, otherwise the control plane stops where AI begins. Practitioners should read DSPM for AI as a governance extension, not a separate security category.

Shadow AI creates an identity problem inside a data problem. If employees can use AI tools without sanctioned access paths, the organisation loses sight of which identities touched which data, when, and for what purpose. That is where human IAM, NHI governance, and data security intersect: the same governance gap now spans people, workloads, and AI-assisted data movement. The implication is that access policy can no longer be maintained only at the application perimeter.

Data minimisation becomes operational in AI environments, not theoretical. AI workflows amplify the risk of collecting or retaining more data than the business can justify, especially when training sets and prompts are reused across tools. The article correctly links minimisation, retention, and auditability to AI governance, because those controls determine whether data use can be defended later. Organisations that treat minimisation as a legal footnote will struggle to operationalise it in AI.

AI security programmes need a named concept: the governance gap between data visibility and data use. DSPM can tell you where data lives, but AI risk emerges from how that data is combined, accessed, and reused inside workflows. That gap is where most governance models fail today, because they stop at inventory instead of following data into action. Practitioners should design controls around use, not merely storage.

Universal coverage matters more than environment-specific comfort. The article’s Microsoft Purview discussion highlights a broader market truth: AI governance that stays inside a single ecosystem is only as complete as that ecosystem. Hybrid, multi-cloud, and third-party AI use cases require visibility across the full data estate, or the organisation will continue to govern only the portion it can see. The implication for practitioners is to test coverage against the real AI footprint, not the preferred platform footprint.

From our research library:

  • Systems with least-privileged AI access had a 17% incident rate vs 76% for over-privileged systems. Organisations failing to scope AI access properly are 4.5x more likely to experience a security incident, according to the 2026 Infrastructure Identity Survey.
  • One in five organisations reported a breach due to shadow AI, and 97% of those breached through an AI model or application lacked proper AI access controls, according to IBM's 2025 Cost of a Data Breach Report.
  • Read next: NHI Lifecycle Management Guide

What this signals

Governance has moved from the perimeter to the data path. AI workflows make the old separation between infrastructure security and data security less useful, because the important question is no longer only where information sits but how it is reused by models, prompts, and agents. Teams should expect more pressure to prove not just control coverage, but control continuity across every AI touchpoint.

Data visibility without data-use governance is the new blind spot. Organisations can know where data resides and still fail to control what AI systems do with it. That is why AI programmes now need to connect discovery, classification, retention, and access review into one operating model rather than treating them as separate disciplines.


For practitioners

  • Map AI workflows to data ownership and purpose Document where sensitive data enters training, inference, prompt, and output paths, and assign accountable owners for each workflow stage.
  • Extend discovery into shadow AI channels Inventory sanctioned and unsanctioned AI tools, browser-based use, and third-party integrations so hidden data paths do not escape monitoring.
  • Enforce least-privilege access for AI datasets Review dataset entitlements, model training inputs, and AI operator permissions to remove access that is broader than the declared task requires.
  • Bind retention and minimisation rules to AI use Set deletion, anonymisation, and retention triggers for data once it has served its AI purpose, and preserve audit evidence of each decision.
  • Validate compliance reporting across AI workflows Require audit trails that show which datasets fed which models and how access controls were enforced across cloud, SaaS, and hybrid environments.

Key takeaways

  • AI security failures often show up first as data-governance failures, because static controls do not map cleanly to dynamic model and prompt workflows.
  • Shadow AI and over-permissioned access create the largest blind spots, especially where sensitive data can move outside monitored approval paths.
  • DSPM for AI only changes outcomes when it is tied to purpose limitation, retention, and access scoping across the full AI data lifecycle.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack surface, NIST CSF 2.0 and NIST AI RMF set the technical controls, and GDPR defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIAI workflows are granted broad data access that exceeds task needs.
NHI-08 — Environment IsolationThe article stresses separating sanctioned, shadow, and third-party AI data paths.
Recommendation — Scope AI dataset access to the minimum necessary for each workflow and review excess entitlements. Segment AI data environments so shadow use and third-party tools cannot inherit trusted access paths.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article centers on controlling who and what can access sensitive data in AI workflows.
Recommendation — Apply PR.AA-05 to review and limit AI workflow entitlements across cloud and hybrid environments.
NIST AI RMFGOVERN — AI Governance and AccountabilityThe article is fundamentally about governance operating model gaps in AI security.
Recommendation — Establish governance ownership for AI data use, retention, and auditability across the enterprise.
GDPRArt.5(1)(c) — Data minimisationThe article explicitly discusses minimisation and retention obligations for AI data use.
Recommendation — Enforce data minimisation and purpose limitation for AI training and inference datasets.

Key terms

  • Data Security Posture Management: Data Security Posture Management, or DSPM, is the continuous discovery and monitoring of where sensitive data lives, how it is exposed, and where policy gaps exist. Its value rises when it feeds remediation rather than generating findings alone, especially in environments where AI expands the number of data paths.
  • Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
  • Data Minimization: Data minimization is the practice of limiting personal data collection to what is adequate, relevant, and necessary for a specific purpose. It reduces exposure by shrinking what is gathered, transferred, retained, and processed. Strong minimization depends on careful form design, purpose review, and strict collection discipline.
  • AI Governance: AI governance is the set of controls used to discover, classify, approve, restrict, monitor, and revoke AI-enabled access. It connects identity, data, and policy so organisations can manage what AI can reach, what it can share, and when it should be stopped.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org